๐ Secure Bits ๐ก
๐ฆ๐๐ถ๐น๐น ๐ฟ๐๐ป๐ป๐ถ๐ป๐ด ๐๐ต๐ฒ ๐ฑ๐ฒ๐ณ๐ฎ๐๐น๐ ๐๐๐๐ต๐ฒ๐ป๐๐ถ๐ฐ๐ฎ๐๐ถ๐ผ๐ป ๐บ๐ฒ๐๐ต๐ผ๐ฑ๐ ๐ฝ๐ผ๐น๐ถ๐ฐ๐ ๐ถ๐ป ๐๐ป๐๐ฟ๐ฎ ๐๐?
Most tenants I look at still have SMS and Voice call enabled for all users โ left over from the old per-user MFA/SSPR settings, never revisited after the move to the unified Authentication methods policy.
๐ช๐ต๐ ๐๐ต๐ฎ๐’๐ ๐ฎ ๐ฝ๐ฟ๐ผ๐ฏ๐น๐ฒ๐บ:
๐น SMS and voice call are phishable โ SIM swap, real-time relay, or a convincing helpdesk call will get through
๐น If Conditional Access accepts any MFA method, attackers will simply target the weakest one enabled
๐น Old OATH hardware/software tokens left enabled “just in case” widen the attack surface once phishing-resistant methods are already in place
๐ช๐ต๐ฎ๐ ๐๐ผ ๐ฒ๐ป๐ฎ๐ฏ๐น๐ฒ ๐ถ๐ป๐๐๐ฒ๐ฎ๐ฑ:
๐น ๐ฃ๐ฎ๐๐๐ธ๐ฒ๐ (๐๐๐๐ข๐ฎ) โ phishing-resistant, security keys and platform authenticators
๐น ๐ ๐ถ๐ฐ๐ฟ๐ผ๐๐ผ๐ณ๐ ๐๐๐๐ต๐ฒ๐ป๐๐ถ๐ฐ๐ฎ๐๐ผ๐ฟ โ passwordless phone sign-in, nothing sent over SMS
๐น ๐ค๐ฅ ๐ฐ๐ผ๐ฑ๐ฒ โ handy for shared devices and frontline workers
๐น ๐๐ฒ๐ฟ๐๐ถ๐ณ๐ถ๐ฐ๐ฎ๐๐ฒ-๐ฏ๐ฎ๐๐ฒ๐ฑ ๐ฎ๐๐๐ต๐ฒ๐ป๐๐ถ๐ฐ๐ฎ๐๐ถ๐ผ๐ป โ scope it to the group that actually needs it, not all users
๐ ๏ธ ๐ช๐ต๐ฒ๐ฟ๐ฒ ๐๐ผ ๐ฐ๐ต๐ฎ๐ป๐ด๐ฒ ๐ถ๐:
Entra admin center โ Protection โ Authentication methods โ Policies. Enable and target the stronger methods first, confirm adoption, then disable SMS, Voice call, and legacy OATH tokens for “All users.”
โ ๏ธ Check Sign-in logs before you disable anything โ you want to know who still relies on SMS/voice today, or you’ll get a wave of helpdesk tickets tomorrow.
๐ฌ ๐ช๐ต๐ฎ๐ ๐ฑ๐ผ๐ฒ๐ ๐๐ผ๐๐ฟ ๐๐๐๐ต๐ฒ๐ป๐๐ถ๐ฐ๐ฎ๐๐ถ๐ผ๐ป ๐บ๐ฒ๐๐ต๐ผ๐ฑ๐ ๐ฝ๐ผ๐น๐ถ๐ฐ๐ ๐น๐ผ๐ผ๐ธ ๐น๐ถ๐ธ๐ฒ ๐ฟ๐ถ๐ด๐ต๐ ๐ป๐ผ๐ โ still default, or hardened?
Author: Martin Strnad
