Do Any of These Security Features Align with Your Current Needs?
Users suggest that Security Defaults may not align with the needs of larger organizations or those requiring fine-grained control, as Conditional Access Policies offer more flexibility. However, for smaller businesses or those with limited IT resources, Security Defaults can be a sufficient baseline.
Conditional Access Policies vs. Security Defaults
Conditional Access Policies offer more control and customization. Users emphasize that Conditional Access Policies (CAP) provide extensive control over security settings, which is essential for complex environments. "Conditional Access Policies are what an MSP should use as it gives you control and tools to manage this process."
Security Defaults are a good baseline but lack granular control. While Security Defaults are better than no security, they are often seen as insufficient for organizations that need to bypass MFA for specific users or services. "You get no control over security defaults."
Licensing is a consideration for Conditional Access Policies. Implementing CAP typically requires Azure AD Premium P1 licenses for all users covered by the policies, which can be a cost factor for some businesses. "Being very specific, you need an AAD P1 license for every account that's using Conditional Access."
Balancing Security and Usability
Overly strict security measures can hinder productivity. Users report that security features that are too intrusive, such as blocking USB devices or certain websites, can prevent employees from performing their jobs effectively. "I mean, I can't access a USB device, I can't email attachments."
Excessive security can lead to workarounds and increased risk. When security is too cumbersome, users may seek ways to bypass it, potentially creating greater security vulnerabilities. "The problem here is that eventually that can lead to users doing even worse things to circumvent that security."
Security should be proportionate and user-friendly. Effective security balances protection with usability, ensuring that measures are reasonable and don't unduly impede workflows. "Security measures should be reasonable and proportionate."
Specific Security Feature Experiences
Secure Boot and BitLocker can be complex to configure. Users have encountered issues when trying to combine Secure Boot and BitLocker, particularly when Secure Boot modes are incorrectly set. "If Secure Boot is in Setup/Custom Mode during imaging and you change it to User/Standard Mode afterward, the PCR 7 value changes and BitLocker can no longer unseal its keys."
Microsoft security updates can sometimes cause unexpected issues. Some Users have experienced problems with features like File Explorer previews or Quick Assist after Microsoft security updates, requiring workarounds or uninstallation of updates. "File Explorer Preview stopped with the most recent security update (KB5066835)"
Security awareness training platforms vary in effectiveness. While many platforms exist, Users note that the quality and relevance of content can differ, with some finding older content "meh or out of date."
Do these distinctions between Security Defaults and Conditional Access Policies help clarify which might be a better fit for your organization?
No comments yet. Start the conversation.