{"id":4123,"date":"2019-01-22T10:36:37","date_gmt":"2019-01-22T09:36:37","guid":{"rendered":"http:\/\/192.168.178.50\/?p=4123"},"modified":"2019-01-22T11:03:35","modified_gmt":"2019-01-22T10:03:35","slug":"4123","status":"publish","type":"post","link":"https:\/\/www.bleuanus.nl\/index.php\/2019\/01\/22\/4123\/","title":{"rendered":"Setup MFA Office365"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">What\nis Multi-Factor Authentication?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Multi-Factor Authentication (MFA)<\/strong>&nbsp;or sometimes\ncalled&nbsp;<strong>two-step verification<\/strong>, is an advanced security layer\nincluded with Office 365 that makes it more difficult for hackers to get access\nand gain control of your account. MFA verifies your identity through a two-step\nprocess before granting you access to online applications. You may already be\nusing MFA to protect online services such as Gmail or Facebook.&nbsp; The two\nverification methods that are usually required to prove your identity are:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>Information you know<\/strong>&nbsp;(like your username and\npassword)<\/li><li><strong>A unique item you have&nbsp;<\/strong>(like your cell phone)<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">When logging in with MFA, you must supply your username\/password&nbsp;<strong>AND<\/strong>&nbsp;prove\nthat you are&nbsp;<strong>in possession of a trusted device<\/strong>&nbsp;(i.e. phone.)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Why MFA?<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Data breaches are becoming more prevalent in today\u2019s always-connected world.\u00a0 It is getting harder to recognize the difference from a legitimate login screen and one that is setup as a\u00a0<strong>phishing<\/strong>\u00a0scheme to steal your username and password. Using MFA provides an\u00a0<strong>additional layer of protection<\/strong>\u00a0for your user account. Should someone guess your password or trick you into providing it by posing as a legitimate source, an attacker will still have an additional barrier preventing them access to company data. Only the user of a registered trusted device can lift this barrier, making MFA the preferred security method.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"> How Does It Work? With MFA, you will need to provide an additional verification method to\u00a0<strong>prove you have access to a trusted device<\/strong>. When logging into company online resources, you will be required to enter your username and password like normal. Then, you may also need to prove that you have access to a trusted device\/phone that you previously registered. Only after\u00a0<strong>completing the additional verification step<\/strong>\u00a0using your trusted device will you be granted access.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"430\" height=\"241\" src=\"http:\/\/192.168.178.50\/wp-content\/uploads\/2019\/01\/image-4.png\" alt=\"\" class=\"wp-image-4124\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">MFA Sign-in Options<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">MFA Sign-in OptionsWith MFA, you will need to provide an additional verification method to prove you have access to a trusted device. The verification methods available with Office 365 and Azure Active Directory can be any of the following:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">With MFA, you will need to provide an additional verification method to prove you have access to a trusted device. The verification methods available with Office 365 and Azure Active Directory can be any of the following:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>Click Approve from a mobile notification (preferred)<\/strong><\/li><li><strong>Enter a code received by SMS text message<\/strong><\/li><li><strong>Answer a registered phone number and press #<\/strong><\/li><li><strong>Retrieve an authorization code from a mobile app\n(similar to an RSA token)<\/strong><\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Keep reading. Instructions for\nconfiguring and logging in with each of these methods are detailed below.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">First Login\nAfter MFA Is Enabled<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Log into your account as you normally would using your username and password. Your first login after MFA has been enabled will require you to setup your additional identity verification methods. To continue click the&nbsp;<strong>Set it up now<\/strong>&nbsp;button.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"269\" height=\"300\" src=\"http:\/\/192.168.178.50\/wp-content\/uploads\/2019\/01\/image-5.png\" alt=\"\" class=\"wp-image-4125\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">You will need to choose the default method you will use to verify your\naccount. We recommend using&nbsp;<strong>the Microsoft Authenticator app<\/strong>&nbsp;on\nyour mobile device that will allow you to simply tap&nbsp;<strong>Approve from a\nmobile notification<\/strong>. In addition to being the most secure method, the\nMicrosoft Authenticator app will also allow you to get the verification code\neven if the device isn\u2019t connected to a cellular network.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You should set up more than\none in case your primary method is unavailable. We also recommend setting up\nyour mobile phone number as your alternate verification phone in case the\nAuthenticator app is not working.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Setup\nMicrosoft Authenticator App<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We recommend\nthis as your default verification option. It is the quickest and easiest way to\ncomplete the login process.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Using this method will require that you download and install the Microsoft\nAuthenticator app on your phone, tablet, or smart watch. The app is available\nfor&nbsp;<a href=\"https:\/\/www.microsoft.com\/es-cr\/p\/microsoft-authenticator\/9nblgggzmcj6?rtc=1&amp;activetab=pivot%3aoverviewtab\">Windows Phone<\/a>,&nbsp;<a href=\"https:\/\/play.google.com\/store\/apps\/details?id=com.azure.authenticator\">Android<\/a>, and&nbsp;<a href=\"https:\/\/itunes.apple.com\/app\/id983156458\">iOS<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Step 1: How should we contact\nyou?<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>Select&nbsp;<strong>Mobile app<\/strong>&nbsp;from\nthe drop-down list.<\/li><li>Select&nbsp;<strong>Receive notifications for\nverification<\/strong><\/li><li>Click&nbsp;<strong>Set up<\/strong>.<\/li><\/ol>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"669\" height=\"411\" src=\"http:\/\/192.168.178.50\/wp-content\/uploads\/2019\/01\/image-6.png\" alt=\"\" class=\"wp-image-4126\"\/><\/figure>\n\n\n\n<ol class=\"wp-block-list\"><li>On your phone or tablet, open\nthe Authenticator app and&nbsp;<strong>add an account<\/strong>.<\/li><li>Specify that you want to add a&nbsp;<strong>work or school\naccount<\/strong>.&nbsp;<em>You may need to allow the Authenticator app permission to\ntake pictures and record video.<\/em>&nbsp;The QR code scanner within the app\nwill then open. If your camera is not working properly, you can select to enter\nyour company information manually.<\/li><\/ol>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"168\" height=\"300\" src=\"http:\/\/192.168.178.50\/wp-content\/uploads\/2019\/01\/image-7.png\" alt=\"\" class=\"wp-image-4127\"\/><\/figure>\n\n\n\n<ol class=\"wp-block-list\"><li>With your mobile device,&nbsp;<strong>scan\nthe QR code<\/strong>&nbsp;displayed on your&nbsp;<strong>computer\u2019s screen<\/strong>&nbsp;to\nregister the mobile app.<\/li><li>Tab&nbsp;<strong>Finish<\/strong>&nbsp;in\nthe mobile app.&nbsp; You should now see an item with a 6 digit code displayed.<\/li><li>Click&nbsp;<strong>Next<\/strong>&nbsp;to\nclose the set up screen.<\/li><li> Ensure that the text next to the Set up button now displays&nbsp;<strong>Mobile app has been configured for notifications and verification codes.<\/strong><\/li><li><\/li><\/ol>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"526\" height=\"64\" src=\"http:\/\/192.168.178.50\/wp-content\/uploads\/2019\/01\/image-8.png\" alt=\"\" class=\"wp-image-4128\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Select&nbsp;<strong>Next<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"169\" height=\"300\" src=\"http:\/\/192.168.178.50\/wp-content\/uploads\/2019\/01\/image-9.png\" alt=\"\" class=\"wp-image-4129\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Step 2: Let\u2019s make sure that we can reach you on your Mobile App device<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>You will now need to approve a\nmobile app notification to continue. A notification screen will open on your\nmobile device asking you to approve your sign in.&nbsp;<strong>Select Approve.<\/strong>&nbsp;After\na brief moment, your web page should continue to complete the login process.<\/li><\/ol>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"179\" src=\"http:\/\/192.168.178.50\/wp-content\/uploads\/2019\/01\/image-11.png\" alt=\"\" class=\"wp-image-4131\"\/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"168\" height=\"300\" src=\"http:\/\/192.168.178.50\/wp-content\/uploads\/2019\/01\/image-12.png\" alt=\"\" class=\"wp-image-4132\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Step 3: In case you lose\naccess to the mobile app<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">At this point, you are\nprompted to setup additional security verification. This is to prevent you from\nbeing locked out if for some reason the Authenticator app is not working\nproperly or you have to replace your phone. Make sure to&nbsp;<strong>use your\nmobile phone number<\/strong>&nbsp;so you can verify your identity wherever you are.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"669\" height=\"399\" src=\"http:\/\/192.168.178.50\/wp-content\/uploads\/2019\/01\/image-13.png\" alt=\"\" class=\"wp-image-4133\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Step 4: Keep using your\nexisting applications<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The mobile\nregistration process creates a default app password for you. Store this\npassword to a safe location and use it for any applications that are unable to\nwork with multi-factor authentication like Outlook, Skype for Business, or\nnative email clients on mobile devices.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">See more about App Passwords\nbelow.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"624\" height=\"177\" src=\"http:\/\/192.168.178.50\/wp-content\/uploads\/2019\/01\/image-14.png\" alt=\"\" class=\"wp-image-4134\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Login With The Microsoft Authenticator App<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>Log in with your username and\npassword as normal.<\/li><li>The next screen will notify you that a notification\nhas been sent to your mobile device to approve your sign-in.<\/li><\/ol>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"252\" height=\"221\" src=\"http:\/\/192.168.178.50\/wp-content\/uploads\/2019\/01\/image-15.png\" alt=\"\" class=\"wp-image-4135\"\/><\/figure>\n\n\n\n<ul class=\"wp-block-list\"><li>On your mobile device, a notification will appear in\nthe notification panel from the Microsoft Authenticator app asking you to\napprove the sign-in.&nbsp;<strong>Select Approve<\/strong>.<\/li><li>You have now successfully\nsigned into your account.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">\n\n\n\nIf your mobile device with the Authenticator app is not available, you\ncan select&nbsp;Sign in another way&nbsp;to choose an alternate\nverification method.\n\n\n\n<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"170\" height=\"300\" src=\"http:\/\/192.168.178.50\/wp-content\/uploads\/2019\/01\/image-16.png\" alt=\"\" class=\"wp-image-4136\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Login\nWith Verification Code From Mobile App<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Microsoft Authenticator\nwill display a 6-digit verification code that changes every 30 seconds. This is\nuseful when your mobile device does not have a data connection or is unable to\nreceive text messages.<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li><strong>Open the Authenticator app<\/strong>&nbsp;on your mobile device.<\/li><li>Enter the current&nbsp;<strong>code displayed in the app<\/strong>&nbsp;and\nclick&nbsp;<strong>Verify<\/strong>.&nbsp; Make sure to leave yourself plenty of time to\nenter the code and click verify before the code changes. Otherwise, you may wait until the next code rotation.<\/li><li>If successful the login will complete.<\/li><\/ol>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"276\" height=\"300\" src=\"http:\/\/192.168.178.50\/wp-content\/uploads\/2019\/01\/image-17.png\" alt=\"\" class=\"wp-image-4137\"\/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"168\" height=\"300\" src=\"http:\/\/192.168.178.50\/wp-content\/uploads\/2019\/01\/image-18.png\" alt=\"\" class=\"wp-image-4138\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Login\nWith Phone Authentication<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Phone authentication can\neither send an SMS text message or call your phone to complete the sign in\nverification.&nbsp; The next screen will notify you that a text or a phone call\nhas been sent to your phone to approve your sign in.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>SMS Code Verification.&nbsp;<\/strong><em>To verify by phone call, see\nbelow.<\/em><\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>Log in with your username and\npassword as normal.<\/li><li>The next screen will notify\nyou that a text has been sent to your phone to approve your sign in.<\/li><li>Once you receive the SMS text\nmessage on your mobile device,&nbsp;<strong>enter the code<\/strong>&nbsp;and click&nbsp;<strong>Verify<\/strong>.<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">\n\n\n\n\n\nIf successful the login will complete.\n\n\n\n<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"276\" height=\"300\" src=\"http:\/\/192.168.178.50\/wp-content\/uploads\/2019\/01\/image-19.png\" alt=\"\" class=\"wp-image-4139\"\/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"168\" height=\"300\" src=\"http:\/\/192.168.178.50\/wp-content\/uploads\/2019\/01\/image-20.png\" alt=\"\" class=\"wp-image-4140\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Phone Call Verification.&nbsp;<\/strong><em>To verify by SMS code, see\nabove.<\/em><\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>Log in with your username and\npassword as normal.<\/li><li>The next screen will notify\nyou that a call is being placed to your phone for sign in verification.<\/li><li><strong>Answer the phone<\/strong>&nbsp;when it rings and&nbsp;<strong>press\n#<\/strong>&nbsp;when prompted.<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">\n\n\n\n\n\nIf successful the login will complete.\n\n\n\n<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"258\" src=\"http:\/\/192.168.178.50\/wp-content\/uploads\/2019\/01\/image-21.png\" alt=\"\" class=\"wp-image-4141\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Changing Verification Options<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">From any Office 365\nweb-browser application,&nbsp;<strong>click on your user logo in the top-right<\/strong>&nbsp;corner\nto expand account options and select&nbsp;<strong>My account<\/strong>.&nbsp;&nbsp;If not\ncurrently in an Office 365 app you can sign in at&nbsp;<a href=\"https:\/\/portal.office.com\/\">https:\/\/portal.office.com<\/a>.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"243\" src=\"http:\/\/192.168.178.50\/wp-content\/uploads\/2019\/01\/image-22.png\" alt=\"\" class=\"wp-image-4142\"\/><\/figure>\n\n\n\n<ol class=\"wp-block-list\"><li>From account settings,\nchoose&nbsp;<strong>Security &amp; privacy<\/strong>.<\/li><li>Then, click&nbsp;<strong>Additional\nsecurity verification<\/strong>&nbsp;to expand additional options.<\/li><li>Now, click&nbsp;<strong>Update your phone numbers used for\naccount security.<\/strong><\/li><\/ol>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"669\" height=\"474\" src=\"http:\/\/192.168.178.50\/wp-content\/uploads\/2019\/01\/image-23.png\" alt=\"\" class=\"wp-image-4143\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">You can now change any of your verification options and set the default method. Our recommendation is to select&nbsp;<strong>Notify me through the app<\/strong>as the default option and use your mobile as the Authentication phone and your Office phone if it will reach you directly or by dialing an extension.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>What is Multi-Factor Authentication? Multi-Factor Authentication (MFA)&nbsp;or sometimes called&nbsp;two-step verification, is an advanced security layer included with Office 365 that makes it more difficult for hackers to get access and gain control of your account. MFA verifies your identity through a two-step process before granting you access to online applications. You may already be using [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-4123","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/www.bleuanus.nl\/index.php\/wp-json\/wp\/v2\/posts\/4123","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.bleuanus.nl\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.bleuanus.nl\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.bleuanus.nl\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.bleuanus.nl\/index.php\/wp-json\/wp\/v2\/comments?post=4123"}],"version-history":[{"count":2,"href":"https:\/\/www.bleuanus.nl\/index.php\/wp-json\/wp\/v2\/posts\/4123\/revisions"}],"predecessor-version":[{"id":4148,"href":"https:\/\/www.bleuanus.nl\/index.php\/wp-json\/wp\/v2\/posts\/4123\/revisions\/4148"}],"wp:attachment":[{"href":"https:\/\/www.bleuanus.nl\/index.php\/wp-json\/wp\/v2\/media?parent=4123"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.bleuanus.nl\/index.php\/wp-json\/wp\/v2\/categories?post=4123"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.bleuanus.nl\/index.php\/wp-json\/wp\/v2\/tags?post=4123"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}