Entra Conditional Access - Deep Dive
Blue Security25 Maalis 2025

Entra Conditional Access - Deep Dive

Summary

In this episode of the Blue Security Podcast, hosts Andy Jaw and Adam Brewer delve into the intricacies of Microsoft Entra's conditional access. They explore the fundamental concepts of conditional access, its policies, and the integration of identity management with device management. The discussion highlights the importance of risk assessment, granular control, and the various conditions that can be applied to access controls. The hosts emphasize the significance of compliance policies and the interplay between different security measures to ensure robust protection against potential threats. In this conversation, Adam Brewer and Andy Jaw delve into the complexities of compliance and security in hybrid environments, focusing on access control mechanisms, session controls, and the innovative concept of authentication context. They explore the importance of ensuring devices are compliant and the various strategies organizations can implement to enhance security measures, including the use of approved client apps and continuous access evaluation. The discussion emphasizes the need for a layered security approach to protect sensitive information effectively.

----------------------------------------------------

YouTube Video Link: https://youtu.be/qvfEt49j2qQ

----------------------------------------------------

Documentation:

https://learn.microsoft.com/en-us/entra/identity/conditional-access/overview

https://learn.microsoft.com/en-us/sharepoint/authentication-context-example

https://techcommunity.microsoft.com/blog/microsoft-entra-blog/conditional-access-authentication-context-now-in-public-preview/1942484

https://techcommunity.microsoft.com/blog/coreinfrastructureandsecurityblog/enhancing-security-with-entra-pim-and-conditional-access-policy-using-authentica/4368002

----------------------------------------------------

Contact Us:

Website: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://bluesecuritypod.com

Bluesky: https://bsky.app/profile/bluesecuritypod.com

LinkedIn: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.linkedin.com/company/bluesecpod

YouTube:

⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.youtube.com/c/BlueSecurityPodcast

-----------------------------------------------------------

Andy Jaw

Bluesky: https://bsky.app/profile/ajawzero.com

LinkedIn: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.linkedin.com/in/andyjaw/

Email: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠andy@bluesecuritypod.com⁠

----------------------------------------------------

Adam Brewer

Twitter: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://twitter.com/ajbrewer

LinkedIn: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.linkedin.com/in/adamjbrewer/

Email: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠adam@bluesecuritypod.com

Tämä jakso on lisätty Podme-palveluun avoimen RSS-syötteen kautta eikä se ole Podmen omaa tuotantoa. Siksi jakso saattaa sisältää mainontaa.

Jaksot(326)

Critical infrastructure hacks and rogue AI agents

Critical infrastructure hacks and rogue AI agents

SummaryIn this episode of the Blue Security Podcast, hosts Andy Jaw and Adam Brewer discuss the recent cyberattacks on water systems in Minnesota, attributed to Iran-linked hackers. They explore the v...

11 Elo 54min

Hotel Wi-Fi Hijacks and Border Phone Searches

Hotel Wi-Fi Hijacks and Border Phone Searches

SummaryIn this episode of the Blue Security Podcast, host Andy Jaw and guest Carly Salmon discuss critical issues in data security, focusing on a recent hotel Wi-Fi hack that exploits DNS settings to ...

4 Elo 47min

MDASH in Prod, Intune Sync, OpenAI-Hugging Face Incident

MDASH in Prod, Intune Sync, OpenAI-Hugging Face Incident

SummaryIn this episode of the Blue Security Podcast, hosts Andy Jaw and Adam Brewer discuss significant developments in cybersecurity, including Microsoft's new AI vulnerability scanner, the long-awai...

28 Heinä 50min

Identity Update: Passkeys by Default, Phone Transfers, Physical Key Security

Identity Update: Passkeys by Default, Phone Transfers, Physical Key Security

SummaryIn this episode of the Blue Security Podcast, hosts Andy Jaw and Adam Brewer discuss the upcoming transition to passkeys as the default method for multi-factor authentication (MFA) in Microsoft...

21 Heinä 34min

North Korean IT Worker Scam

North Korean IT Worker Scam

SummaryIn this episode of the Blue Security Podcast, host Andy Jaw delves into the alarming rise of North Korean IT worker scams, exploring their historical context, operational tactics, and the finan...

14 Heinä 48min

Claude Fable, SharePoint RCE, and CISA's KEV list

Claude Fable, SharePoint RCE, and CISA's KEV list

SummaryIn this episode of the Blue Security Podcast, hosts Andy Jaw and Adam Brewer discuss Andy's career transition from Microsoft to Zscaler, the return of the AI model Fable and its user experience...

7 Heinä 22min

Helping or Hurting? - An Honest Conversation About AI

Helping or Hurting? - An Honest Conversation About AI

SummaryIn this episode of the Blue Security Podcast, hosts Andy Jaw and Adam Brewer engage in a deep discussion about the implications of AI on society and the security industry. They explore whether ...

30 Kesä 1h 3min

Your MDM Admin Can Wipe Everything. Are You Protecting Them Like It?

Your MDM Admin Can Wipe Everything. Are You Protecting Them Like It?

SummaryIn this episode of the Blue Security Podcast, hosts Andy Jaw and Adam Brewer delve into the critical topic of Mobile Device Management (MDM) and the associated administrative rights. They discu...

23 Kesä 32min