๐ Secure Bits ๐ก
๐ ๐ถ๐ฐ๐ฟ๐ผ๐๐ผ๐ณ๐ ๐๐ถ๐น๐น ๐ฏ๐น๐ผ๐ฐ๐ธ ๐ฎ๐ฐ๐ฐ๐ฒ๐๐ ๐ ๐ถ๐ฐ๐ฟ๐ผ๐๐ผ๐ณ๐ ๐ฏ๐ฒ๐ฑ ๐ฎ๐ฑ๐บ๐ถ๐ป ๐ฝ๐ผ๐ฟ๐๐ฎ๐น๐ ๐๐ถ๐๐ต๐ผ๐๐ ๐ ๐๐. Are you ready?
Microsoft announced that sign-ins to the Microsoft 365 Admin Center ๐๐ถ๐น๐น ๐ฟ๐ฒ๐พ๐๐ถ๐ฟ๐ฒ ๐ ๐๐ โ ๐ rollout startedย Feb 3, 2025, andย from Feb 9, 2026ย password-only sign-ins will be blocked. Accounts without MFA will simply ๐ฏ๐ฒ ๐ฑ๐ฒ๐ป๐ถ๐ฒ๐ฑ ๐ฎ๐ฐ๐ฐ๐ฒ๐๐.
โ ๏ธ This may sounds obvious โ but in many tenants, this will catch many administrators of guard if youโre not prepared.
๐ช๐ต๐ ๐๐ต๐ถ๐ ๐บ๐ฎ๐๐๐ฒ๐ฟ๐:
๐น Admin portals are one of the highest-value targets in Microsoft 365
๐น A single compromised admin account can lead to tenant takeover, data loss, or persistence
๐น By doing this, Microsoft is removing the last excuse for โweโll enable MFA laterโ
๐ช๐ต๐ฎ๐โ๐ ๐ฟ๐ฒ๐ฎ๐น๐น๐ ๐ต๐ฎ๐ฝ๐ฝ๐ฒ๐ป๐ถ๐ป๐ด:
๐น MFA will be enforced at sign-in time, not just โrecommendedโ
๐น Legacy admin habits (password-only, shared admin accounts) will simply stop existing
๐น If you havenโt updated emergency access accounts according to Microsoftโs latest recommendation, they will not be usable
๐๐ผ๐ ๐๐ผ ๐ฝ๐ฟ๐ฒ๐ฝ๐ฎ๐ฟ๐ฒ (๐ฑ๐ผ ๐๐ต๐ถ๐ ๐ป๐ผ๐):
๐ ๏ธย ๐๐ป๐ณ๐ผ๐ฟ๐ฐ๐ฒ ๐ ๐๐ ๐ณ๐ผ๐ฟ ๐ฎ๐ฑ๐บ๐ถ๐ป๐ ๐ฒ๐
๐ฝ๐น๐ถ๐ฐ๐ถ๐๐น๐
โข Spread the word that this is happening amongst other admins
โข Use Conditional Access and target privileged directory roles
โข Require MFA for all admin roles, not just Global Admins
๐ก๏ธ ๐๐ถ๐
๐๐ผ๐๐ฟ ๐ฏ๐ฟ๐ฒ๐ฎ๐ธ-๐ด๐น๐ฎ๐๐ ๐ฎ๐ฐ๐ฐ๐ผ๐๐ป๐๐
โข Break-glass accounts should each have a different form of MFA
โข Use: FIDO2 security keys, Certificate-based authentication, Software TOTP on FIDO2 key
โข A long password alone is not enough anymore
โข Quick start:ย use the Conditional Access templateย โRequire multifactor authentication for Microsoft admin portalsโand tailor it to your needs
โ ๏ธ ๐ง๐ฒ๐๐ ๐๐ผ๐๐ฟ ๐ฎ๐ฐ๐ฐ๐ฒ๐๐
โข Validate all admins can access Microsoft 365 portals before this is out
โข Verify emergency accounts work before you really need them
โ Treat this change as a forced ๐๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ ๐ต๐๐ด๐ถ๐ฒ๐ป๐ฒ ๐ฐ๐ต๐ฒ๐ฐ๐ธ. If MFA breaks your admin access, the problem isnโt Microsoft โ itโs your security posture.
๐ฌ ๐๐ผ ๐๐ผ๐ ๐ฎ๐น๐ฟ๐ฒ๐ฎ๐ฑ๐ ๐ต๐ฎ๐๐ฒ ๐ ๐๐-protected admin access and break glass accounts, or are you still relying on passwords? Let us know.
๐๐ถ๐ต๐ฉ๐ฐ๐ณ ๐ฐ๐ง ๐ต๐ฉ๐ฆ ๐ฑ๐ฐ๐ด๐ต: Martin Strnad
