Mitigating risks of enabling TAP authentication in an Entra tenant?
Mitigating risks of enabling TAP authentication in an Entra tenant?
Mitigating risks of enabling TAP authentication in an Entra tenant?
Re: Mitigating risks of enabling TAP authentication in an Entra tenant?
If the admin changes the account password, the user will only notice if they use their password. Your users should ideally be using Hello or some other passwordless method anyway.
Setting a TAP requires Authentication Administrator rights, which you can restrict behind PIM. You could also send Entra audit logs to your SIEM and generate alerts when a TAP is generated.
Setting a TAP requires Authentication Administrator rights, which you can restrict behind PIM. You could also send Entra audit logs to your SIEM and generate alerts when a TAP is generated.