Block That Flow – Device Code Flow in Microsoft Entra ID

As you read this, I’m at the Xchange Security Conference in Dallas, and I learned something yesterday that I must share to protect your data. I will need to work with you to block device code flow in Microsoft Entra ID. In simple terms, it’s disabling a code system that’s similar to how you match a code on two devices when signing into Netflix.

Device code flow is typically used to sign into accounts on devices such as smart TVs or IoT devices. You enter the short code displayed on the device into a separate device, such as your smartphone or computer, to complete the authentication process.

It’s super convenient, but it also poses security risks, particularly related to phishing attacks. Attackers can exploit this flow to gain unauthorized access to accounts without needing to steal credentials directly. It’s especially critical to prevent phishing attacks.

Microsoft advises organizations to block device code flow unless absolutely necessary. This should help mitigate the risk of phishing attacks. At the same time, we will need to help you implement conditional access policies to control and restrict the use of device code flow. This includes specifying when and where it can be used.

We can tailor conditional access policies based on factors such as user location, device status, and risk assessments. This allows you to enforce specific security measures that align with your needs and compliance requirements. This approach enhances security by ensuring that only authorized users can access sensitive information.

Some of things we’ll discuss with you are:

  1. Determining which users or groups need specific access controls based on their roles or functions.
  2. Setting conditions based on the factors mentioned above. For example, you might require MFA for users accessing data from untrusted locations.
  3. Choosing the appropriate access controls, such as blocking access, requiring MFA, or enforcing device compliance.
  4. Testing all of your policies in a report-only mode to assess their impact without affecting users.
  5. Continuously monitoring the effectiveness of the policies and make adjustments as necessary based on user feedback and security incidents.

Call us – 973-433-6676 – or email us to discuss how to block the flow and develop access control policies for your specific needs.

Not All Cloud Storage is a Backup

We tend to use the terms data storage and data backup interchangeably. It can be a costly mistake.

Cloud storage is all about easy access to files. It’s not only your access, but also collaborative access that allows teams of people to work on projects together without the need to email various versions. Cloud storage servers such as Microsoft OneDrive, Google Drive, and Dropbox allow team members to be online at the same time and see changes to files in real time. They also allow a single user to access files from anywhere in the world where you can get an internet connection.

Stored files typically are not encrypted or protected with any special technology, and that makes them vulnerable to theft and ransomware attacks. If just one team member has lax security, such as an easily cracked password or uses an unsecured public network, all those stored files are exposed. Further, it could open someone up to SIM swapping.

How should you store your data? We like Microsoft’s Conditional Access, an access management solution that enforces security policies by bringing together real-time signals from users, devices, locations, and applications to block, allow, or require additional verification steps to access resources.

It works on a granular level. For example, you can set limits on which countries someone can log into your system. You can limit IP addresses. Steps like these can provide extremely useful insurance against worldwide hacker organizations that take advantage of local weaknesses in our global networks.

Installing and configuring the right access limits for your needs is not something you should attempt by yourself. There are myriad variables to the conditions that limit access, and if you make a mistake, you could lock out access to people who need it. If that happens, you’ll need an IT professional to undo the problems and reconfigure your system.

How should you back up your data? The short answer is to use specific backup technology. It makes a copy of files in storage and then encrypts them for protection. In the event of a cyberattack, a system outage or some other disaster, the encrypted files are used to restore the files to your system.

We can help you set up and configure both Microsoft Conditional Access and a backup program to keep you safely up and running. We can also provide the training needed to maintain both systems. Call us – 973-433-6676 – or email us to set up an appointment to design a coordinated plan that best meets your needs.