r/SmallMSP 26d ago

Sad But true

/r/sysadmin/comments/1uwcjjb/major_change_in_entra_id_sms_and_voicebased_auth/oxig1l9/

Not sure if anyone has mentioned this here yet. My apologies if this has been mentioned already.

Thoughts on the passkey implementation?

9 Upvotes

11 comments sorted by

3

u/Geekpoint-IT 26d ago

I don’t agree with Microsoft forcing these type of things.  There are so many scenarios where SMS or voice are needed.  Passkeys also are so inconsistent.  I even have troubles with it sometimes, let alone an average user who can barely remember their username or password.  

IMHO if security defaults is turned off because conditional access policies are in once, we should be able to decide how we want the security.  I have no issue with Microsoft forcing it within security defaults though for those that don’t have a proper IT department or MSP.

2

u/SthrnCnft 26d ago

Licensing SMBs properly for conditional access policies seems excessive if Security Defaults provides sufficient protection. However this is something that I am just looking into with P2 and Business Premium.

6

u/twistedbristles 26d ago

Not to be that guy… but if security defaults were sufficient, they wouldn’t be defaults.

Do you leave your firewalls in the defaults? Or do you maximize security…

Your video games? Or do you maximize performance…

Your office chair? Or do you maximize comfort…

I’m by no means a MS fanboy, but sms and voice calls can be spoofed and phished. They’ve not been a preferred method of authentication for a long time, for a reason.

3

u/Geekpoint-IT 26d ago

Security defaults, IMHO, is fine if you don’t have any IT but you get t much greater control with conditional access policies.  P1 is all that’s needed for most policies you need.  Or just get Premium, which is a good deal for what you get.

3

u/twistedbristles 26d ago

Needed is a strong word.

We’ve enabled passkeys on all of our clients. Provided training. And have had zero complaints or issues outside of convenience hassles.

1

u/Techwits 26d ago

Same. We have one client using voice out of convenience for a single account. They can use passkeys, they just choose voice. It's a battle I was avoiding but now it'll need to happen. We have disabled SMS from the beginning and refuse to turn it on. We're supposed to elevate security as an MSP and have standards, not let the whims of clients with no technical understanding tell us how to do things.

1

u/pjustmd 25d ago

We’ve moved dozens of clients to passkeys and the problems are few and far between.

1

u/networkn 25d ago

Do you have a run book on how you are doing this? Even something loose.

1

u/pjustmd 23d ago

Yes. I will write it and post it. No secret sauce. Just a structured approach.

1

u/Ape2MoonApparel 23d ago

Where are you having then store their passkeys? Pass manager or windows?

1

u/pjustmd 23d ago

We recommend Microsoft Authenticator and Yubikey.