Emergency Accounts: Last Call!
ID: 3fe522ee-da5f-5e80-8680-a8e0e86331f1
STIX ID: report--3fe522ee-da5f-5e80-8680-a8e0e86331f1
Feed Name: NVISO Labs
Guidance outlining Microsoft’s upcoming mandatory MFA for Azure, Entra, and Intune admin portals, with a focus on updating emergency “break glass” accounts to phishing-resistant MFA—preferably FIDO2 hardware keys—supported by conditional access policies, separation-of-duties governance (quorum), secure storage, redundancy, monitoring/alerting of sign-ins and MFA changes, and regular testing; it also flags that MFA for non-personal/service accounts via Azure CLI/PowerShell is scheduled for early 2025 and urges inventory and migration planning.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
