20/10/2022
Yesterday we successfully implemented the starting steps to security within Azure Active Directory for a client.
To start we created security groups for each department within the business, next we moved to assign sign in risk, user risk and multi factor authentication enrolment policies to the user accounts within departmental security groups.
After this we moved to conditional access policies, this began by created a named location that is trusted within this Azure environment. From here we were able to set up a locational access policy to prevent attackers from outside of the clients region from even making it to the password login page.
To add some more strength to MFA previously set up we have created some enforcement policies that require every user to complete an additional factor of authentication in order to access their accounts.
This is just the start of an exciting and strong phase for cyber security within the clients Azure Active Directory environment.