• Start
  • JohnF@ .
  • Cancel
  • Use App Passwords to Support Active Clients




    Download 78.77 Kb.
    bet7/8
    Sana22.07.2021
    Hajmi78.77 Kb.
    #15678
    1   2   3   4   5   6   7   8

    Use App Passwords to Support Active Clients


    Task

    Detailed Steps



    Complete these steps from an internet-connected Windows computer.

    Enforce MFA for all external users

    1. In your host machine Windows 8 or newer machine, navigate to the Start screen and launch the modern Mail app

    Note: This application uses ActiveSync to connect to a user’s mailbox and will allow us to conduct some quick and easy tests for the app password feature.

    1. In the Mail app, bring up the charms menu on the right, click Settings and Accounts

    2. Click Add an account and click Exchange

    3. Type JohnF@. in the Email address field and pass@word1 in the Password field

    4. Click Connect

    Note: You are unable to authenticate using the on-premises credentials for JohnF; this is because the Exchange ActiveSync protocol does not support multi-factor authentication and consequently cannot allow the user to interact with AD FS to invoke and complete multi-factor authentication.

    1. Click Cancel

    Generate a new app password

    1. In your host machine, start a new Internet Explorer InPrivate browsing session

    2. Navigate to https://myapps.microsoft.com and enter the username JohnF@., you are redirected; sign in to AD FS

    3. Under the Multi-Factor Authentication heading, click Continue and complete the verification

    4. You should now be redirected to the profile page of the Azure Active Directory Access Panel as an authenticated user

    5. Switch to the profile tab

    6. Click Additional security verification

    7. Click app passwords

    8. Click create

    9. Type Windows Laptop in the Name field and click next

    10. Notice that the password generated is 16 characters long, but consists of only letters

    11. Click copy password to clipboard and click close

    Note: There is no way to obtain the generated password again. It can only be deleted.

    Use the app password to set up an Exchange ActiveSync client

    1. Switch back to the Windows Mail app on your host machine

    2. In the Mail app, bring up the charms menu on the right, click Settings, and then click Accounts

    3. Click Add an account, and click Exchange

    4. Type JohnF@. in the Email address field

    5. Paste the app password from the clipboard to the Password field

    6. Click Connect - notice that you are able to successfully authenticate via ActiveSync to the Exchange Online mailbox using the app password

    7. If you are prompted to make your PC more secure, click Cancel, and click Close when prompted

    8. Bring up the charms menu on the right, click Settings and click Accounts

    9. Select the account you just added

    10. Scroll down and click Remove account, click All my synchronised PCs

    Review administrative options for app passwords

    1. On DC1 VM navigate to https://manage.windowsazure.com from a new InPrivate Internet Explorer browsing session and sign in as admin2@.onmicrosoft.com

    2. Click Active Directory in the left navigation menu and click Contoso ...

    3. Navigate to the USERS tab and click MANAGE MULTI-FACTOR AUTH in the command bar

    4. Switch to the service settings tab

    Note: You can enable or disable app passwords for the entire organization, but cannot disable the feature at a more granular level. While you are here, also notice that you can also now specify IP whitelists (trusted IPs) which force Azure Active Directory to suppress MFA challenges when users are authenticating from well-known IP addresses, such as a private corporate network. Notice that you can also now configure Azure Active Directory to supress MFA for all federated users, which serves as a replacement for the claim rule you created in the previous exercise.

    1. Navigate to the users tab

    2. Select JohnF and click Manage user settings

    3. Select the Delete all existing app passwords generated by the selected users and click save and close



    Download 78.77 Kb.
    1   2   3   4   5   6   7   8




    Download 78.77 Kb.

    Bosh sahifa
    Aloqalar

        Bosh sahifa



    Use App Passwords to Support Active Clients

    Download 78.77 Kb.