Why Your Conditional Access Policies Are Failing [5 Major Pitfalls]

Sdílet
Vložit
  • čas přidán 9. 09. 2024

Komentáře • 11

  • @eddiegerlach7121
    @eddiegerlach7121 Před měsícem +2

    Another professional from the Entra ID group shared this video and I'm subbed! Excellent video! As an aspiring Cybersecurity Analyst, I appreciated the multi-layered approach to conditional access, especially where the principle of Least Privilege was illustrated. Also found the Conditional Access for Zero Trust Framework exciting, particularly where he addressed the multiple exclusions by naming conventions thru 'personas'. Thanks for sharing! 👍

  • @MrArt954
    @MrArt954 Před měsícem +2

    Amazing video. Very informative and captivating content.

  • @Sergio-Here-In-Community
    @Sergio-Here-In-Community Před měsícem +3

    Terrific video,
    That is a high level security for Conditional access.

    • @threatscape
      @threatscape  Před měsícem +1

      Thanks Sergio! Glad you found it useful

  • @ernie3878
    @ernie3878 Před měsícem +2

    Really good video covering many common gaps

    • @threatscape
      @threatscape  Před měsícem +2

      Glad it was helpful! Do let us know what you would like us to cover next.

    • @ernie3878
      @ernie3878 Před měsícem +2

      @@threatscape Continuous Access evaluation (CAE) and Token protection please :)

  • @matthewlevy6759
    @matthewlevy6759 Před měsícem +1

    Amazing video Ru. Just a question about the VPNs, are you saying consumer VPNs are not evaluated or considered in location based CA policies? And so, in your UK example, if a user from the UK was connected to a VPN to access streaming video from the USA for example, they wouldn't be blocked by the CA policy? Hence the MDA policy requirement. Or are you saying a bad actor can use a VPN to appear to come from Ireland for example, when they are in fact in the far east and without the MDA policy would be able to sign in?🤕

    • @rucam365
      @rucam365 Před měsícem +2

      Hey Matt, it's the latter. For example, if I have a CA policy that only allows Irish IPs, CA will accept IPs of VPNs, data centres, VPSs, etc, as long as their IP matches Irish geo data. Using MDA, you can refine it by saying "also block if the category - not just location - of the IP is XYZ".

  • @AnthGags333
    @AnthGags333 Před 25 dny +1

    What if- Literally saved my sanity

  • @niranmanandhar8517
    @niranmanandhar8517 Před měsícem

    The content is amazing expecti9nal the, but the background color that green background needs to be changed .we need new modern look