Introduction

This post is a collaboration with Indefent where you will see the first 5 tips around Microsoft Entra and Intune in my post and the others in his blog post:

http://www.indefent.com/top-10-entra-intune-security-tips/

Let's jump right into it:

1: Intune compliance default setting

First off; Assuming your Intune devices have no compliance policy assigned, how would you imagine they would show up in the portal? Not compliant, right? Well, Microsoft sees this differently.

Intune default compliance logic: devices without an assigned compliance policy are marked compliant or not compliant depending on the tenant setting

To verify/change this behavior go to the Intune compliance settings:

Intune admin center compliance settings: mark devices with no compliance policy assigned as not compliant

Read more:

Intune compliance intro
Intune device compliance explained: compliance policies, Conditional Access, actions for noncompliance, tenant settings and a deployment plan.

2: Entra Authentication Methods

There are still a lot of tenants out there who rely on weak multi-factor authentication methods. Keep in mind, this is the hierarchy in terms of security:

Authentication methods ranked from weakest to strongest: security questions, email, SMS, voice call, Microsoft Authenticator and FIDO2 passkeys

You should configure your enabled Authentication Methods and ultimately force FIDO2 or Passkeys for robust identity security - read more in this dedicated blog post:

Entra Authentication Overview
Microsoft Entra authentication overview: authentication methods, MFA and passwordless options, use cases and security recommendations.

3: Entra Authentication Strength

Multi-factor authentication is mandatory these days. However, as described before, there are weaker and stronger MFA methods. To enforce MFA with Conditional Access we all know this setting:

Conditional Access policy CA01-RequireMFA with the grant control Require multifactor authentication

This setting requires any MFA method, without specific requirements. In Entra we have Authentication strengths to enforce specific methods, such as Phishing-resistant MFA or passwordless options. Microsoft offers these strengths built-in:

Microsoft Entra authentication strengths list with custom and built-in strengths such as phishing-resistant MFA

Use these strengths, instead of "Require multi-factor authentication" in your Conditional Access policies:

Conditional Access grant control using Require authentication strength set to phishing-resistant MFA instead of Require MFA

Read more:

Advanced Conditional Access
Advanced Conditional Access in Microsoft Entra ID: protected actions, authentication contexts and combining Conditional Access with PIM.

4: Entra Log Analytics + KQL

Many customers don't save their logs to an Azure Log Analytics Workspace. In my opinion this should be mandatory, because:

  • Default logs are only stored for 30 days
  • In case of a security incident you need more and better insights
  • Built-in filters and search is poor
  • Use KQL and Azure Workbooks, as shown below for custom reports:

Configure in Entra Health & Diagnostics and connect it to a Log Analytics Workspace:

⚠️
Keep in mind, that for any Azure Log Analytics Workspace you should configure the
-Data Retention: Defines how long logs are stored
-Daily cap: Defines how much data can be ingested per day (will save your budget)
Log Analytics workspace usage and estimated costs page with daily cap and data retention options

Read more:

Logs & Monitoring in Entra ID
Monitor Microsoft Entra ID with logs and workbooks: sign-ins, MFA, Conditional Access and Identity Protection insights, and what to do with the data.

5: Intune Security Baselines

Many customers solely use Intune for device staging and configuration management. However, security should be at top of mind - a modern endpoint security architecture should incorporate the following technologies:

Windows security layers: default settings, security baseline and Defender antivirus, plus BitLocker, firewall, Windows Hello for Business, LAPS and attack surface reduction

Security baselines provide an orientation around security frameworks, that you can follow along. Deep dive into my dedicated post:

Dive into Microsoft Security Baselines
Microsoft security baselines deep dive: updating, deployment methods, Intune baselines, Policy Analyzer and HardeningKitty for Windows hardening.

powered by Oceanleaf

Oceanleaf
Technology blog on Microsoft Cloud. Learn about cutting edge tech, explained simply & straightforward in quality focused blog posts.
You’ve successfully subscribed to Oceanleaf
Welcome back! You’ve successfully signed in.
Great! You’ve successfully signed up.
Success! Your email is updated.
Your link has expired
Success! Check your email for magic link to sign-in.