MFA guides
Multi-factor authentication — proving identity with more than just a password. See the glossary entry →
36 guides touch on mfa.
- Adding a named location without breaking Conditional Access
How to add or change a named location in Entra without breaking Conditional Access: MFA and risk side effects, the report-only sequence, the egress-IP trap.
- App consent policies and the admin consent workflow
How to stop consent phishing without blocking legitimate apps: Entra ID app consent policies, the admin consent workflow, and a review process that scales.
- Business Email Compromise response playbook
How to respond to a confirmed BEC incident in Microsoft 365 — containment, investigation, remediation, and prevention.
- Compromised Microsoft 365 account response runbook
Compromised Microsoft 365 account runbook: what to run in the first fifteen minutes, what to check in the first hour, and when it is safe to hand it back.
- Conditional Access break-glass account design
How to design break-glass accounts that survive every Conditional Access disaster — credentials, monitoring, and recovery.
- Conditional Access for Microsoft 365 admin accounts
Conditional Access policies for admin accounts: phishing-resistant MFA, managed devices, short sessions, no legacy auth, plus exclusions and rollout order.
- Cross-Tenant Access Settings design
How to design Cross-Tenant Access Settings (CTAS) — the foundational trust controls for B2B and cross-tenant collaboration.
- Cross-tenant synchronization in Entra ID
Cross-tenant synchronization auto-provisions B2B guests between Microsoft Entra ID tenants in a multi-tenant organisation.
- Entra External ID vs Azure AD B2C
Microsoft has two products for customer identity. Here's the difference and which to pick today.
- Entra ID authentication contexts
Authentication contexts let Conditional Access trigger step-up authentication for specific actions, not just specific apps.
- Entra ID B2B guest access
How Entra ID B2B brings external users into your tenant as guests — invitations, controls, and lifecycle.
- Entra ID Conditional Access design
Designing a Conditional Access baseline: the policies, the principles, the order to write them in, and the habits that keep the estate healthy.
- Entra ID passwordless authentication
The realistic options for going passwordless in Microsoft 365 — Authenticator, FIDO2, Windows Hello, and passkeys.
- Entra ID Privileged Identity Management
PIM turns standing admin access into just-in-time, approval-gated activation. The model, what it covers, role settings that work, and a rollout that sticks.
- How to require MFA for all users with Conditional Access
How to require MFA for all users in Entra ID with Conditional Access: the exclusions that matter, report-only rollout, registration campaign, enforcement.
- How to reset MFA for a user in Entra ID
How to reset a user's MFA in Entra ID when they have a new phone or lost their authenticator: re-register, revoke sessions, and issue a Temporary Access Pass.
- Intune compliance policies and Conditional Access
Combining Intune compliance with Conditional Access gives you device-aware access control — the heart of zero trust.
- Investigating a suspicious sign-in with Entra sign-in logs
How to work a suspicious sign-in in the Entra sign-in logs: which log, which columns matter, traveller vs attacker, and when to escalate to compromise.
- Microsoft 365 admin role design
How to design admin role assignments for least-privilege Microsoft 365 administration at scale.
- Microsoft 365 administrator roles
The Entra ID admin roles that gate Microsoft 365 administration — and how to assign them with least privilege.
- Microsoft 365 for small business
How to choose, set up, and run Microsoft 365 in a small business — the plan, the basics, and the security baseline.
- Microsoft 365 incident response runbook
A structured incident response runbook for Microsoft 365 — detection, triage, containment, eradication, recovery, lessons.
- Microsoft 365 Lighthouse for MSPs
Microsoft 365 Lighthouse is the multi-tenant management portal for managed service providers running many SMB tenants.
- Microsoft 365 security and compliance
A practical tour of the Microsoft 365 security and compliance stack — Defender, Purview, Entra, and how they fit together.
- Microsoft 365 security baselines
The minimum security configuration every Microsoft 365 tenant should have — and how to get there.
- Microsoft 365 tenant audit checklist
A practical checklist for auditing a Microsoft 365 tenant's configuration, security posture, and compliance.
- Microsoft Entra ID Recommendations
The Entra ID Recommendations dashboard surfaces tenant-specific improvement actions based on Microsoft's analysis.
- Microsoft Entra Verified ID
Entra Verified ID is Microsoft's decentralised identity / verifiable credential service. Here's the model and the use cases.
- OneDrive Personal Vault
What OneDrive Personal Vault is, why it exists only in consumer OneDrive, and the equivalent protections for sensitive files in a work or school tenant.
- PIM operational playbook
How to run Privileged Identity Management as a working process — onboarding, activation, approvals, and audit.
- Ransomware preparedness for Microsoft 365
How to harden a Microsoft 365 tenant against ransomware — prevention, detection, response, and recovery.
- SAML SSO with Entra ID
How to set up SAML single sign-on between a third-party app and Microsoft Entra ID.
- Setting up Microsoft 365 from scratch
The setup order for a brand-new Microsoft 365 tenant — tenant, domain, identity, security baseline, then data and clients. Sequence matters more than speed.
- Teams Rooms deployment and management
How to plan, deploy, and operate Microsoft Teams Rooms at scale — devices, accounts, policies, and the Pro Management Portal.
- Token protection and token theft in Microsoft 365
Token theft has become a leading attack pattern. Here's how it works and what Microsoft 365 offers to defend against it.
- What is Microsoft Entra ID?
What Microsoft Entra ID is: the identity service behind every Microsoft 365 sign-in, how it relates to Active Directory, and the licensing tiers that matter.