@sysadmintutor: Management says: “We need MFA for everyone.” Here’s how a sysadmin could handle that request using Conditional Access in Microsoft Entra — from creating the policy to testing the actual user experience. #IT #helpdesk #cybersecurity #sysadmin #microsoftintune
What is break glass account? This be global admin account I’m assuming?
2026-09-24 14:27:58
9
DJBsec (CISSP) :
You should go with Authentication strength not just MFA and force users to use strong MFA
2026-09-25 05:07:29
3
maloneozzy :
Who tf says 2fa
2026-09-25 02:55:13
0
imsofedup :
I was about to slaughter the MSP of my old company when they had MFA disabled for 3 YEARS. Someone actively went in. Disabled it. Called it a day. One month in I reenabled that mf
2026-09-26 21:55:55
7
dona :
what certs can you advice for one to pursue please
2026-09-28 17:19:36
0
Adrik Boyd :
I wouldn't because mfa is the bane of my existence
2026-09-25 04:28:39
0
Jankss The Troll :
did you just pronounce it "Ontra" 😳
2026-09-26 13:00:42
1
vaseline :
This is assuming licensing above Business Basic and that the org migrated from Security Defaults to Conditional Access policies though… would you really be setting up 2FA at this step?? You’d likely already have MFA existing as part of Security Defaults no??
2026-09-26 00:08:42
1
Noah :
excluding break glass from MFA is insane. Get 2 yubikeys and use passkey mfa and lock the yubikeys somewhere safe
2026-09-26 02:06:16
7
Skip :
weather is made not predicted
2026-10-06 09:46:43
0
Greg Gautelehara :
How would you go about creating a policy to install and application automatically, but this application requires another app to install it. For example terraform it needs chocolatey to install but I can’t seem to implement it to a device
2026-09-25 00:10:10
0
kade :
What job “title” does this kind of stuff? Role, certs, etc
2026-09-25 02:40:18
0
R3ND0123 :
Also exclude service accounts
2026-09-30 02:11:15
1
Teddy :
What’s the difference between this and setting something up like Duo?
2026-09-24 13:09:00
0
Bruce :
Ngl im about to do this type of project
2026-09-25 04:18:05
2
Gismo ❌ :
Making employees use their personal phones for this shit should be a crime. They should pay for smart cards or yubie keys.
2026-09-25 07:15:53
0
ShawnTech :
PR auth strength and don't exclude a gd thing
2026-09-26 18:50:00
0
Jordan :
Break glass accounts should be setup with a security key like yubikey and stored in a secure location for the company that your IT Admin can access. You shouldn’t exclude them anymore, IMO.
2026-09-25 00:27:24
0
sycoticlyme :
so enforcement also handles the enrollment campaign cool
2026-10-01 04:06:47
1
12tree :
thx bro! we need more of these
2026-09-24 15:29:18
0
To see more videos from user @sysadmintutor, please go to the Tikwm
homepage.