Soldato
- Joined
- 30 Sep 2005
- Posts
- 16,736
Hi all,
Has anyone enabled 2FA for their Office365 users?
My main two questions really are:
1. If a hacker has managed to get hold of a users username and password, what is to stop them inputting their own mobile number to recieve the code?
2. Can you customize the setup form to only allow the users mobile number which is stored in AD (therefore preventing the issue in Q1)?
anything else to think about?
We have users at work who keep filling in their username and passwords into spam sites. Unfortunately a small number get through exchange, and of those a small few have links which get through our firewall. Between the time an email goes around the company and the time our firewall team can block the link 20 or so users have filled in the form!
Thanks!!
Has anyone enabled 2FA for their Office365 users?
My main two questions really are:
1. If a hacker has managed to get hold of a users username and password, what is to stop them inputting their own mobile number to recieve the code?
2. Can you customize the setup form to only allow the users mobile number which is stored in AD (therefore preventing the issue in Q1)?
anything else to think about?
We have users at work who keep filling in their username and passwords into spam sites. Unfortunately a small number get through exchange, and of those a small few have links which get through our firewall. Between the time an email goes around the company and the time our firewall team can block the link 20 or so users have filled in the form!
Thanks!!