Skip to main content
conditional access system

conditional access system

Search complete. 16 mentions across 5 episodes found for "conditional access system".

Aug 31, 2026

Andrew CameronGUEST
9:40
where we just made that a mandatory configuration on their device where they had to at least set up a PIN and have that registered as a passkey.
Andrew CameronGUEST
9:48
And from there, it was, that's why, you know, conditional access is such a key technology that we're able to then start to guide our CA policies to have a mandate for requiring only the strong auth methods and start to disable using the weaker methods.
Merill FernandoHOST
10:06
Right.
Merill FernandoHOST
10:06
Nice.

13 MINS LATER

Merill FernandoHOST
23:29
Yeah.
Andrew CameronGUEST
23:30
Yeah, what we do and has worked really well is we just target small groups.
Andrew CameronGUEST
23:36
You know, conditional access policies are great for that, for targeting small groups of users and letting them kind of validate the advanced security experiences that we're rolling out.
Andrew CameronGUEST
23:48
And that becomes immediate feedback because that group, typically security-facing users, are eager and willing to adopt everything that's asked of them.
Merill FernandoHOST
16:46
Because most probably the assumption is that everyone is covered.
Merill FernandoHOST
16:50
The thing that's confusing is conditional access does support nested groups.
Gregor ReimlingGUEST
16:57
Yeah.
Gregor ReimlingGUEST
16:57
And I think this is really also the complex thing about nested groups that you have this limitation.
Gregor ReimlingGUEST
17:02
So I've seen also that you can use it for conditional access and you cannot use this for GSA.
Gregor ReimlingGUEST
17:07
I see also you cannot use it for licensing.
Gregor ReimlingGUEST
17:10
So when you have members in nested groups and assign it to a group which is a less licensed assigned, the nested group members doesn't get the license.

6 MINS LATER

Eric WoodruffGUEST
22:55
I was wondering how they're saying that once, you know, we hit that date and the dynamic group won't process anymore, are you able to still then edit the dynamic group rules if you wanted to change it to some other rule set? Or can you only change it before we hit the...

Unknown podcast

Zimbra Zero-Click RCE, Check Point Bypass, and Device Code Phishing

Aug 24 · 3 Mentions

Mauven MacLeodHOST
15:02
Without it, you've no forensic record of what happened in the event of a compromise.
Mauven MacLeodHOST
15:07
Consider conditional access policies that restrict or flag device code authentication flows, particularly for accounts with access to sensitive SharePoint content.
Mauven MacLeodHOST
15:17
And if your organization is on Microsoft 365 Business Basic or Standard, raise this specifically with your IT provider.
Mauven MacLeodHOST
15:25
We covered conditional access licensing in episode 36 on Thursday, and it's worth revisiting.
Mauven MacLeodHOST
15:31
Conditional access availability varies by license tier, and you need to know where the compensating controls are in place if the full feature set isn't available to you.
Mauven MacLeodHOST
15:41
Three separate threats.
Mauven MacLeodHOST
15:42
One common thread running through all of them.
Videsh ChavanGUEST
20:03
Okay? Then the second was is like, of course, identifying the first baseline.
Videsh ChavanGUEST
20:08
Okay? Like here, uh, we should make conditional access and identity protection as the foundation-
Mirko PetersHOST
20:13
Mm-hmm
Videsh ChavanGUEST
20:13
... not an afterthought, of course.

36 MINS LATER

Mirko PetersHOST
55:48
Uh, cloud native or hybrid?
Videsh ChavanGUEST
55:50
Uh, hybrid.
Mirko PetersHOST
55:52
Uh, compliance policy or conditional access?
Videsh ChavanGUEST
55:56
Conditional access.
Michael GrafnetterGUEST
20:57
They, they should read the, the information written in the dialog window without just automatically clicking the OK button.
Michael GrafnetterGUEST
21:09
So against some, some other attacks, it makes sense to create more advanced conditional access policies, you know.
Michael GrafnetterGUEST
21:17
So not only requiring phishing-resistant authenticators, but also requiring compliant devices and so on, making sure that EDR is really running on that computer, making sure that some permission security hardening is applied on that computer from which a person, and especially a privileged user, is accessing the cloud services.
Michael GrafnetterGUEST
21:41
And I'm, I'm not saying to, to apply such security hardening to, to all of your devices, but s- uh, you should, you should definitely treat devices of global administrators differently than other devices.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.