詳細検索

Visualize security risks with Microsoft Entra's recommendation function! Ideal for MFA and privilege review

Avatar
by 堤
3 min read

Visualize security risks with Microsoft Entra's recommendation function! Ideal for MFA and privilege review
Translated from 日本語 • View original
堤

Hello! This is Tsutsumi, sales representative of Colorkrew Security. In this article, we will introduce the recommendation features that you can find in the Entra admin center.

**What is the Recommendation Feature? **

Based on security best practices, this function analyzes the configuration status of your own tenants and suggests "next actions".
Official documentation: What are Microsoft Entra recommendations?

You can check what kind of recommendations there are by following the steps below.

(1) Visit the Microsoft Entra admin center
(2) Overview in identity→ recommendations

It even describes the response procedure, so you don't have to know what to do in the end.

**What kind of recommendations do you make? **

It's quick to actually see what's inside, but here is one thing that stands out.

Don't expire passwords

Some people may think, "Isn't it recommended to renew it when it expires?"

However, in operations that require regular updates, it is troublesome to think of and remember a new password every time, and users tend to set simple passwords and change them little by little to respond.

As a result, passwords often remain weak after updates, making it less meaningful to update in practice.

Therefore, it is now recommended that once you set a strong password, you should continue to use that password.

How to Leverage This Recommendation Feature

Each recommendation has a three-level priority: high, medium, and low, so it is recommended to start with the one with a high priority.

In addition, many recommendations are summarized in the following three points, so it is effective to be aware of these and prioritize them.

- Set up MFA (multi-factor authentication)
- Minimize privileges
- Delete unused resources (such as applications and credentials)

Conclusion

In this article, we introduced the recommendation features that you can find in the Entra admin center.

This feature is very effective as an early countermeasure because it allows for easy visibility into security risks.

However, the recommendation function only covers pointing out the current configuration inadequacies. It does not have the ability to detect and notify suspicious behavior or incidents in real time.

Therefore, in order to implement continuous and effective security measures, an operational system (SOC) with a dedicated team is essential.

We provide SOC services for companies using Microsoft 365 and fully support the monitoring and operation of Microsoft environments, including Entra.

In addition to Microsoft 365, we also support the following security products, and by integrating monitoring and operating multiple products, we will strengthen your company's security posture.

・WAF (AWS, AZURE WAF, etc.)
EDR (Cybereason, CrowdStrike, etc.)
SaaS (Slack, Dropbox, etc.)
・Firewall (Fortigate, Meraki, etc.)
・PC operation log (SKYSEA Client) View, LANSCOPE Endpoint Manager, etc.)

If you are a company that wants to achieve a stronger defense while reducing the operational burden of security, please feel free to contact us. Our dedicated team will work with you to find the right security operation for your company.

Related Articles