Deploy or validate your identity and access
To prevent bad actors from using Copilot to more quickly discover and access sensitive data, the first step is to prevent them from gaining access. You must ensure that:
- Users are required to use strong authentication that can't be compromised by guessing user passwords alone.
- Authentication attempts are evaluated for their risk and have more requirements imposed.
- You can perform reviews of access granted to user accounts to prevent oversharing.
Getting started with Microsoft 365 E3
Microsoft 365 E3 includes Microsoft Entra ID P1 licenses. With this plan, Microsoft recommends using common Conditional Access policies. Conditional Access policies at their simplest are if-then statements. In other words, if a user wants to access a resource, then they must complete an action. For example: If a user wants to access an application or service like Microsoft 365, they must first perform multifactor authentication to gain access.
Microsoft Entra Conditional Access analyzes signals such as user, device, and location to automate decisions and enforce organizational access policies for resource. You can use Conditional Access policies to apply access controls like multifactor authentication (MFA). Conditional Access policies allow you to prompt users for MFA when needed for security and stay out of users' way when not needed.
Microsoft provides standard conditional policies called security defaults that ensure a basic level of security. However, your organization might need more flexibility than security defaults offer. You can use Conditional Access to customize security defaults with more granularity and to configure new policies that meet your requirements.
Planning your Conditional Access policies in advance and having a set of active and fallback policies is a foundational pillar of your Access Policy enforcement in a Zero Trust deployment. Take the time to configure known network locations in your environment. Even if you don't use these network locations in a Conditional Access policy, configuring these IPs informs the risk of Microsoft Entra ID Protection.
Create Conditional Access policies from Conditional Access policy templates
Common conditional access policies can be created from conditional access policy templates, which Microsoft 365 provides. Microsoft 365 organizes Conditional Access policy templates into the following categories:
- Secure foundation. Microsoft recommends these policies as the base for all organizations.
- Zero Trust. These policies as a group help support a Zero Trust architecture.
- Remote work. These policies help secure organizations with remote workers.
- Protect administrator. These policies are directed at highly privileged administrators in your environment, where compromise might cause the most damage.
- Emerging threats. Policies in this category provide new ways to protect against compromise.
Since the focus of this training is on Microsoft's Zero Trust architecture that supports both Microsoft 365 and Microsoft 365 Copilot, let's take a look at the Zero Trust conditional access templates. They include:
- Require multifactor authentication for admins
- Securing security info registration
- Block legacy authentication
- Require multifactor authentication for all users
- Require multifactor authentication for guest access
- Require multifactor authentication for Azure management
- Require multifactor authentication for risky sign-ins (Requires Microsoft Entra ID P2)
- Require password change for high-risk users (Requires Microsoft Entra ID P2)
- Block access for unknown or unsupported device platform
- No persistent browser session
- Require approved client apps or app protection policies
- Require compliant or Microsoft Entra hybrid joined device or multifactor authentication for all users
- Require multifactor authentication for admins accessing Microsoft admin portals
- Block access for users with insider risk (Requires Microsoft Purview)
If you create conditional access policies based on any of these templates, ensure that you include Microsoft 365 Services and your other SaaS apps in the scope of the policies.
If your environment includes hybrid identities with on-premises Active Directory Domain Services, be sure to deploy Microsoft Entra Password Protection. This capability detects and blocks known weak passwords and their variants and can also block more weak terms within passwords that are specific to your organization.
Next steps with Microsoft 365 E5
Microsoft 365 E5 includes Microsoft Entra ID P2 licenses. Organizations with an E5 subscription should implement Microsoft's recommended set of Conditional Access and related policies, including:
- Require MFA when sign-in risk is medium or high.
- Require high risk users change their password (applicable when you aren't using passwordless authentication).
For more information about implementing protection for identity and access based on your licensing plan, see Increase sign-in security for hybrid workers with MFA.
Microsoft 365 E5 and Microsoft Entra ID P2 both include more protection for privileged accounts. Microsoft recommends implementing the capabilities summarized in the following table.
| Capability | Resources |
|---|---|
| Privileged Identity Management (PIM) | Provides protections for privileged accounts that access resources, including resources in Microsoft Entra ID, Azure, and other Microsoft Online Services such as Microsoft 365 or Microsoft Intune. See Plan a Privileged Identity Management deployment. |
| Microsoft Purview Privileged Access Management | Allows granular access control over privileged Exchange Online admin tasks in Microsoft 365. It can help protect your organization from breaches that use existing privileged admin accounts with standing access to sensitive data or access to critical configuration settings. See Privileged access management overview. |
Finally, you should consider implementing access reviews as part of your overall Just-Enough-Access (JEA) strategy. Access reviews enable your organization to efficiently manage group memberships, access to enterprise applications, and role assignments. User's access can be reviewed regularly to make sure only the right people have the appropriate continued access.