Entra.Chat

How to Kill SMS MFA in Entra ID Without a Single Script


Listen Later

Louis Mastelinck, a Microsoft MVP and Security Consultant at Proximus NXT, joins me to discuss the critical journey of moving organizations away from SMS-based MFA.

We deep dive into a practical strategy for migrating users to the Authenticator app, starting with β€œstopping the bleed” and managing user groups. We also explore a significant security blind spot regarding Email OTP for SharePoint guest access and how to resolve it.

Finally, we debate the future of authentication with device-bound versus synced Passkeys and how to defend against downgrade attacks.

Subscribe with your favorite podcast player or watch on YouTube πŸ‘‡

About Louis Mastelinck

Louis Mastelinck is a Security Consultant at Proximus NXT and a recognized Microsoft MVP based in Belgium. Specializing in Incident Response and the full Microsoft Security stack (including MDE, MDO, Sentinel, and Identity Management), he is dedicated to neutralizing threats and securing digital environments. A GCFA-certified professional, Louis is known for his deep technical expertise in areas like Conditional Access and authentication methods.

LinkedIn - https://www.linkedin.com/in/louismastelinck/

πŸ”— Related Links

* Microsoft: Hang up on SMS - http://aka.ms/hangup

πŸ“— Chapters

00:00 Intro

00:52 Props and PIM

01:41 The Dangers of SMS MFA

04:51 Strategy: Stopping the Bleed

10:06 Migrating Existing Users off SMS

19:20 Impact on Self-Service Password Reset

22:39 The SharePoint Email OTP Security Gap

25:13 Enabling Entra B2B Integration

34:28 Passkeys: Device-Bound vs Synced

44:40 Defending Against MFA Downgrade Attacks

Podcast Apps

πŸŽ™οΈ Entra.Chat - https://entra.chat

🎧 Apple Podcast β†’ https://entra.chat/apple

πŸ“Ί YouTube β†’ https://entra.chat/youtube

πŸ“Ί Spotify β†’ https://entra.chat/spotify

🎧 Overcast β†’ https://entra.chat/overcast

🎧 Pocketcast β†’ https://entra.chat/pocketcast

🎧 Others β†’ https://entra.chat/rss

Merill’s socials

πŸ“Ί YouTube β†’ youtube.com/@merillx

πŸ‘” LinkedIn β†’ linkedin.com/in/merill

🐀 Twitter β†’ twitter.com/merill

πŸ•Ί TikTok β†’ tiktok.com/@merillf

πŸ¦‹ Bluesky β†’ bsky.app/profile/merill.net

🐘 Mastodon β†’ infosec.exchange/@merill

🧡 Threads β†’ threads.net/@merillf

πŸ€– GitHub β†’ github.com/merill



Get full access to Entra.News - Your weekly dose of Microsoft Entra at entra.news/subscribe
...more
View all episodesView all episodes
Download on the App Store

Entra.ChatBy Merill Fernando

  • 5
  • 5
  • 5
  • 5
  • 5

5

4 ratings


More shows like Entra.Chat

View all
Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

372 Listeners

Risky Business by Patrick Gray

Risky Business

372 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

651 Listeners

The Amp Hour Electronics Podcast by The Amp Hour (Chris Gammell and David L Jones)

The Amp Hour Electronics Podcast

231 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,020 Listeners

Microsoft Cloud IT Pro Podcast by Ben Stegink, Scott Hoag

Microsoft Cloud IT Pro Podcast

62 Listeners

Cybersecurity Today by Jim Love

Cybersecurity Today

179 Listeners

Hacking Humans by N2K Networks

Hacking Humans

315 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

189 Listeners

Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

Defense in Depth

74 Listeners

Practical 365 Podcast - Microsoft 365, Copilot & Cybersecurity News & Discussions by Practical 365

Practical 365 Podcast - Microsoft 365, Copilot & Cybersecurity News & Discussions

9 Listeners

The Azure Security Podcast by Michael Howard, Sarah Young, Gladys Rodriguez and Mark Simos

The Azure Security Podcast

25 Listeners

Cyber Security Headlines by CISO Series

Cyber Security Headlines

139 Listeners

Blue Security by Andy Jaw & Adam Brewer

Blue Security

15 Listeners

Risky Bulletin by risky.biz

Risky Bulletin

44 Listeners