Microsoft MFA Lockdown: SMS and Phone Call Options are Going Away

computer g0a8b51607 1920

twofactor - mfa graphicWe recommend you apply MFA to everything you possibly can. It’s especially important on Office 365 as Microsoft’s data says almost all of their account breaches would have been prevented had MFA been properly enabled (but only if you don’t have MFA fatigue or click when you shouldn’t have). While MFA isn’t foolproof, it’s still a requirement for many cyber insurance policies and you won’t be able to get covered (or could have a claim denied) if MFA is not setup properly at your business.

One of the earliest forms of MFA was getting text messages (SMS) or automated phone calls to verify identity. While SMS-based MFA is better than no MFA, it’s still not nearly as secure as other MFA methods. SMS messages are much easier than other methods to intercept to spoof. And because they are well-established and aren’t really adaptable technologies, there’s not a whole lot than can be done to harden SMS MFA.

Microsoft is eventually going to be completely turning off SMS and Phone MFA options in the future (they’ve already made it a non-preferred method in Office 365 and Azure). Since we want to make sure our clients are as secure as possible, we are going to be working with our clients over the next several months to migrate away from SMS-based MFA to using app-based authentication (using the Microsoft Authenticator app) or hardware-based MFA (using something like a Yubikey of some sort). Many folks are already using the Microsoft Authenticator app, but this audit will make sure that we get SMS disabled and secure things up the best we can. You will be hearing from your lead technician and account manager as we work out way through that roll out.

Facebook
Twitter
LinkedIn
Categories
Archives