1
00:00:00,000 --> 00:00:11,440
Welcome to the Everyday Defender podcast.

2
00:00:11,440 --> 00:00:15,040
I'm your co-host Chris Goosen and I'm joined by my co-goose, Koos.

3
00:00:15,040 --> 00:00:17,240
Hey Chris, how are you doing?

4
00:00:17,240 --> 00:00:18,240
Doing great, doing great.

5
00:00:18,240 --> 00:00:19,240
Hey, I figured co-parties are everywhere, right?

6
00:00:19,240 --> 00:00:25,240
So you may as well have a co-goose if you're going to be doing a podcast.

7
00:00:25,240 --> 00:00:27,920
Then it's three geese in a podcast, right?

8
00:00:27,920 --> 00:00:28,920
That's right.

9
00:00:28,920 --> 00:00:34,320
In today's episode, we're very, very excited today to be talking about MFA.

10
00:00:34,320 --> 00:00:35,600
I had some thoughts about MFA.

11
00:00:35,600 --> 00:00:41,180
I've been working sort of with customers in that MFA space for a while now, but recently

12
00:00:41,180 --> 00:00:44,600
I kind of rethought, you know, went through this process of just reflecting a little bit

13
00:00:44,600 --> 00:00:49,840
on the state of MFA and I thought it'd be good for us to share, for me to share that

14
00:00:49,840 --> 00:00:50,840
with you.

15
00:00:50,840 --> 00:00:53,620
We'll talk about MFA and some guidance around there.

16
00:00:53,620 --> 00:00:58,520
And then Koos, you had some some Parsky's news and things you wanted to talk about,

17
00:00:58,520 --> 00:00:59,520
right?

18
00:00:59,520 --> 00:01:03,040
Yeah, I recently dabbled into Parsky's FIDO2 enrollment.

19
00:01:03,040 --> 00:01:07,160
So I ran into a couple of challenges there I wanted to share.

20
00:01:07,160 --> 00:01:08,160
Excellent, excellent.

21
00:01:08,160 --> 00:01:13,080
I'm sure that I'm sure there's going to be some really, really valuable information there.

22
00:01:13,080 --> 00:01:18,520
So what else have you been doing the last the last couple of weeks?

23
00:01:18,520 --> 00:01:24,800
Well, I was actually involved in a rather large security breach at one of the customers.

24
00:01:24,800 --> 00:01:27,080
So that was kind of tough.

25
00:01:27,080 --> 00:01:33,840
Unfortunately, they weren't finished with putting everything in Microsoft security stack

26
00:01:33,840 --> 00:01:35,380
just yet.

27
00:01:35,380 --> 00:01:41,400
And well, what a coincidence that they just targeted and entered some kind of VPN tunnel

28
00:01:41,400 --> 00:01:44,600
with a too easy to guess password, you know how it goes.

29
00:01:44,600 --> 00:01:46,720
But it was very unfortunate.

30
00:01:46,720 --> 00:01:49,120
So I was kind of busy with that one, to be honest.

31
00:01:49,120 --> 00:01:54,400
Yeah, well, it's it's always unfortunate when when these things happen, because for one,

32
00:01:54,400 --> 00:01:59,040
for guys like us who are kind of helping respond to these things, it's really valuable information

33
00:01:59,040 --> 00:02:00,040
right often.

34
00:02:00,040 --> 00:02:03,360
So so there's there's a level of real interest there.

35
00:02:03,360 --> 00:02:05,760
But it also is devastating for the customer, right?

36
00:02:05,760 --> 00:02:07,160
And for the environment that you're working in.

37
00:02:07,160 --> 00:02:09,680
So I can definitely understand that.

38
00:02:09,680 --> 00:02:10,680
That's that's yeah.

39
00:02:10,680 --> 00:02:15,240
And it's also a bit like though I told you years ago to stop doing that.

40
00:02:15,240 --> 00:02:18,600
Why are you still but yes, we all know how it goes.

41
00:02:18,600 --> 00:02:23,120
But essentially, bottom line, we learn from it, the company learns from it.

42
00:02:23,120 --> 00:02:29,600
And I hope I can share some details later so that others can also learn from their mistakes.

43
00:02:29,600 --> 00:02:30,600
That's awesome.

44
00:02:30,600 --> 00:02:31,600
Fantastic.

45
00:02:31,600 --> 00:02:36,240
Well, while you were doing that, I've been on holiday or vacation, I guess, for our American

46
00:02:36,240 --> 00:02:37,240
listeners.

47
00:02:37,240 --> 00:02:39,520
So I haven't been doing a whole bunch of anything.

48
00:02:39,520 --> 00:02:41,680
So it's been well, I say that.

49
00:02:41,680 --> 00:02:45,040
But I also I haven't been doing a whole lot of IT tech work, right?

50
00:02:45,040 --> 00:02:47,240
I you know, I do I live on a farm.

51
00:02:47,240 --> 00:02:49,680
So this kind of always something to be done around here.

52
00:02:49,680 --> 00:02:53,080
We've got we've got some alpacas down in the paddock.

53
00:02:53,080 --> 00:02:55,880
So there's always there's always some sort of animal related stuff.

54
00:02:55,880 --> 00:02:59,120
But other than that, I haven't really been doing too much.

55
00:02:59,120 --> 00:03:01,720
But you're able to wind down doing that, right?

56
00:03:01,720 --> 00:03:02,720
It's been good.

57
00:03:02,720 --> 00:03:04,880
But I think it's going to you know, things start kind of getting crazy again towards

58
00:03:04,880 --> 00:03:05,880
the end of the year.

59
00:03:05,880 --> 00:03:06,880
And it was good.

60
00:03:06,880 --> 00:03:08,000
It was a good unwind.

61
00:03:08,000 --> 00:03:11,680
I think we all need to take some time for our mental health and all of that every now

62
00:03:11,680 --> 00:03:13,680
and then just to to unwind.

63
00:03:13,680 --> 00:03:17,000
Yeah, I'm glad to succeed.

64
00:03:17,000 --> 00:03:21,200
So into it, I guess, let's get into to MFA.

65
00:03:21,200 --> 00:03:25,160
And so, you know, one of the things I was thinking about this a little while back, you

66
00:03:25,160 --> 00:03:30,480
know, we've I think we've all been talking about MFA and telling customers, telling anyone

67
00:03:30,480 --> 00:03:33,800
who will listen that MFA enable MFA on everything.

68
00:03:33,800 --> 00:03:34,800
Right.

69
00:03:34,800 --> 00:03:37,840
I think that's that's kind of been the message now for probably a whole like a decade.

70
00:03:37,840 --> 00:03:39,880
We've been here and say that.

71
00:03:39,880 --> 00:03:40,880
Right.

72
00:03:40,880 --> 00:03:46,200
Sadly, though, I I still see organizations, you know, that don't have any MFA.

73
00:03:46,200 --> 00:03:47,200
Right.

74
00:03:47,200 --> 00:03:48,200
Nothing.

75
00:03:48,200 --> 00:03:50,120
Not just, you know, pockets, but zero.

76
00:03:50,120 --> 00:03:54,960
And almost always the excuse is that there's a particular business case or a particular

77
00:03:54,960 --> 00:03:59,360
use case that it prevents them from from from deploying MFA.

78
00:03:59,360 --> 00:04:04,320
So they they pause the whole project for everyone because they're trying to solve, you know,

79
00:04:04,320 --> 00:04:05,920
for a very, very small group of people.

80
00:04:05,920 --> 00:04:07,600
And I feel like that's a that's a real problem.

81
00:04:07,600 --> 00:04:12,000
So one of the things I kind of wanted to talk about a little bit was, you know, well, MFA,

82
00:04:12,000 --> 00:04:14,080
is it is it still relevant for us today?

83
00:04:14,080 --> 00:04:15,920
Do we really care?

84
00:04:15,920 --> 00:04:20,200
Is it an unachievable sort of utopia that we will never get to?

85
00:04:20,200 --> 00:04:25,160
And I think, you know, for me, definitely, I think that we definitely still care about

86
00:04:25,160 --> 00:04:26,160
MFA.

87
00:04:26,160 --> 00:04:27,960
MFA is more relevant now than it's ever been before.

88
00:04:27,960 --> 00:04:28,960
Right.

89
00:04:28,960 --> 00:04:31,560
And I know we have all these kind of shiny new things like pass keys, which we'll get

90
00:04:31,560 --> 00:04:33,120
to a little later.

91
00:04:33,120 --> 00:04:37,040
But I think MFA is still really, really critical for a lot of environments, all environments,

92
00:04:37,040 --> 00:04:38,040
really.

93
00:04:38,040 --> 00:04:39,720
And I don't think it's an unachievable utopia.

94
00:04:39,720 --> 00:04:44,320
I think that there are some things that can be done in every environment that that can

95
00:04:44,320 --> 00:04:45,840
help secure that environment.

96
00:04:45,840 --> 00:04:49,720
So I really wanted to kind of break into this a little bit.

97
00:04:49,720 --> 00:04:55,400
And, you know, like I said, I think instead of saying go out and configure MFA, what I

98
00:04:55,400 --> 00:05:00,040
wanted to do today was talk a little bit about here's how you can go out and configure MFA.

99
00:05:00,040 --> 00:05:04,160
Here are some things you can do to look at that MFA deployment.

100
00:05:04,160 --> 00:05:11,240
So if we start with where should we be right now, like what is our baseline or at least

101
00:05:11,240 --> 00:05:12,520
where should everyone be?

102
00:05:12,520 --> 00:05:13,520
Right.

103
00:05:13,520 --> 00:05:17,440
So depending on who you ask, you may get some different opinions here.

104
00:05:17,440 --> 00:05:22,080
Personally, I think that you should be in a place where you have MFA for everyone.

105
00:05:22,080 --> 00:05:27,920
It doesn't matter whether they're an information worker, end user or admin, privilege user.

106
00:05:27,920 --> 00:05:31,920
They should, everyone in the environment should have some form of MFA.

107
00:05:31,920 --> 00:05:33,720
I don't really mind what it is.

108
00:05:33,720 --> 00:05:34,720
Right.

109
00:05:34,720 --> 00:05:38,400
I mean, obviously, we know that certain MFA factors are better than others.

110
00:05:38,400 --> 00:05:39,400
Right.

111
00:05:39,400 --> 00:05:45,560
So, you know, weak, fish resistant, FIDO2, very strong and everything in between.

112
00:05:45,560 --> 00:05:46,760
It doesn't really matter.

113
00:05:46,760 --> 00:05:49,800
As long as you're at that place where you have MFA for everyone, I think you're in a

114
00:05:49,800 --> 00:05:53,680
fairly good place.

115
00:05:53,680 --> 00:05:59,800
But as with everything, I think there's a lesson here that your MFA deployment is not

116
00:05:59,800 --> 00:06:00,900
set and forget.

117
00:06:00,900 --> 00:06:05,040
It's not something you're going to just set up, walk away from, and that's the end of

118
00:06:05,040 --> 00:06:06,040
it.

119
00:06:06,040 --> 00:06:07,040
Right.

120
00:06:07,040 --> 00:06:12,160
So, habits, all of these sort of the tactics and techniques continue to change.

121
00:06:12,160 --> 00:06:18,000
So we need to continue to evolve and mature the way that we deploy these things.

122
00:06:18,000 --> 00:06:23,680
And so what I wanted to talk about here is how we do that practically within the night

123
00:06:23,680 --> 00:06:24,680
bar.

124
00:06:24,680 --> 00:06:25,680
Right.

125
00:06:25,680 --> 00:06:29,800
Personally, I think that there's the way that you want to be deploying these things and

126
00:06:29,800 --> 00:06:33,200
deploying MFA is with conditional access.

127
00:06:33,200 --> 00:06:39,120
Now to do that, you need at least an entry ID P1 license in your M365 environment or

128
00:06:39,120 --> 00:06:41,040
when you enter environment.

129
00:06:41,040 --> 00:06:46,320
I understand that not everyone has that, but, you know, if you have a small business license

130
00:06:46,320 --> 00:06:50,740
with M365, small business premium, you'll have that too.

131
00:06:50,740 --> 00:06:56,560
If you don't have P1 at all, I would strongly urge you to think about that because conditional

132
00:06:56,560 --> 00:07:00,240
access is very, very important tool in your security arsenal.

133
00:07:00,240 --> 00:07:01,240
Right.

134
00:07:01,240 --> 00:07:05,480
So if it's just for MFA, but there are a lot of other things you can do with it with conditional

135
00:07:05,480 --> 00:07:06,480
access.

136
00:07:06,480 --> 00:07:11,120
And I think it makes a lot of sense for you to be considering that and planning towards

137
00:07:11,120 --> 00:07:12,720
that in your next true up.

138
00:07:12,720 --> 00:07:17,080
But let's assume you have at least entry ID P1.

139
00:07:17,080 --> 00:07:20,960
What you want to be doing here is I think you need at least two policies for your MFA

140
00:07:20,960 --> 00:07:21,960
deployment.

141
00:07:21,960 --> 00:07:22,960
Why two?

142
00:07:22,960 --> 00:07:24,880
Well, I'm going to tell you.

143
00:07:24,880 --> 00:07:30,320
The first policy that you need is one that applies MFA to all users across the org.

144
00:07:30,320 --> 00:07:33,000
So you're actually going to scope that to your cloud apps and you're going to apply

145
00:07:33,000 --> 00:07:36,280
it to the all users setting, right.

146
00:07:36,280 --> 00:07:37,740
In the environment.

147
00:07:37,740 --> 00:07:39,880
That's pretty simple one, pretty self explanatory.

148
00:07:39,880 --> 00:07:43,880
The second one, and I think this is the one that a lot of organizations kind of miss is

149
00:07:43,880 --> 00:07:46,720
you want one that applies to your admin roles as well.

150
00:07:46,720 --> 00:07:52,600
So you want a conditional access policy that applies and is scoped to the admin role itself.

151
00:07:52,600 --> 00:07:58,640
Not a group that contains the admins, not the individual users who are admins, but to

152
00:07:58,640 --> 00:07:59,640
the role itself.

153
00:07:59,640 --> 00:08:04,520
That way anything that assumes the role of an administrator, global admin or any of the,

154
00:08:04,520 --> 00:08:07,640
I don't know, there's like a hundred admin roles, right.

155
00:08:07,640 --> 00:08:12,800
Any one of those roles within the tenant will then be forced for MFA.

156
00:08:12,800 --> 00:08:17,440
And one of the reasons why we want to do this as a separate policy is that you can then

157
00:08:17,440 --> 00:08:20,400
start maturing that and you can start hardening that.

158
00:08:20,400 --> 00:08:26,880
So what you could do is when while the rest of the organization is maybe using the authenticator

159
00:08:26,880 --> 00:08:31,840
app for their MFA, you can start looking at the administrators and saying, hey, we think

160
00:08:31,840 --> 00:08:34,880
that we want to do some fishing resistant MFA here, right.

161
00:08:34,880 --> 00:08:38,400
And I'll talk about a fish resistant MFA in just a second, but you can then apply that

162
00:08:38,400 --> 00:08:41,920
fish resistant MFA only to admin roles.

163
00:08:41,920 --> 00:08:46,000
And already then what you've done is you've taken that next step to hardening the environment

164
00:08:46,000 --> 00:08:50,480
just a little bit more and you've taken that sort of next, the next level of maturity.

165
00:08:50,480 --> 00:08:55,920
So two policies, one for all your users, one for your admin roles.

166
00:08:55,920 --> 00:09:02,000
And if you can start looking at how you implement a fish resistant MFA for those admin roles,

167
00:09:02,000 --> 00:09:03,000
right.

168
00:09:03,000 --> 00:09:07,360
And by that, we mean you want something that is FIDO, FIDO2, that's FIDO2 tokens.

169
00:09:07,360 --> 00:09:09,440
I have some of these ones that I use.

170
00:09:09,440 --> 00:09:12,680
I personally, I'm a very big fan of these token two tokens.

171
00:09:12,680 --> 00:09:14,400
I think the price point on them is great.

172
00:09:14,400 --> 00:09:15,760
I really like using them.

173
00:09:15,760 --> 00:09:19,240
They come in different form factors.

174
00:09:19,240 --> 00:09:22,720
So you can, if you want to put credit card thingy in your wallet, that's great.

175
00:09:22,720 --> 00:09:25,480
This is not an ad for token two, by the way.

176
00:09:25,480 --> 00:09:28,400
We can mention the YubiKeys and all the other ones as well.

177
00:09:28,400 --> 00:09:31,840
So it was not sponsored by.

178
00:09:31,840 --> 00:09:32,840
Not sponsored by token two.

179
00:09:32,840 --> 00:09:37,880
But that's great with conditional access Chris, focusing on the roles is much better than

180
00:09:37,880 --> 00:09:39,360
focusing on groups, right.

181
00:09:39,360 --> 00:09:41,400
Because we all know how it goes.

182
00:09:41,400 --> 00:09:44,660
People are added into groups, removed from groups.

183
00:09:44,660 --> 00:09:49,000
And now that you're scoping on a role, you know that you cover all of the admins all

184
00:09:49,000 --> 00:09:50,440
of the time, right?

185
00:09:50,440 --> 00:09:51,440
100%.

186
00:09:51,440 --> 00:09:52,440
That's it.

187
00:09:52,440 --> 00:09:55,640
From that perspective, then it doesn't matter if someone's trying to slip themselves into

188
00:09:55,640 --> 00:10:01,200
an elevated role or what have you, whatever happens, you're now forcing that fish resistant

189
00:10:01,200 --> 00:10:02,960
MFA on the admin roles, right?

190
00:10:02,960 --> 00:10:05,040
So I love it.

191
00:10:05,040 --> 00:10:08,920
You're probably going to have to exclude the directory sync role if you're running inter

192
00:10:08,920 --> 00:10:09,920
ID connect.

193
00:10:09,920 --> 00:10:13,760
Otherwise, your inter ID connect will not sync because it's also going to be expected

194
00:10:13,760 --> 00:10:14,760
to MFA.

195
00:10:14,760 --> 00:10:17,920
But you know, that's something that you want to deal with.

196
00:10:17,920 --> 00:10:21,120
So back to those fish resistant MFA.

197
00:10:21,120 --> 00:10:24,040
So we mentioned FIDO.

198
00:10:24,040 --> 00:10:27,240
Anything that's PKI based as well, I think is pretty good, right?

199
00:10:27,240 --> 00:10:29,960
And I think, of course, you're going to talk about pass keys and stuff in a second.

200
00:10:29,960 --> 00:10:31,880
But you know, that's kind of where you want to be going.

201
00:10:31,880 --> 00:10:36,240
Pass keys, Windows Hello for Business falls into, I think, that category as well.

202
00:10:36,240 --> 00:10:40,780
Those types of sort of hardened fish resistant MFA methods, right?

203
00:10:40,780 --> 00:10:45,200
So I think that really is what you do.

204
00:10:45,200 --> 00:10:48,840
Now you may be asking, okay, two policies, this interesting.

205
00:10:48,840 --> 00:10:54,080
I've heard folks talk about many baseline conditional access policies.

206
00:10:54,080 --> 00:10:57,360
You'll get different opinions from different folks in the industry.

207
00:10:57,360 --> 00:11:02,120
And they may be, you know, they're perfectly valid opinions.

208
00:11:02,120 --> 00:11:03,120
Every environment is different.

209
00:11:03,120 --> 00:11:06,480
So you may need more policies.

210
00:11:06,480 --> 00:11:10,400
I like the two policy approach because it's a really easy baseline to configure.

211
00:11:10,400 --> 00:11:13,140
It also aligns very well with the CIS benchmarks.

212
00:11:13,140 --> 00:11:19,240
So I use the CIS benchmarks a lot when I do assessments of customer environments.

213
00:11:19,240 --> 00:11:25,680
And CIS 4.0, two policies, that's kind of their recommendation with fish resistant MFA

214
00:11:25,680 --> 00:11:26,680
on the admin roles.

215
00:11:26,680 --> 00:11:32,200
So you'd be getting yourself CIS compliant if you did that straight away.

216
00:11:32,200 --> 00:11:36,860
And I'm happy to see that Microsoft is now also starting and forcing their customers

217
00:11:36,860 --> 00:11:39,240
to apply MFA, right?

218
00:11:39,240 --> 00:11:44,240
With the Azure portal and more stuff is on its way.

219
00:11:44,240 --> 00:11:49,040
Because I still see companies excluding just too many users or entire groups with lots

220
00:11:49,040 --> 00:11:50,680
of users.

221
00:11:50,680 --> 00:11:55,600
Like you said before, because they just think it's a hassle to onboard the MFA if it's an

222
00:11:55,600 --> 00:11:57,600
authenticator app or SMS or whatever.

223
00:11:57,600 --> 00:12:02,520
They don't want to put that burden on their users and they just exclude those users.

224
00:12:02,520 --> 00:12:07,320
And well, soon you cannot find, not sure what the deadline is or already passed or later

225
00:12:07,320 --> 00:12:08,320
this month.

226
00:12:08,320 --> 00:12:13,000
It's the exact date, but soon you won't be able to exclude that any longer.

227
00:12:13,000 --> 00:12:14,000
That's right.

228
00:12:14,000 --> 00:12:16,280
I mean, that secure future initiative is coming for you, right?

229
00:12:16,280 --> 00:12:19,000
So better be prepared with it.

230
00:12:19,000 --> 00:12:24,500
And I think that you bring up a very good point because when it comes to exclusions,

231
00:12:24,500 --> 00:12:27,480
what about those break glass emergency accounts, right?

232
00:12:27,480 --> 00:12:32,160
We've been saying for years, you need to break glass accounts, you need to make sure that

233
00:12:32,160 --> 00:12:37,360
they have strong passwords, that the passwords are stored in a safe, that type of thing.

234
00:12:37,360 --> 00:12:41,640
We've also been saying for years that those accounts should be excluded from MFA.

235
00:12:41,640 --> 00:12:44,320
Well, that's no longer the case, right?

236
00:12:44,320 --> 00:12:49,320
We're at a place now where even your break glass accounts need to have MFA.

237
00:12:49,320 --> 00:12:56,960
Obviously, you don't want to have MFA registered on one person's device in that instance, because

238
00:12:56,960 --> 00:13:03,200
if Johnny or Jane are on a beach in Aruba and that MFA is needed, that's never a good

239
00:13:03,200 --> 00:13:04,200
place.

240
00:13:04,200 --> 00:13:08,360
So this is one of those things, again, where FIDO2 tokens makes perfect sense because you

241
00:13:08,360 --> 00:13:12,560
can keep the token in the safe as well.

242
00:13:12,560 --> 00:13:16,120
You want to think about your processes around all of this, right?

243
00:13:16,120 --> 00:13:19,720
Don't just sit and forget that you've got a process there of managing those accounts,

244
00:13:19,720 --> 00:13:23,000
the passwords, testing the logons occasionally.

245
00:13:23,000 --> 00:13:25,760
You also want to then obviously be testing those tokens, making sure that that stuff

246
00:13:25,760 --> 00:13:31,760
works, that there's a well understood procedure and process for how do we actually use these

247
00:13:31,760 --> 00:13:32,760
things?

248
00:13:32,760 --> 00:13:35,200
How do we develop this and use these accounts?

249
00:13:35,200 --> 00:13:40,160
So all of those things need to be documented and thought about as a process, right?

250
00:13:40,160 --> 00:13:41,160
Really, really important.

251
00:13:41,160 --> 00:13:47,040
So regarding the break the glass, Chris, I actually recently discovered a feature in

252
00:13:47,040 --> 00:13:49,920
a password vault from Keeper.

253
00:13:49,920 --> 00:13:55,420
We use Keeper at the company as a business solution for a lot of our passwords.

254
00:13:55,420 --> 00:14:02,720
And I actually discovered that Keeper provides a way to provide a OTP based MFA method inside

255
00:14:02,720 --> 00:14:03,720
Keeper.

256
00:14:03,720 --> 00:14:08,080
And the great thing about that is if you share those credentials with other people which

257
00:14:08,080 --> 00:14:13,320
should have access to the break the glass account, they can actually pull out the OTP

258
00:14:13,320 --> 00:14:16,520
from Keeper, put it in the login.

259
00:14:16,520 --> 00:14:21,700
To be honest, technically it's not the most secure and best solution because you still

260
00:14:21,700 --> 00:14:26,360
have a dependency on the Entra ID MFA service.

261
00:14:26,360 --> 00:14:30,040
So people at Microsoft will tell you that the FIDO2 key is even better.

262
00:14:30,040 --> 00:14:32,520
And I would agree with that.

263
00:14:32,520 --> 00:14:36,160
But like you said, the FIDO2 key is living in a safe.

264
00:14:36,160 --> 00:14:39,240
Now you should also think about the process.

265
00:14:39,240 --> 00:14:41,000
How can we enter that safe?

266
00:14:41,000 --> 00:14:42,880
Who has the key to that safe, right?

267
00:14:42,880 --> 00:14:46,920
A whole bunch of challenges might arise.

268
00:14:46,920 --> 00:14:51,880
And that's why I do think that although it might not be on the top of the list regarding

269
00:14:51,880 --> 00:14:58,000
the securest way, I think it's secure because it has a different additional dependency.

270
00:14:58,000 --> 00:15:05,200
There might be an issue with Microsoft services while causing the OTP MFA not to work.

271
00:15:05,200 --> 00:15:13,000
But I still think it's much better than SMS or Authenticator from the CEO on the beach.

272
00:15:13,000 --> 00:15:14,000
That's right.

273
00:15:14,000 --> 00:15:20,680
And I think that's a really good point because again, just small gains here, small things

274
00:15:20,680 --> 00:15:23,120
that you do add up over time.

275
00:15:23,120 --> 00:15:27,060
So don't let perfect be the enemy of good with this.

276
00:15:27,060 --> 00:15:31,460
If today your break glass accounts are there and they're excluded, the next really good

277
00:15:31,460 --> 00:15:32,680
step could be something like that.

278
00:15:32,680 --> 00:15:40,780
I know Bitwarden does the same thing you can have in password vault OTP as well.

279
00:15:40,780 --> 00:15:44,360
There are other solutions as well that you can look at.

280
00:15:44,360 --> 00:15:45,360
Think about these things.

281
00:15:45,360 --> 00:15:47,720
And the important thing is to revisit these things.

282
00:15:47,720 --> 00:15:53,440
If you're going to do this today, next year or in the next six months, whenever you're

283
00:15:53,440 --> 00:15:57,120
looking at all of your security again, look at these things and see if there's a better

284
00:15:57,120 --> 00:16:00,120
solution or if there's a better option available for you.

285
00:16:00,120 --> 00:16:04,760
So yeah, I hear the argument a lot of times as well at customers that they don't want

286
00:16:04,760 --> 00:16:10,040
to enforce an Authenticator app, for example, on mobile phones because they're privately

287
00:16:10,040 --> 00:16:15,640
owned devices and some employees don't want to mess with business apps on their privately

288
00:16:15,640 --> 00:16:16,640
owned devices.

289
00:16:16,640 --> 00:16:17,640
Right.

290
00:16:17,640 --> 00:16:22,040
I think it might be not a popular opinion, but then go for SMS MFA.

291
00:16:22,040 --> 00:16:24,320
It's even better than no MFA.

292
00:16:24,320 --> 00:16:31,160
And especially where phone companies make it harder to copy SIM cards nowadays.

293
00:16:31,160 --> 00:16:35,880
I think, well, of course it's still a risk and other MFA is better, but it's better than

294
00:16:35,880 --> 00:16:36,880
nothing.

295
00:16:36,880 --> 00:16:37,880
Again, a hundred percent.

296
00:16:37,880 --> 00:16:42,400
And these are the types of things that I think we come up with.

297
00:16:42,400 --> 00:16:47,320
Real world example is I was working with a customer not too long ago and this exact thing

298
00:16:47,320 --> 00:16:48,820
came up.

299
00:16:48,820 --> 00:16:55,520
This customer, most of their users belonged to a U.S. based customer.

300
00:16:55,520 --> 00:16:58,080
Most of their users belonged to a union.

301
00:16:58,080 --> 00:17:06,200
And as part of the union, they do not allow the use of personal devices for work activities.

302
00:17:06,200 --> 00:17:10,600
Their stance on this is very much that if it's going to be used for work, workers to

303
00:17:10,600 --> 00:17:11,960
provide it.

304
00:17:11,960 --> 00:17:17,600
For the company or for the organization, very large expense to be providing phones for everyone.

305
00:17:17,600 --> 00:17:23,320
But you can provide these things to people for relatively, it's relatively affordable

306
00:17:23,320 --> 00:17:27,200
compared to providing someone a new iPhone every few years.

307
00:17:27,200 --> 00:17:28,200
And you're right, this happens.

308
00:17:28,200 --> 00:17:33,840
I think in Europe where you are, it's quite common to either be provided a work phone

309
00:17:33,840 --> 00:17:35,680
or not be expected to use it at all.

310
00:17:35,680 --> 00:17:40,440
I know I worked for a Swiss company before and it was the same thing.

311
00:17:40,440 --> 00:17:42,760
The company just said, you will use our phone.

312
00:17:42,760 --> 00:17:44,640
It's secured by our policy.

313
00:17:44,640 --> 00:17:50,480
And if you want to access anything outside of the office, this is what you use.

314
00:17:50,480 --> 00:17:56,440
So I think that's one of the reasons why the iPhone SE is doing so well in Europe as well.

315
00:17:56,440 --> 00:17:57,920
Right, they still make that thing.

316
00:17:57,920 --> 00:18:01,540
It's a portable iPhone and it has a very long support period.

317
00:18:01,540 --> 00:18:05,240
So that's probably the choice that most companies are making.

318
00:18:05,240 --> 00:18:06,240
Fair enough.

319
00:18:06,240 --> 00:18:09,200
I mean, look, if you're really just using it for Teams email and authenticator, there's

320
00:18:09,200 --> 00:18:14,000
probably not, you probably don't need a great hunking phone.

321
00:18:14,000 --> 00:18:18,040
So look, I think to summarize and some takeaways here, and obviously, folks, we're going to

322
00:18:18,040 --> 00:18:19,560
put all of this information in.

323
00:18:19,560 --> 00:18:23,920
We'll link this to the blog, to our blog, and we'll be able to kind of read all this

324
00:18:23,920 --> 00:18:24,920
information.

325
00:18:24,920 --> 00:18:28,640
So don't worry if you haven't summarized all of this while we've been talking.

326
00:18:28,640 --> 00:18:33,500
But some takeaways here that I kind of wanted to leave you with here is if you don't already

327
00:18:33,500 --> 00:18:38,040
have MFA deployed, I think it's really, really important to start somewhere.

328
00:18:38,040 --> 00:18:43,560
If you have a particular use case, a particular group of users or whatever you that can't,

329
00:18:43,560 --> 00:18:46,480
there's no immediate solution for, that's okay.

330
00:18:46,480 --> 00:18:51,360
Work on that in the background, but continue to deploy your MFA across the org to other

331
00:18:51,360 --> 00:18:52,360
folks.

332
00:18:52,360 --> 00:18:56,800
I think it's really, really important that your admin accounts are very well secured.

333
00:18:56,800 --> 00:18:58,960
Look at that Fisheries system MFA.

334
00:18:58,960 --> 00:19:01,040
And then make sure you limit exclusions.

335
00:19:01,040 --> 00:19:07,600
I think it's far too easy in environments where, especially where you have a lot of

336
00:19:07,600 --> 00:19:12,320
admins, it becomes very, very easy for folks to just start excluding and excluding from

337
00:19:12,320 --> 00:19:13,320
policy.

338
00:19:13,320 --> 00:19:17,000
It's not a good place to be unless you absolutely have to.

339
00:19:17,000 --> 00:19:18,600
So yeah, not all or nothing.

340
00:19:18,600 --> 00:19:20,000
And it's really not all said.

341
00:19:20,000 --> 00:19:21,220
It's not said and forget.

342
00:19:21,220 --> 00:19:25,440
This is something that you want to, as with all your security configurations and processes.

343
00:19:25,440 --> 00:19:29,720
And we're going to talk a little bit later in the episode when we look at our community

344
00:19:29,720 --> 00:19:33,920
tool spotlight, we'll talk about some tooling to kind of help you with some of the sort

345
00:19:33,920 --> 00:19:36,520
of continuous improvement stuff.

346
00:19:36,520 --> 00:19:40,840
But yeah, MFA, it's not going anywhere, I don't think.

347
00:19:40,840 --> 00:19:45,200
But Kos, why don't you tell us about Parsky's and kind of what you've been up to in that

348
00:19:45,200 --> 00:19:46,200
space.

349
00:19:46,200 --> 00:19:47,200
Yeah, thanks, Chris.

350
00:19:47,200 --> 00:19:52,920
MFA is actually, it should be a no brainer, especially when you see that the password

351
00:19:52,920 --> 00:20:00,200
attacks are still the most popular attacks and main reasons why adversaries are entering

352
00:20:00,200 --> 00:20:04,880
your company's organization, the company's network.

353
00:20:04,880 --> 00:20:11,760
But although the password attacks are still the most popular attack factor, we also see

354
00:20:11,760 --> 00:20:16,360
a rise in phishing for MFA.

355
00:20:16,360 --> 00:20:22,280
So called adversary in the middle attacks, where an adversary is in the middle between

356
00:20:22,280 --> 00:20:24,760
you and the authentication.

357
00:20:24,760 --> 00:20:28,360
And they actually are able to phish your session token.

358
00:20:28,360 --> 00:20:33,540
So you think you're authenticating to the portal, to your application, but you're actually

359
00:20:33,540 --> 00:20:39,280
sending out the authentication key to the adversary, which can steal your token.

360
00:20:39,280 --> 00:20:44,680
And as long as the token is valid, they can authenticate as you and probably register

361
00:20:44,680 --> 00:20:50,440
an additional MFA method, for example, so that they have some kind of persistence and

362
00:20:50,440 --> 00:20:54,000
can keep coming back.

363
00:20:54,000 --> 00:20:55,440
I was really scary.

364
00:20:55,440 --> 00:20:58,680
Like I've seen some of the tooling that they use for that.

365
00:20:58,680 --> 00:21:02,320
Yeah, it's I mean, you know, you'd be able to convince most folks to.

366
00:21:02,320 --> 00:21:07,720
Yeah, I also want to encourage people to start messing with those tools as well.

367
00:21:07,720 --> 00:21:13,680
One of the most popular ones is Evil Genics, probably well known in the community.

368
00:21:13,680 --> 00:21:23,480
It's an open source tool you can run as a proxy between and simulate this kind of attacks

369
00:21:23,480 --> 00:21:28,600
where the user sees a Microsoft online dot com URL, but the O is a zero or something

370
00:21:28,600 --> 00:21:29,600
like that.

371
00:21:29,600 --> 00:21:35,400
So with a slight change, they'll probably won't notice that all kinds of impressive

372
00:21:35,400 --> 00:21:36,880
demos with that.

373
00:21:36,880 --> 00:21:42,280
And indeed, it makes you think the next time you connect to Starbucks Wi Fi, is it really

374
00:21:42,280 --> 00:21:46,800
the Starbucks Wi Fi or am I connecting to a spot in somebody's backpack?

375
00:21:46,800 --> 00:21:47,800
Right?

376
00:21:47,800 --> 00:21:50,280
Well, don't ever connect to the Starbucks Wi Fi.

377
00:21:50,280 --> 00:21:52,880
That's the easiest solution there.

378
00:21:52,880 --> 00:21:53,880
But now I hear what you're saying.

379
00:21:53,880 --> 00:21:58,840
And, you know, I think it's an interesting concept because these tools exist.

380
00:21:58,840 --> 00:22:01,560
And if you bury your head in the sand and ignore them, it doesn't mean they're going

381
00:22:01,560 --> 00:22:02,560
to go away.

382
00:22:02,560 --> 00:22:03,560
Right.

383
00:22:03,560 --> 00:22:07,760
And I think Merrill Fernando from Microsoft sort of posted on LinkedIn or X the other

384
00:22:07,760 --> 00:22:10,720
day and he was wrestling with the issue, right?

385
00:22:10,720 --> 00:22:13,880
Is how much information do you provide folks?

386
00:22:13,880 --> 00:22:18,080
Because when you provide them enough information, they can either choose to use that information

387
00:22:18,080 --> 00:22:22,280
as in a good way as a defender to protect their environment.

388
00:22:22,280 --> 00:22:26,480
Or that same information can also be weaponized and used in a bad way.

389
00:22:26,480 --> 00:22:27,480
Right.

390
00:22:27,480 --> 00:22:31,360
And I think it's one of those things is if you just ignore it, it's not going to go away.

391
00:22:31,360 --> 00:22:34,840
So I think it's really good to be talking about the tools that are being used, getting

392
00:22:34,840 --> 00:22:40,200
folks across that stuff and familiar with it so they know how to defend against it.

393
00:22:40,200 --> 00:22:41,200
Yeah.

394
00:22:41,200 --> 00:22:42,200
Yeah.

395
00:22:42,200 --> 00:22:45,120
And again, I still stand by my earlier remark.

396
00:22:45,120 --> 00:22:50,240
If your only MFA option right now due to all kinds of policies you have in a company is

397
00:22:50,240 --> 00:22:53,540
SMS MFA, it's even better than none.

398
00:22:53,540 --> 00:22:58,280
But I would strongly encourage looking into the pass keys as an MFA method.

399
00:22:58,280 --> 00:23:03,200
Or if you're already using MFA with your authenticator app, look into pass keys as well.

400
00:23:03,200 --> 00:23:07,540
So pass keys is a pair of cryptography keys, right?

401
00:23:07,540 --> 00:23:13,400
Like you mentioned earlier, as a PKI based authentication where the private key is protected

402
00:23:13,400 --> 00:23:20,280
on the device by a pin or biometric authentication with a fingerprint or something like that.

403
00:23:20,280 --> 00:23:24,720
And pass keys you can use as a passwordless login as well.

404
00:23:24,720 --> 00:23:29,700
And you're probably seeing a lot of sites popping up lately providing you the option

405
00:23:29,700 --> 00:23:32,920
to register a pass key, GitHub, Google.

406
00:23:32,920 --> 00:23:36,680
Google is annoyingly good at that.

407
00:23:36,680 --> 00:23:37,680
It pops up all the time.

408
00:23:37,680 --> 00:23:39,880
And if you're not paying attention, you just generate pass key.

409
00:23:39,880 --> 00:23:40,880
Yeah.

410
00:23:40,880 --> 00:23:43,840
And the other day I had a look and I had all these pass keys and I'm like, I don't even

411
00:23:43,840 --> 00:23:45,560
remember where I generated these things.

412
00:23:45,560 --> 00:23:48,200
So they were annoyingly good at pushing that out.

413
00:23:48,200 --> 00:23:49,200
Yeah.

414
00:23:49,200 --> 00:23:53,560
And then especially when you're using a password vault, if you're either using Apple's own

415
00:23:53,560 --> 00:23:59,120
iCloud key chain or something, or one password or LastPass or Keeper or whatever, you can

416
00:23:59,120 --> 00:24:05,220
store those pass keys in your password vault and you don't even need to know a password

417
00:24:05,220 --> 00:24:07,560
to authenticate to that website, right?

418
00:24:07,560 --> 00:24:10,600
So there are actually two types of password pass keys.

419
00:24:10,600 --> 00:24:15,620
So these are the cloud syncable pass keys we're talking about, but Microsoft is currently

420
00:24:15,620 --> 00:24:19,060
not providing those types of pass keys just yet.

421
00:24:19,060 --> 00:24:20,060
They might in the future.

422
00:24:20,060 --> 00:24:21,260
I don't know.

423
00:24:21,260 --> 00:24:27,480
So currently they only offer device bound pass keys, which means that the pass key is

424
00:24:27,480 --> 00:24:34,440
bound to a physical device, either a FIDO2 key, which is also a pass key.

425
00:24:34,440 --> 00:24:37,520
You held them up in front of the camera earlier.

426
00:24:37,520 --> 00:24:38,840
We're familiar with those.

427
00:24:38,840 --> 00:24:45,080
But recently Microsoft also provided you the option to register a device bound pass key

428
00:24:45,080 --> 00:24:50,920
inside their authenticator app on your phone, which essentially makes your phone a FIDO2

429
00:24:50,920 --> 00:24:54,600
key, if you will, so to speak.

430
00:24:54,600 --> 00:25:00,600
And the way that that works, you scan a QR code from your screen with the authenticator

431
00:25:00,600 --> 00:25:02,560
app and then you authenticate.

432
00:25:02,560 --> 00:25:05,340
And I was like, this is kind of peculiar, right?

433
00:25:05,340 --> 00:25:06,920
Why is this phishing resistant?

434
00:25:06,920 --> 00:25:11,600
How can a attacker not generate a QR code, which I need to scan?

435
00:25:11,600 --> 00:25:19,280
But the problem is, well, the solution there lies in the fact that the device you're authenticating

436
00:25:19,280 --> 00:25:25,620
with needs to be in a close by proximity of the actual authentication.

437
00:25:25,620 --> 00:25:30,700
And that's also why Bluetooth is used on your smartphone, for example, or with a FIDO key,

438
00:25:30,700 --> 00:25:34,160
you physically bring it to the computer, right, and stick it in.

439
00:25:34,160 --> 00:25:40,720
And that's why Bluetooth is also required on the device.

440
00:25:40,720 --> 00:25:48,160
And although it is the safest method of MFA right now, pass keys, it also comes with a

441
00:25:48,160 --> 00:25:54,920
couple of limitations, of course, because that makes sure that we won't run out of work,

442
00:25:54,920 --> 00:25:55,920
Chris.

443
00:25:55,920 --> 00:25:59,080
Well, I was just going to ask you how ready for prime time is this?

444
00:25:59,080 --> 00:26:05,960
Because just to take a second here, I think we talked earlier about MFA and deploying

445
00:26:05,960 --> 00:26:07,200
the authenticator app.

446
00:26:07,200 --> 00:26:11,800
Well, if you've already done the work to deploy the authenticator app to your end users and

447
00:26:11,800 --> 00:26:15,880
they are already using it, that makes it a little bit easier for them to then adopt something

448
00:26:15,880 --> 00:26:16,880
like pass keys, right?

449
00:26:16,880 --> 00:26:19,960
So again, there's that sort of maturity that can be done.

450
00:26:19,960 --> 00:26:25,640
Yeah, I have to put a caveat here is that it's still in preview, the pass key through

451
00:26:25,640 --> 00:26:27,600
authenticator app.

452
00:26:27,600 --> 00:26:33,360
So that might already be a reason companies will probably stay away from it until it becomes

453
00:26:33,360 --> 00:26:34,400
GA.

454
00:26:34,400 --> 00:26:39,960
But there is now a seamless onboarding method from the authenticator apps for like you said,

455
00:26:39,960 --> 00:26:42,640
it's very easy to onboard.

456
00:26:42,640 --> 00:26:45,520
But still, there are a couple of challenges there.

457
00:26:45,520 --> 00:26:52,640
And I would say a FIDO key, a physical keys is already more maybe perhaps a proven technology.

458
00:26:52,640 --> 00:26:59,640
Again, I mentioned the Bluetooth requirements on the authenticator app, which can be a problem

459
00:26:59,640 --> 00:27:04,320
in companies where they want to restrict Bluetooth connections, for example, from your laptop.

460
00:27:04,320 --> 00:27:08,520
And Microsoft has written interesting guides for that.

461
00:27:08,520 --> 00:27:15,360
And we will link them to the show notes, of course, where they help you restrict Bluetooth,

462
00:27:15,360 --> 00:27:21,760
but allow the authenticator app smartphone connection, for example, through an Intune

463
00:27:21,760 --> 00:27:24,640
policy deployment, for example.

464
00:27:24,640 --> 00:27:33,960
But when I was at the company I worked for, we were actually enforcing the phishing resistant

465
00:27:33,960 --> 00:27:35,360
MFA strength.

466
00:27:35,360 --> 00:27:38,880
That's what Microsoft calls it inside the conditional access.

467
00:27:38,880 --> 00:27:41,280
And we actually ran into a completely different issue.

468
00:27:41,280 --> 00:27:44,560
And I wanted to highlight that as well today.

469
00:27:44,560 --> 00:27:50,120
We had external contractors logging on an Azure Virtual Desktop environment.

470
00:27:50,120 --> 00:27:53,860
And the Azure Virtual Desktop environment is a trusted environment.

471
00:27:53,860 --> 00:27:56,720
Those devices are compliant.

472
00:27:56,720 --> 00:28:00,400
And thus from there, they can authenticate into all the company apps.

473
00:28:00,400 --> 00:28:04,320
And with conditional access, we check device compliance, we check risk status, all those

474
00:28:04,320 --> 00:28:05,500
kinds of things.

475
00:28:05,500 --> 00:28:10,680
But the thing is, when those external contractors were using a Mac, and they were using the

476
00:28:10,680 --> 00:28:15,320
remote desktop connection client by Microsoft to connect into the Azure Virtual Desktop

477
00:28:15,320 --> 00:28:21,360
environment, that client does not support Web of N. And that's actually the name of

478
00:28:21,360 --> 00:28:29,800
the protocol used to do passkey authentication, which makes it impossible to do a seamless

479
00:28:29,800 --> 00:28:38,920
phishing resistant MFA connection on the remote virtual desktop machine with a FIDO key stuck

480
00:28:38,920 --> 00:28:42,000
into the local MacBook, for example.

481
00:28:42,000 --> 00:28:43,000
Interesting.

482
00:28:43,000 --> 00:28:44,760
Yeah, that is a challenge.

483
00:28:44,760 --> 00:28:45,760
That is.

484
00:28:45,760 --> 00:28:50,480
And of course, Microsoft will tell you, well, you can onboard the Mac and use how do you

485
00:28:50,480 --> 00:28:56,120
call it, a system level, a single sign on or something like that with Intune.

486
00:28:56,120 --> 00:28:57,540
Of course, you can do that.

487
00:28:57,540 --> 00:29:01,080
And then you can use the FIDO key locally on the machine.

488
00:29:01,080 --> 00:29:03,440
That's no problem for Mac as well.

489
00:29:03,440 --> 00:29:08,800
But if you are relying on a remote desktop connection in between, you're kind of screwed

490
00:29:08,800 --> 00:29:09,800
actually.

491
00:29:09,800 --> 00:29:10,800
Interesting.

492
00:29:10,800 --> 00:29:14,280
And obviously, in a contractor scenario, that's why you would have that, right?

493
00:29:14,280 --> 00:29:18,240
Is you have contractors bringing their own devices and you want to put them on their

494
00:29:18,240 --> 00:29:19,240
remote desktop because...

495
00:29:19,240 --> 00:29:20,240
Yeah.

496
00:29:20,240 --> 00:29:21,240
So this is still a major downside.

497
00:29:21,240 --> 00:29:27,320
And I also noticed that even Windows users using the remote desktop connection app from

498
00:29:27,320 --> 00:29:34,080
the Windows Store, which is funnily enough, exactly the same as the MSI you download and

499
00:29:34,080 --> 00:29:35,080
install.

500
00:29:35,080 --> 00:29:40,200
It looks the same, has the same icon, but the Windows Store version also does not come

501
00:29:40,200 --> 00:29:43,760
with WebAuth and redirection abilities.

502
00:29:43,760 --> 00:29:47,320
And this probably has something to do with the fact that those Windows Store apps run

503
00:29:47,320 --> 00:29:52,680
in a kind of containerized sandbox-like process on the machine.

504
00:29:52,680 --> 00:29:57,640
And that's why they cannot reach out to the USB port or the Bluetooth connection to process

505
00:29:57,640 --> 00:29:58,640
that.

506
00:29:58,640 --> 00:29:59,640
Okay.

507
00:29:59,640 --> 00:30:00,640
That's interesting.

508
00:30:00,640 --> 00:30:01,640
Wow.

509
00:30:01,640 --> 00:30:02,640
Yeah.

510
00:30:02,640 --> 00:30:05,400
So if you're running into those issues with Windows, make sure to download the MSI version

511
00:30:05,400 --> 00:30:07,600
of the remote desktop connection.

512
00:30:07,600 --> 00:30:12,480
And for Mac, I'm really hoping Microsoft is able to figure out an updated connection for

513
00:30:12,480 --> 00:30:18,160
Mac users as well, because this customer actually had to hand out Windows laptops now to those

514
00:30:18,160 --> 00:30:23,640
external contractors to make sure that they're able to authenticate to their resources remotely.

515
00:30:23,640 --> 00:30:24,640
Wow.

516
00:30:24,640 --> 00:30:25,640
Yeah.

517
00:30:25,640 --> 00:30:29,800
And look, there's nothing worse than telling a Mac guy that he has to use Windows.

518
00:30:29,800 --> 00:30:32,000
I know how it feels.

519
00:30:32,000 --> 00:30:37,480
Sacrilege, because that's happened to me before, so I understand.

520
00:30:37,480 --> 00:30:40,340
But I would also like, it's 2024, right?

521
00:30:40,340 --> 00:30:44,160
Are we still having the Windows versus Mac discussion from the 90s?

522
00:30:44,160 --> 00:30:45,160
That's right.

523
00:30:45,160 --> 00:30:46,160
Well, apparently we do.

524
00:30:46,160 --> 00:30:47,160
Yeah.

525
00:30:47,160 --> 00:30:48,160
Okay.

526
00:30:48,160 --> 00:30:54,800
And another thing I also noticed, I'm a big fan of one password.

527
00:30:54,800 --> 00:31:01,560
Although I am stuck into the Apple ecosystem with a lot of my devices and photos and everything,

528
00:31:01,560 --> 00:31:06,440
I tend to like the idea that my passwords and everything are still in a third party

529
00:31:06,440 --> 00:31:10,000
company, right?

530
00:31:10,000 --> 00:31:12,680
In this case, I've chosen for one password.

531
00:31:12,680 --> 00:31:19,320
But the thing is with iOS, when you use one password to automatically fill in the passwords

532
00:31:19,320 --> 00:31:24,640
for you and the pass keys, for example, and you want to enroll the pass key on the Microsoft

533
00:31:24,640 --> 00:31:30,440
Authenticator app, you have to make the Authenticator app the primary application to fill in the

534
00:31:30,440 --> 00:31:36,200
passwords for you, because otherwise Authenticator app will not pop up being able for you to

535
00:31:36,200 --> 00:31:38,800
complete the authentication request.

536
00:31:38,800 --> 00:31:43,520
Luckily, iOS 18 solves this issue, and I know it's already out now for a couple of

537
00:31:43,520 --> 00:31:49,040
weeks, but when I was struggling with these issues, iOS 18 was still in beta, and iOS

538
00:31:49,040 --> 00:31:55,080
18 now allows you to select multiple password providers.

539
00:31:55,080 --> 00:31:57,760
And I believe this wasn't an issue on Android devices.

540
00:31:57,760 --> 00:32:03,040
So also keep in mind, if you're running into it, do this issue, update to iOS 18.

541
00:32:03,040 --> 00:32:04,040
Interesting.

542
00:32:04,040 --> 00:32:05,040
That's good info.

543
00:32:05,040 --> 00:32:10,360
I think that being able to use multiple password managers and all that, I think it's important.

544
00:32:10,360 --> 00:32:14,400
And I think the adoption of pass keys, I think, is only going to continue to grow once we

545
00:32:14,400 --> 00:32:16,200
can actually properly sync them.

546
00:32:16,200 --> 00:32:20,400
Because I think the FIDO Alliance is actually, they're working on actually allowing it as

547
00:32:20,400 --> 00:32:24,080
part of the actual, what do you call it, the standard, right?

548
00:32:24,080 --> 00:32:29,280
To allow the synchability and make it a little bit more open for everyone to be able to sync

549
00:32:29,280 --> 00:32:30,280
these things.

550
00:32:30,280 --> 00:32:32,000
So yeah, good to know.

551
00:32:32,000 --> 00:32:36,480
I used, like you, most of my stuff is Apple too.

552
00:32:36,480 --> 00:32:39,640
I use BOOKWARDEN as my password manager.

553
00:32:39,640 --> 00:32:44,040
I also like to have that third party thing that's just outside, right?

554
00:32:44,040 --> 00:32:48,360
Just keeps things kind of nicer from a cleaner, I guess, from that perspective.

555
00:32:48,360 --> 00:32:51,600
So very, very nice.

556
00:32:51,600 --> 00:32:54,480
Any closing thoughts on pass keys here?

557
00:32:54,480 --> 00:32:57,760
Well, yeah, I think I already gave that away, I guess.

558
00:32:57,760 --> 00:33:05,280
I think it is, especially FIDO 2 keys is the way to go, in my opinion.

559
00:33:05,280 --> 00:33:11,600
But again, if you want to stick with SMS for now, do that instead of don't enabling it

560
00:33:11,600 --> 00:33:12,840
at all.

561
00:33:12,840 --> 00:33:16,960
But also be aware of some potential downsides with the FIDO 2 keys.

562
00:33:16,960 --> 00:33:18,880
You have to hand them out.

563
00:33:18,880 --> 00:33:25,080
Also a thing you have to remember, if you really want to enforce phishing-resistant

564
00:33:25,080 --> 00:33:31,120
MFA on all users, you also have to think about an additional step when you onboard new users.

565
00:33:31,120 --> 00:33:36,520
Because if you have a new user and he or she authenticates for the first time to your environment,

566
00:33:36,520 --> 00:33:42,240
normally you would receive a pop-up asking you to register your authenticator as an MFA

567
00:33:42,240 --> 00:33:43,240
method.

568
00:33:43,240 --> 00:33:48,200
For FIDO 2 keys, pass keys, that is unfortunately not yet possible.

569
00:33:48,200 --> 00:33:53,440
And since you are forcing the conditional access policy to require an MFA method with

570
00:33:53,440 --> 00:33:56,680
a phishing-resistant strength, you cannot register.

571
00:33:56,680 --> 00:34:01,880
So you have an egg problem.

572
00:34:01,880 --> 00:34:07,560
So the way you can work around this is by registering a temporary access pass with a

573
00:34:07,560 --> 00:34:09,880
new user for the first time.

574
00:34:09,880 --> 00:34:12,880
It can be a one-time valid, for example.

575
00:34:12,880 --> 00:34:17,280
They authenticate with the temporary access pass, and then they register the FIDO 2 key,

576
00:34:17,280 --> 00:34:23,680
and that will be the authentication method for all future authentications.

577
00:34:23,680 --> 00:34:33,200
Yeah, but also take a look at Evolgenics and how scary and easy it is for adversaries to

578
00:34:33,200 --> 00:34:35,200
phish your session tokens.

579
00:34:35,200 --> 00:34:40,120
And yeah, I think this should really be on your list of to-dos.

580
00:34:40,120 --> 00:34:41,120
Yeah, absolutely.

581
00:34:41,120 --> 00:34:42,120
Thank you.

582
00:34:42,120 --> 00:34:43,120
I think that's great.

583
00:34:43,120 --> 00:34:48,320
We have that in the show notes, so we can definitely refer to that.

584
00:34:48,320 --> 00:34:53,600
One of the things we want to do with the show as part of providing this information to folks,

585
00:34:53,600 --> 00:34:58,080
I think, is we want to highlight a lot of the really good work that's coming out of

586
00:34:58,080 --> 00:34:59,080
the community.

587
00:34:59,080 --> 00:35:06,080
And there's a lot of work being done by MVPs and just folks in the broader Microsoft and

588
00:35:06,080 --> 00:35:11,320
security communities to help everyone get more secure.

589
00:35:11,320 --> 00:35:13,880
One of the things I think for this week that we wanted to talk about, or the thing for

590
00:35:13,880 --> 00:35:17,840
this week that we want to talk about, is a project called Maester.

591
00:35:17,840 --> 00:35:25,480
Now, if you are into inter-ID at all, then you probably follow Meryl Fernando on the

592
00:35:25,480 --> 00:35:32,920
socials, and you'll know that he is not an AI bot, but in fact, a very, very smart fellow

593
00:35:32,920 --> 00:35:34,400
that works for Microsoft.

594
00:35:34,400 --> 00:35:37,120
He's actually based here in Melbourne, in Australia.

595
00:35:37,120 --> 00:35:41,280
Now, part of a project that Meryl's been involved in, and he's not the only one, he seems to

596
00:35:41,280 --> 00:35:45,520
be the face of the project, but I know there's Fabien and a bunch of other guys that are

597
00:35:45,520 --> 00:35:49,200
folks that are involved in this project, is called Maester.

598
00:35:49,200 --> 00:35:55,640
What it is, is it's essentially an easy button for being able to run continuous testing on

599
00:35:55,640 --> 00:35:58,720
your M365 environment.

600
00:35:58,720 --> 00:36:04,720
It's a PowerShell module that allows you to run a bunch of tests against your environment

601
00:36:04,720 --> 00:36:07,320
and basically see the output and outcome of those tests.

602
00:36:07,320 --> 00:36:11,480
You can run those tests as a one-off to see, draw a line in the sand and see where you

603
00:36:11,480 --> 00:36:18,440
are, or if you really want to take your set ops to the next level, if you will, and look

604
00:36:18,440 --> 00:36:20,960
for things like configuration drift and all of that.

605
00:36:20,960 --> 00:36:26,860
You might run this on a continual basis occasionally every now and then, just to see if there has

606
00:36:26,860 --> 00:36:32,980
been any conflict drift in your environment and look at how you could improve it.

607
00:36:32,980 --> 00:36:34,300
I wanted to bring that up today.

608
00:36:34,300 --> 00:36:39,680
If you haven't come across it, well, firstly, you've got to go follow Merrill, at Merrill.

609
00:36:39,680 --> 00:36:44,920
Merrill has great content, but also Merrill posts about Maester and the Maester project

610
00:36:44,920 --> 00:36:45,920
a lot.

611
00:36:45,920 --> 00:36:49,240
There are a ton of other MVPs associated with that.

612
00:36:49,240 --> 00:36:54,120
Sorry, guys, I don't have everyone's names to hand, so I'm not trying to discredit you

613
00:36:54,120 --> 00:36:56,120
in any way or not give you the credit where it's due.

614
00:36:56,120 --> 00:36:59,160
I know this has been a really big community project.

615
00:36:59,160 --> 00:37:02,640
But out of the box, there are a bunch of tests already available.

616
00:37:02,640 --> 00:37:10,200
So the Scuba framework, which is the American CESA agency, has sort of provided that.

617
00:37:10,200 --> 00:37:15,640
There's a bunch of community-built tests for entry and conditional access and things like

618
00:37:15,640 --> 00:37:16,640
that.

619
00:37:16,640 --> 00:37:20,360
I think there are 36 or 37 tests already just out of the box.

620
00:37:20,360 --> 00:37:24,320
Because it's built on Pesta, the Pesta test framework, you can actually go and actually

621
00:37:24,320 --> 00:37:26,440
create your own tests, write your own tests.

622
00:37:26,440 --> 00:37:31,840
So if you're a consultant like I am and you work with customers and there's particular

623
00:37:31,840 --> 00:37:36,160
things you want to check for, you can build those tests yourself.

624
00:37:36,160 --> 00:37:42,440
Or if you work internal to an organization and your environment has some quirks and you

625
00:37:42,440 --> 00:37:45,120
want to build some special tests to look for things like that, you can do that too.

626
00:37:45,120 --> 00:37:46,120
So great project.

627
00:37:46,120 --> 00:37:51,480
Like I said, easy button for continuous testing in your environment.

628
00:37:51,480 --> 00:37:52,480
Called Maester.

629
00:37:52,480 --> 00:37:53,960
Maester.dev is the website.

630
00:37:53,960 --> 00:38:00,000
We will have this information and a link to sort of introduction, intro YouTube video

631
00:38:00,000 --> 00:38:02,640
and the show notes for you to take a look at.

632
00:38:02,640 --> 00:38:03,640
Yeah.

633
00:38:03,640 --> 00:38:05,600
Really great effort.

634
00:38:05,600 --> 00:38:07,600
Yeah.

635
00:38:07,600 --> 00:38:10,240
That brings us to the end of the show.

636
00:38:10,240 --> 00:38:12,840
Man, time flies when you're having fun, right?

637
00:38:12,840 --> 00:38:14,680
Or talking about security.

638
00:38:14,680 --> 00:38:19,280
So you know, a good few interesting few weeks coming up.

639
00:38:19,280 --> 00:38:23,700
We've got Ignite coming up here in, well, next week, actually.

640
00:38:23,700 --> 00:38:26,520
So I'm not sure when we'll publish this.

641
00:38:26,520 --> 00:38:28,120
Probably will be after Ignite.

642
00:38:28,120 --> 00:38:29,440
But we have Ignite coming up.

643
00:38:29,440 --> 00:38:33,800
So in future episodes, there may be some information about what happened at Ignite and some important

644
00:38:33,800 --> 00:38:35,280
takeaways from Ignite.

645
00:38:35,280 --> 00:38:36,280
Definitely.

646
00:38:36,280 --> 00:38:38,080
So be sure to look out for that.

647
00:38:38,080 --> 00:38:39,480
Kost, what do you got?

648
00:38:39,480 --> 00:38:42,440
Anything interesting coming up here in the next couple of weeks?

649
00:38:42,440 --> 00:38:46,400
Well actually, I have a visit to Stockholm coming up.

650
00:38:46,400 --> 00:38:53,680
I'm actually going to ESPC in Stockholm and I was asked to speak there about building

651
00:38:53,680 --> 00:38:58,180
your security data lake with Sentinel and Azure Data Explorer.

652
00:38:58,180 --> 00:39:00,160
So I'm really looking forward to that one.

653
00:39:00,160 --> 00:39:01,160
Yeah, very nice.

654
00:39:01,160 --> 00:39:07,200
We'll definitely share that talk and content once it's all done and does it as well.

655
00:39:07,200 --> 00:39:09,200
So that's some really, really good information.

656
00:39:09,200 --> 00:39:11,440
Summarize it a bit in a future episode.

657
00:39:11,440 --> 00:39:12,440
Yeah, perfect.

658
00:39:12,440 --> 00:39:14,680
Well, thank you folks for listening.

659
00:39:14,680 --> 00:39:20,880
Be sure to like, subscribe on your favorite podcast platform.

660
00:39:20,880 --> 00:39:25,960
You can also catch us if you like video and you like to look at us when we're talking

661
00:39:25,960 --> 00:39:26,960
to you.

662
00:39:26,960 --> 00:39:30,560
You can catch us on the Cloud Architects YouTube channel.

663
00:39:30,560 --> 00:39:35,920
All of the information available in the show notes and associated blog posts.

664
00:39:35,920 --> 00:39:40,760
If you have any tips or sorry, not tips, suggestions, things that you want to see, things that you're

665
00:39:40,760 --> 00:39:46,160
fighting with, grappling with in your environment or things that you're just not sure about,

666
00:39:46,160 --> 00:39:52,080
reach out to us and we'll see what we can do to build an episode around it or to kind

667
00:39:52,080 --> 00:39:53,800
of get you that info.

668
00:39:53,800 --> 00:40:00,320
But until next time, thank you very much for listening and Goose and Goose signing off.

669
00:40:00,320 --> 00:40:01,320
See you next time.

670
00:40:01,320 --> 00:40:24,160
Bye bye.

