Comments on: Resolving the Five Most Common Conditional Access Misconfigurations https://practical365.com/five-most-common-conditional-access-misconfigurations/ Practical Office 365 News, Tips, and Tutorials Wed, 18 Oct 2023 15:14:36 +0000 hourly 1 https://wordpress.org/?v=6.3.2 By: Brandon Colley https://practical365.com/five-most-common-conditional-access-misconfigurations/#comment-270172 Thu, 27 Jul 2023 14:30:41 +0000 https://practical365.com/?p=58799#comment-270172 In reply to Thomas Nielsen.

Thanks Thomas, good point about not even reaching Entra ID. Conditional Access Policies only apply AFTER authentication. Here is Microsoft’s guidance on the options for disabling SMTP in Exchange Online. https://learn.microsoft.com/en-us/exchange/clients-and-mobile-in-exchange-online/authenticated-client-smtp-submission

]]>
By: Thomas Nielsen https://practical365.com/five-most-common-conditional-access-misconfigurations/#comment-270140 Thu, 27 Jul 2023 04:40:04 +0000 https://practical365.com/?p=58799#comment-270140 In reply to Jakke.

Regarding authenticated SMTP, I also recommend to implement authentication policy’s in exchange online and create exceptions for those who need it.
The result is that the attempt will not even reach Entra ID.
In most organizations the accounts that need authenticated SMTP can be counted on one hand.
Yet, this is only a add on to Conditional access and the recommendation to limit the accounts to specific WAN IPs still apply.

]]>
By: Brandon Colley https://practical365.com/five-most-common-conditional-access-misconfigurations/#comment-269202 Wed, 19 Jul 2023 12:41:01 +0000 https://practical365.com/?p=58799#comment-269202 In reply to Jakke.

Thanks Jake! I see you already got your answer. I believe SMTP must be fully blocked whenever possible. Allowing any form of legacy authentication tenant wide opens the avenue for attack. My recommendation for accounts that require SMTP is to exclude them from this policy using a group and then apply a new CAP to heavily restrict those accounts by location or device. Accounts bypassing MFA, such as these, need to abide by more strict password guidelines, enforcing long and random passwords help mitigate risk. More stringent monitoring on these accounts would also help with detection of abnormal behaviors.

]]>
By: Jakke https://practical365.com/five-most-common-conditional-access-misconfigurations/#comment-269179 Wed, 19 Jul 2023 06:44:37 +0000 https://practical365.com/?p=58799#comment-269179 just realized it… The answer is yes

]]>
By: Jakke https://practical365.com/five-most-common-conditional-access-misconfigurations/#comment-269178 Wed, 19 Jul 2023 06:41:47 +0000 https://practical365.com/?p=58799#comment-269178 Nice Article Brandon, the CA “Legacy Authentication and MFA” would that block SMTP Auth?

]]>