2.22 Ensure that 'Require Multifactor Authentication to register or join devices with Microsoft Entr

1 votes

I would like to challenge this recommendation.

If imposing MFA on "device registration and joining", wont this interfere with users registering their MFA devices?

I would like to suggest that the optimal choice is:

"Ensure that "Users may join devices to Microsoft Entra" is set to Selected or No."

Users don't typically need to join devices; only admins / selected identities do (albeit a different case for Intune; I think this configuration may interfere).

In any case, I believe that imposing MFA on "device registration" will add more work for Administrators in the long run.

I would also recommend Conditional Access Policies enforcing Device Compliance (Health, EDR, Trusted Networks, etc.) on authentication as well; this will deter attempts to upgrade to a Primary Refresh Token from rogue joined devices (ref. Dirk-Jan M.'s work)

Done Benchmark Community Suggestion Suggested by: Filip Jodoin Upvoted: 18 Feb, '25 Comments: 1

Comments: 1
OldestNewestMost likesFewest likes