Security: Setup your Microsoft 365 environment for passkeys

On April 11, 2024, Microsoft has launched a public preview that allows the use of device-bound Passkeys for Microsoft 365 services / Microsoft Entra ID logins, which can be stored in the Microsoft Authenticator App. This development marks a significant step forward in the realm of secure authentication.

In this post, we’ll delve into Passkeys, understanding their benefits, prerequisites, and configuring them within Entra ID. Additionally, we’ll explore the user journey of generating and signing in with Passkeys.

  1. What are passkeys and how do they work?
  2. What are the advantages of passkeys over conventional passwords and other MFA methods?
  3. What are the prerequisites?
    1. General prerequisites
    2. Android
    3. iOS
  4. How do I configure Entra ID to support passkeys?
  5. What does the user experience look like?
    1. Setup your Passkey with Microsoft Authenticator over iOS / User Experience
    2. Sign-In with your created Passkey to Microsoft 365 over IOS / User Experience
  6. Conclusion
Continue reading

News: My Top 10 Takeaways from Microsoft Ignite 2023

Microsoft Ignite 2023 took place from November 14-17, 2023, as a hybrid event, online and onsite in Seattle. Under the headline “Experience AI transformation in action, online from anywhere“, Microsoft showcased over 100 new solutions or updates to existing products. Microsoft showed how much they focus on AI. AI and Copilot were the buzzwords that dominated the event. But Copilot was not all that Ignite had to offer. There were also other exciting news and developments outside of Copilot that we will take a closer look at. This blog article presents my top 10 takeaways from Microsoft Ignite 2023 with a focus on Modern Workplace, Security and Windows Server vNext.

Continue reading

Security: Exploring Windows LAPS for Azure Active Directory – Initial Impressions in a Cloud-Only Setting

Recently, Windows LAPS for Windows Server Active Directory was made available to the public, and I shared my initial test impressions:
Getting to Know Windows LAPS for Active Directory – First Look

As of April 21st, 2023, Windows LAPS for Azure Active Directory is now also accessible in a public preview. This presents an opportunity to test it in a cloud-only environment, and in this blog post, I will be sharing my initial testing impressions of Windows LAPS with Azure Active Directory in this scenario.

Continue reading

Security: Getting to Know Windows LAPS for Active Directory- First Look

In October 2022, I published a blog post titled The 10 most important details about the upcoming Windows LAPS solution, which revealed that Microsoft was developing a new LAPS solution called Windows LAPS. This solution would address the long-awaited support for cloud-only devices. As of April 11, 2023, Windows LAPS for Windows Server Active Directory is now publicly available. Previously, Windows LAPS was only accessible through private preview. Unfortunately, Windows LAPS for Azure Active Directory remains in private preview and is not open to new customers. However, the Azure Active Directory LAPS scenario is anticipated to enter public preview in Q2 2023. In this blog post, I will be sharing my initial testing impressions of Windows LAPS with the Windows Server Active Directory (on-premises) scenario.

  1. Supported platforms
  2. The advantages of Windows LAPS over Legacy Microsoft LAPS
    1. # Seamless integration
    2. # Password encryption
    3. # More New capabilities
  3. Windows LAPS for Windows Server Active Directory – Configuration
    1. Windows LAPS Requirements
    2. Prepare Windows LAPS ADMX templates
    3. Update the Windows Server Active Directory schema
    4. Grant the managed device permission to update its password
    5. Delegate Windows LAPS permission
    6. Configure policy settings for Windows LAPS
  4. Windows LAPS for Windows Server Active Directory – Admin Experience
    1. Read Windows LAPS Password
    2. Windows LAPS password rotation
    3. Get Windows LAPS Password History
    4. Password backup for DSRM accounts
  5. Conclusion
Continue reading

Microsoft Intune: First impressions of Endpoint Privilege Management (EPM)

Endpoint Privilege Management (EPM) is one of the most anticipated features of the Microsoft Intune premium add-on suite and was already announced at Microsoft Ignite 2022. With EPM, Microsoft has finally developed a solution for assigning temporary administrator rights. Users no longer need to be made local administrators. Instead, your users can be given standard account permissions and be designated administrators for specific tasks. Microsoft has now released a first public preview. This blog article covers first test impressions about the new Microsoft Intune Endpoint Privilege Management feature.

  1. Licensing
  2. Windows Client requirements
  3. What files can be elevated
  4. Documentation
  5. Activate Endpoint Privilege Management (EPM)
  6. First test run – First impressions
    1. Admin Configuration – Elevation settings policy
    2. User Experience with Elevation settings policy in place
    3. Admin Configuration – Elevation rules policy
    4. User Experience with elevation rules policy in place
  7. Troubleshooting and further testing
  8. Conclusion
Continue reading

Security: Application Whitelisting with Microsoft Intune and AppLocker

While AppLocker has been around since Windows 7 and Windows Server 2008 R2, I have rarely found the solution in enterprises. The main reason was always that the implementation is very time and resource consuming and that you must constantly maintain a whitelist. This is a bummer, because the security gain is enormous when a solution like AppLocker is used. If you deal with the AppLocker rules intensively and have developed a good concept at the beginning, you will realize that you do not have to adjust the rule regularly and that the operation is not as complex as you thought.

This blog article shows the important things to consider when implementing AppLocker, how to create a usable basic ruleset that requires minimal maintenance, and how to manage with Microsoft Intune.

  1. Application whitelisting technology overview
  2. AppLocker basic recommendations
  3. AppLocker deployment considerations
  4. AppLocker OS Requirements
  5. AppLocker AppIDSvc Service Requirements
  6. Configure AppLocker and start with Audit Only Mode
  7. Configure Basic Ruleset
  8. Exceptions
    1. Path Exeptions
    2. Publisher Exception
  9. AaronLocker
  10. AppLocker deployment with Microsoft Intune
  11. Event monitoring
    1. AppLocker Event IDs
    2. _PSScriptPolicyTest*. PowerShell Scripts
    3. Azure Log Analytics / KQL
      1. Check for Audit Mode Events with KQL
      2. Check for Enforce Mode Events with KQL
    4. AppLocker Microsoft Intune Rules Storage Location
  12. Configure Enforce Mode
Continue reading

Security: First impressions of the new Windows 11 22H2 security feature Enhanced Phishing Protection

This blog article covers the new Windows 11 22H2 security feature Enhanced Phishing Protection in Microsoft Defender SmartScreen and gives first impressions.

  1. What is Enhanced Phishing Protection?
  2. How does Enhanced Phishing Protection work?
  3. How do I activate and configure Enhanced Phishing Protection?
  4. What are the first impressions?
    1. Warn me about malicious apps and sites
    2. Warn me about password reuse
    3. Warn me about unsafe password storage
    4. Phishing alerts in the Defender for Endpoint (MDE) portal
  5. Sources and additional links
Continue reading

Security: The 10 most essential details about the new Windows LAPS solution

The Local Administrator Password Solution (LAPS) from Microsoft has been around since 2015 and I have always liked using it because it was quite easy to implement and manage. Unfortunately, Azure AD (Cloud Only) support was missing and LAPS could only be used with an on-premises Active Directory. Therefore, in a cloud only environment, you had to use alternatives such as the community solution CloudLAPS. Fortunately, Microsoft is working on a new LAPS solution with the name Windows LAPS that finally offers the long-awaited support for cloud-only devices.

This blog article presents the 10 most essential details about the new Windows LAPS solution.

  1. #1 Operating System Integration
  2. #2 Supported scenarios
  3. #3 Supported platforms
  4. #4 Architecture
  5. #5 New Features
  6. #6 Management & Configuration
  7. #7 Legacy Support
  8. #9 Release Date
  9. #10 Documentation, session and demos
Continue reading

Security: How to configure Advanced Microsoft Authenticator security features in the Microsoft Entra Admin Center and why it is important to implement them now

It’s time to make Microsoft Authenticator more secure for your users. Since October 25, 2022, new Advanced Microsoft Authenticator security features are Generally Available. This blog article shows how to enable the new Advanced Microsoft Authenticator security features in Microsoft Entra admin center.

  1. Why is it important to implement these new Microsoft Authenticator security features and inform your users about them?
  2. Which security features are new available?
  3. How to configure Advanced Microsoft Authenticator security features
  4. With all the new security features enabled, how will the new user experience look like?
Continue reading