Overview
Join Bob Salmans as he takes a look at how to enable MFA within Azure AD and discusses which options are available. He'll also explore passwordless authentication, as well as its options and how to configure it.
Recommended Experience
- An understanding of concepts taught in Microsoft Security, Compliance, and Identity Fundamentals is recommended
Related Certifications
- Microsoft Identity and Access Administrator
Related Job Functions
- IT Security Professionals
- Microsoft Cloud Operations Professionals
- Microsoft Security Compliance Managers
Bob Salmans has been a CBT Nuggets trainer since 2020. He has received certifications from Cisco, Microsoft, VMware, Offensive Security, and more. His expertise areas include networking, network security, cybersecurity, information security, systems administration, and virtualization.
Multi-Factor Authentication
In this video, we discuss what MFA is and some of the options we have for using MFA within Azure AD.
Knowledge Check
The free version of Azure AD does not include the use of MFA. True or false?
Deploying MFA in Azure AD
In this video, we dive into Azure AD and learn how to enable per-user MFA and associated settings like App Passwords.
Knowledge Check
Which of the following can be set up and used to bypass MFA for legacy applications?
Manage and Troubleshoot MFA
In this video, we take a look at how to manage MFA on a daily basis and perform some common tasks, like re-setting up MFA for a user. We also look at some tools we can use to troubleshoot MFA login problems.
Knowledge Check
An administrator can require a user to re-register their MFA directly from Azure Active Directory. True or false?
User Authentication Options
In this video, we discuss some options for user authentication other than a simple username and password.
Knowledge Check
Which of the following is not an option for passwordless authentication within Azure AD?
Implementing Passwordless Authentication in Azure AD
In this video, we implement passwordless authentication in Azure AD.
Knowledge Check
Azure AD only supports using FiDO2 security keys for passwordless authentication. True or false?
Self-Service Password Reset
In this video, we set up SSPR and its options.
Knowledge Check
Which of the following is not an option to authenticate when resetting your password?
Password Protection and Smart Lockouts
In this video, we use Password Protection and Smart Lockouts to increase the security of our logins.
Knowledge Check
Which of the following is the default lockout duration for accounts when using Smart Lockouts?
Certificate-Based Authentication in Azure AD
In this video, we're going to discuss what certificate-based authentication in Azure is, how it works and why we would want to use it.
Knowledge Check
Using CBA requires that we have access to some sort of PKI. True or false?
Setting Up Our PKI
In this video, we're going to install certificate services so that we can issue certificates to users.
Knowledge Check
When deploying our PKI it's ok if we choose to use a Standalone CA over an Enterprise CA. True or false?
Generating a User Certificate
In this video, we're going to generate and install a user certificate that will be used to authenticate our user to Azure via certificate-based authentication.
Knowledge Check
What type of certificate did we generate?
Configuring CBA In Azure
In this video, we're going to configure certificate based authentication within Azure and test it out.
Knowledge Check
Which two binding policies did we configure within Azure AD for CBA?
Configure Azure AD User Authentication for Azure Windows VMs
In this video, we're going to set up Azure AD user authentication for Windows Azure VMs.
Knowledge Check
Which two roles will allow you to log into an Azure VM using Azure AD credentials?
Configure Azure AD User Authentication for Azure Linux VMs
In this video, we're going to set up Azure AD user authentication for Linux Azure VMs.
Knowledge Check
In which two ways can you log into an Azure Linux VM with Azure AD credentials?
Conclusion
I hope this has been informative for you and I would like to thank you for consuming.
View Transcript
Multi-Factor Authentication
0:06It's time to talk about multifactor authentication,
0:09or MFA.
0:11Now MFA is far superior than simply
0:14using a username and password, and guess who agrees?
0:17That's right, Microsoft, and they've built it into Azure.
0:20So it's time to jump in and talk about multifactor
0:23authentication a little bit more and see what options we
0:26have within Azure.
0:29All right, so what is multifactor authentication?
0:32If you're not familiar with it, it's using multiple factors
0:36to authenticate.
0:37So instead of just a username and a password,
0:41we're going to use an additional factor of authentication.
0:45Now what are factors of authentication?
0:47Well, there's three of them.
0:49And these are all something--
0:51so I'm going to put that up here something.
0:54And that is something you know.
0:58So what is something you know?
0:59Well, it could be a password, or it
1:02could be a PIN that you know, maybe
1:05your PIN to your debit card or something
1:07like that, but that is something you know.
1:09It's also something that you have.
1:12So in this instance, it could be that you have a YubiKey--
1:18and that's just like a USB key that
1:22is used for authentication, so you can plug it in
1:25and that can authenticate you.
1:27It could be that on your cell phone
1:29that you have an app, like an authenticator app,
1:32and that generates a PIN that you enter,
1:35and it rotates that pin every 60 seconds or whatever.
1:39But it's something that you have.
1:40It's a physical something that you have.
1:43Or it's something that you are.
1:46So here, we're talking really about biometrics.
1:49So it could be a retinal scan of your eye,
1:54or it could be a fingerprint scan, so you got there,
1:58or it could be a palm scan.
2:00That's a great hand, by the way.
2:02So it could be a palm scan, but it is
2:05something you are biometrics.
2:06So something you know, something you have, something you are,
2:09and multifactor-- that's what we're doing here.
2:12So something you know would be a password,
2:15but we need another factor-- maybe a USB, a YubiKey,
2:18or an authenticator app, or some type of biometrics
2:22check to validate you are who you say you are.
2:25Now multifactor-- it is far more secure than a simple password.
2:30That is very true, and that's because it's passwords--
2:33well, passwords are constantly being fished.
2:36There's phishing going on all the time,
2:39and passwords are exposed, and there's data breaches,
2:42and within those breaches, oftentimes, passwords
2:46are identified, and then those are put out there
2:49on the dark web out there for everyone to see or purchase
2:55or download or something.
2:57But the idea is passwords are breached all the time,
3:00and a lot of them are out there, and people reuse passwords.
3:03So that's another thing, password reuse-- not cool.
3:06So multifactor helps to address all of those things.
3:12Now, when deploying multifactor authentication,
3:15do you just turn everybody on at once?
3:17Well, generally not.
3:18You do some type of phased approach,
3:22where you're turning on individuals
3:24or groups of individuals.
3:26So you have a first group over here,
3:28and then you have a second group, and this way,
3:30your first group is really kind of your test group
3:32to make sure everything goes OK, and then you go ahead
3:35and you roll it out.
3:36So who's in this first group?
3:37That's the real question.
3:38Who should we put in this first group?
3:42Well, we really want to make sure all of our admins
3:45have MFA turned on first.
3:47So we want them in our first group to really test out.
3:50Plus they;re tech savvy.
3:51They're the folks working with it anyway.
3:53They're going to be able to troubleshoot and find problems.
3:55But our admins should be some of the first folks up here leading
3:59the pack when deploying MFA.
4:02Now what about different methods of authentication?
4:05We talked about using apps on your phones,
4:08or YubiKeys, things like that.
4:10But what options do we have within Azure?
4:14And so when it comes to Azure, we really
4:16have four primary options.
4:19I'm going to put 1 through 4 down here.
4:21And the first one is a phone call.
4:24So you could actually have an automated service call
4:27your phone, then you answer it, and it tells you a PIN number
4:30to enter.
4:32But in order for this to work, you
4:34have to have your phone number in your user account attributes
4:40because that is where the service is going
4:44to look up your phone number.
4:45And if there is no phone number there, guess what?
4:47They're not going to be able to call you.
4:49And then we have texting as well,
4:52and that can go through an app that is registered,
4:55or it could be to your phone number,
4:57but if it's to your phone number,
4:58again, you got have a phone number registered.
5:00Then we have a mobile app, and there are different mobile apps
5:04you can use.
5:05Microsoft Authenticator is a good one to use.
5:08Google has an authenticator.
5:09There's multiple out there.
5:11But the idea is you can use that mobile app,
5:13and the service can send you a message that you can approve.
5:17So basically, you get this message that says,
5:19do you want to allow this log in?
5:21And you either approve or disapprove
5:24and you just hit the button.
5:25Or along this mobile app, we're going to go down here--
5:29it's still a mobile app, but it is a code
5:33or a PIN from the mobile app.
5:35So you open your mobile app, and you have a PIN that rotates,
5:38and this number that rotates every 60 or 90 seconds,
5:42basically you're going to need to enter that
5:43into an application, where you're
5:46going to have your identifier, your PIN
5:48here, and that rotates, so you're
5:50going to have to enter that, and that
5:53will be your additional factor of authentication.
5:55So we've got a couple of different options within Azure.
5:59Now let's talk about licensing.
6:02So with multifactor authentication in Azure,
6:05what licenses do you have to have?
6:07Well, let's find out.
6:09All right, here we are on Microsoft's documentation.
6:11We're looking at "Features and licenses for Azure AD
6:13Multi-Factor Authentication.
6:15Now we're going to scroll on down here.
6:16They talk about a couple of different things,
6:18but I want to go down to "Feature comparison
6:20based on licenses."
6:22Now your Azure AD free comes with multifactor
6:26authentication.
6:26All of these features come with your basic multifactor
6:30authentication, even the free.
6:31That's what I really want to point out.
6:33So if we go down here and look at the different features,
6:36though, we see that we have "Protect your Azure AD tenant
6:39admin accounts with MFA."
6:41This is also your general accounts.
6:42Don't think it's not because it didn't say general accounts
6:45or anything like that, but it does include it,
6:46and I'll show you in the documentation
6:48here in just a minute.
6:49Also allows you to use the mobile app,
6:51like your Microsoft Authenticator,
6:53as a second factor.
6:56But if you want to use features like phone call or SMS
6:58like texting you have to have your Azure AD
7:02Free for global admin-- so that's only
7:05for your global admins.
7:07But if you go to Office 365 licensing, and you'll see
7:10it's included for everyone there.
7:12So that would be good as well.
7:13As well as Azure AD Premium one, your P1 and P2.
7:16And there's different features as we scroll
7:19down here that you can look at.
7:20But I just want you to realize that your standard MFA,
7:23like we've talked about using the authenticator app-- hey,
7:26that's included for everyone.
7:27And as we scroll down here, Microsoft
7:30does recommend that you use conditional access,
7:33and that's something we're going to talk about
7:35not in this set of videos, but in the next set in this course.
7:39So we're going to get to that.
7:41And as we scroll down here, I wanted to show you--
7:44here we go, Azure AD Free tier.
7:47All users in an Azure AD Free tenant
7:50can use security MFA by using the security defaults.
7:55And that's turned on by default, and we've
7:56talked about that earlier.
7:58So there you go.
7:59Now the thing is the mobile authenticator app
8:01is the only method that can be used for your multifactor
8:05when using MFA in the Azure AD Free security default.
8:09So just keep that in mind.
8:11Even if you just got the free version,
8:13hey, you can still use MFA with the authenticator app.
8:17So that is something good.
8:18And hey, I prefer the authenticator app.
8:20It's so easy to use.
8:23So there we go with MFA.
8:24That's kind of the basics of it-- just a good review--
8:27and then looking at some of the options you can use
8:29and the licensing required for those options in Azure.
8:32But in the next Nugget, we're going
8:34to be deploying MFA in Azure Active Directory,
8:37so I look forward to seeing you there.
8:39I hope this has been informative for you,
8:41and I'd like to thank you for viewing.
Deploying MFA in Azure AD
0:00[MUSIC PLAYING]
0:06Now that we've had a little refresher on MFA
0:08and discussed some of the features
0:10that Azure provides us within MFA,
0:12and even looked at the licensing requirements for MFA,
0:15it's time to jump into the Azure portal.
0:18And let's turn on some MFA already.
0:21Here we are in the Azure portal.
0:23I'm going to jump over to Azure Active Directory.
0:26Here we are in our Nugget labs tenant in our Azure Active
0:29Directory.
0:30Now, what we're going to do is we're
0:32going to deploy something called per user MFA,
0:36because we're going to turn it on per user.
0:38Pretty straightforward.
0:40So we're going to go under Users here.
0:42Excellent.
0:44And we see over here per user MFA.
0:46We're going to go ahead and click on that.
0:48It's going to open up a new tab here.
0:50Now, when it comes to deploying multifactor authentication
0:53in Azure AD, it is a 2-step process.
0:56Number one, we have to turn it on for the user.
0:58Number two, the users have to go through the enrollment process
1:02to set it up.
1:03And it's just a little wizard-- super simple.
1:05And they'll be prompted to do so when they log in.
1:09So how do we turn this on already?
1:11Here we go-- per user MFA.
1:13We come down here.
1:14Look at all of our users here.
1:16I want to show you this real quick.
1:17Multifactor authentication status we see is disabled.
1:21And we go all the way down, and we do have one-- that's me.
1:24I'm enabled already, but the other users are disabled.
1:28So how do we turn them on?
1:29Well, you can just click on that and say enable.
1:33It's that simple.
1:35So we're going to go ahead and turn this on for any Oracle.
1:38And you don't have to do it just for one, though.
1:40You could like select multiple, see?
1:41So we could go through here and select all of those
1:43and say enable, or we can select everything.
1:46Whoa, whoa, whoa, whoa, whoa?
1:48What happened?
1:48My enable MFA disappeared.
1:50Yes, because I've selected me, and I'm enabled already,
1:55so that changes this.
1:56So be careful when you do that.
1:58Don't select the folks that are already enabled.
2:00So I would want to disabled me-- there we go--
2:02and enable is back.
2:04There we go.
2:05So let's go ahead and click on Enable here.
2:07And it says about enabling MFA.
2:10They give you a link to a nice deployment guide
2:13so you can read up on it if you want to.
2:15But here's something very important.
2:17If your users do not regularly sign in through the browser--
2:21because that's where they're prompted
2:22to go ahead and enroll in MFA--
2:24you can send them this link.
2:27So you would want to copy this link to your--
2:29and email it to your users, because if they're not
2:33logging in through a browser, well,
2:35they're not going to get the option to enroll.
2:37And basically, we'll just come down here
2:39and say enable multifactor authentication,
2:41but I'm not going to do that.
2:43All you do is click that.
2:44I'm not going to do that for all these users
2:45because I don't need to.
2:47So let's deselect it.
2:48Why'd it deselect everybody?
2:49Let's go through here and deselect these folks here.
2:52I want to show you something else here.
2:55Now, let's go down to me and click me.
2:58Now, once it's enabled, I can go in here and I can disable it.
3:03So if you want to disable MFA for a user or users,
3:07just come in here and disable it.
3:08But then we have something that says enforce.
3:11Now, what is enforce?
3:13Now, enforce forces the users to register for MFA the next time
3:17they log in with a browser.
3:19Because when you turn this on, your users
3:22have the opportunity to bypass the setting up
3:26or enrollment for 14 days.
3:28But you can do enforce and force them to enroll.
3:31However, this will affect legacy applications
3:35that don't support MFA.
3:36So if you run on something like Outlook 2012 for some reason--
3:40I know know-- you have a reason to run an old version--
3:43and it doesn't support MFA, guess what?
3:45You're not going to be able to log in using MFA,
3:49so you're going to have a problem there.
3:50And at that point, we have to create something called an app
3:53password, which is a password that allows you to bypass MFA
3:58for your legacy applications.
4:02And we're going to look at doing that here shortly,
4:04but here, we have manage user settings.
4:07And if I was to click someone else-- you see--
4:10that is disabled, all I get is manage user settings.
4:13So let's go ahead and I'm going to deselect any Oracle.
4:15And look at these manage user settings.
4:17If I click on that, I have three options here.
4:19The first one is require users to provide contact methods.
4:24Again, this forces them--
4:25next time they log in-- to provide their contact
4:28information-- again, their contact methods.
4:30So if you need to redo that for some reason, you can do that.
4:35Delete all existing app passwords
4:37generated by the selected users.
4:39Now, those app passwords are when we enable MFA
4:43and we need to still use legacy applications.
4:45So that's sort of those app passwords that we create.
4:48You can delete them all for a user if you want to,
4:50and you can restore MFA authentication
4:52on all remembered devices.
4:54kl if you've had a user go through multiple devices
4:57and they switch back to another one,
4:59you can restore MFA for that.
5:01So those are your options there under Manage user settings.
5:04So as you see, it's really simple to turn it on,
5:07which is superb because we don't like complex things-- at least,
5:10I don't like complex things.
5:12I like to keep it simple.
5:14Let's go up to the top here and look at service settings.
5:19We'll click on that up here, and there we go.
5:21Hey, look, there's our app passwords.
5:23So this is allow users to create app passwords
5:26to sign into non-browser apps, so we're talking to legacy apps
5:30here, really.
5:30So if you're not running legacy apps,
5:32you could just say don't allow users to create app passwords
5:35because you don't need them.
5:36But if you are-- and we're talking about legacy Microsoft
5:39apps--
5:39something old like Outlook 2012 or something-- and you
5:43need to use apps passwords, then this is an option.
5:46And when the user registers or enrolls
5:48in multifactor authentication, they
5:50will have an option there to create an app password,
5:53or app passwords if they have multiple applications.
5:56So that's pretty cool.
5:57That's where we turn those settings on and off.
6:00And as we come down here, we have trusted IPs.
6:03This is pretty cool.
6:04So this allows you to skip multifactor authentication
6:07for requests from federated users on any internet.
6:11So this is when we're talking about our Federated.
6:13Users.
6:13So if you have on premise users, and you've
6:16done a federation from your local Active Directory
6:19to Azure, you can actually skip MFA authentication
6:23from these trusted IPs.
6:25So what would you do?
6:26Well, you put in your office IP addresses, really,
6:28is what you would put in here.
6:30And that way-- like your public IPs,
6:32as it's going to go out across the internet
6:34and authenticate to office, or portal, or endpoint,
6:38whatever you're accessing in Microsoft.
6:41But once you put those in there, you
6:43can actually allow your users to skip MFA
6:46because they're coming from a trusted IP address,
6:48so that's pretty interesting.
6:50And as we scroll down here, we also have verification options,
6:55and these are how the users can use MFA.
6:59And you see call to phone is grayed out,
7:01and that's because I don't have any phone numbers entered
7:05into anybody's attributes, so I can't use call to phone there.
7:10But I have text message to phone, notification
7:13through mobile app, verification code.
7:15And really, I like to select all these, and here's why.
7:18When a user goes through the enrollment,
7:20they get the option to choose which one of these
7:23they want to use.
7:24However, if I want to force something--
7:27say I want them to use notification
7:28through the mobile app, I would deselect these.
7:30Then when the enrollment process comes along for a user,
7:33that's the only option that they have.
7:36If you want to give them multiple options,
7:38go ahead and select other verification options here.
7:41So that's where these come into play.
7:43Pretty cool.
7:44And then lastly, we have remember
7:45multifactor authentication on trusted devices.
7:49Now, this I do like because a trusted device
7:53is a device that's enrolled in Azure Active Directory.
7:56So that's what our trusted device is.
7:58And what we can do is if we click on this,
8:00and allow users to remember MFA on devices they trust--
8:05this is between 1 and 365 days-- what
8:06this does is it allows them to no longer use MFA.
8:11They'll authenticate with MFA the first time,
8:14but then it's going to be remembered, so they won't
8:16have to on that trusted device.
8:18And here for 90 days, which is the default.
8:21But if you want them to use MFA every time they log in,
8:23do not enable this.
8:25But you can if you would like to.
8:27There may be certain individuals who you don't want to use MFA,
8:30and so that is how we can enable that feature.
8:33And then you would just come down here and just
8:35click on Save.
8:37Now, I want to tell you about something,
8:39and this is Microsoft's recommendation.
8:43I'm going to go back here to Users real quick.
8:45This is where we enable our per user MFA.
8:48Microsoft does not recommend you use this.
8:52If-- I want to put a big if out there--
8:55if you're using conditional access policies--
8:58now, conditional access policies we're
9:00going to talk about in the next skill, which
9:02is the next set of videos in this course.
9:04And the conditional access policy
9:05is basically where you set up a rule.
9:07And the rule says, if you're using this application,
9:09you have to use MFA.
9:10Or if you're using this application
9:13from this type of device, you don't have to use MFA,
9:15or you know what I mean?
9:17So what we're doing is these conditional access
9:19policies can influence how MFA is used.
9:22So what you could have then is a conflict.
9:25So you don't want to use per user MFA and conditional access
9:29policies.
9:30Just keep that in mind.
9:31You could end up with some big headaches,
9:33and nobody likes a big headache.
9:35And there we go.
9:36That's how to turn on, enable, configure, look at the settings
9:39for per user MFA in Azure Active Directory.
9:42I hope this has been informative for you,
9:43and I'd like to thank you for viewing.
Manage and Troubleshoot MFA
0:00[MUSIC PLAYING]
0:06All right, now that we have enabled MFA for our users
0:10within Azure Active Directory, we are all done with MFA.
0:15Well, not exactly.
0:17We know that MFA, and really anything,
0:20isn't set it and forget it.
0:22We need to manage our MFA.
0:24There's going to be times when we need to troubleshoot MFA.
0:27Well, that's what we're going to look at right now--
0:29our day-to-day management of MFA, and troubleshooting.
0:33Here we are in our Azure portal.
0:35We're going to go to Azure Active Directory.
0:37And we're in our NuggetLabz tenant, as usual.
0:40Now, here we go.
0:42Guess what?
0:43We're going to go over to Users because Annie Oracle-- well,
0:47guess what Annie did?
0:49Well, she lost her phone.
0:50That's right.
0:52And she went and got a new one.
0:54So she had to reinstall her authenticator app.
0:58And guess what?
0:59She installed it, but since she didn't
1:02have a backup of her settings, well, we
1:05need to re-setup Annie Oracle with MFA.
1:08How do we do that?
1:09Well, we're going to go into Annie Oracle.
1:11We're going to go down to authentication methods, down
1:14here on the left.
1:14We're going to click on that.
1:16And here at the top, we're going to click on require re-register
1:20MFA.
1:21Click it, there we go, operation complete.
1:24It's that simple.
1:25Next time Annie logs in through the browser, well,
1:28she's going to have to re-register for MFA.
1:31And at that point, she can re-setup her authenticator app.
1:34It's that simple.
1:36But you can also go in here and revoke MFA sessions.
1:41So if I click on this, it's going to revoke the session.
1:44So any active sessions that she has, through an MFA,
1:48it's going to terminate those sessions,
1:50forcing her to re-authenticate.
1:52Now, why would you want to do that?
1:54Because this, I see--
1:55she lost her phone, got a new phone,
1:57and she needs to re-sign up.
1:58Well, what if we find out that she lost her phone,
2:03and that was on Friday.
2:05This is Monday.
2:05She gets a new phone, needs to register.
2:07But we've seen sessions logging in over the weekend.
2:11So somebody has been able to use her phone
2:13to log in with her MFA app.
2:15So that means we have a compromise.
2:16Well, boom.
2:17We go there, we revoke the MFA sessions,
2:19that knocks the user out.
2:21At which point, we would want to go ahead and probably change
2:24her password, because that would stop that from happening.
2:28And then we could go ahead and have her re-sign up for MFA.
2:32We'd have to go ahead and do that, as well.
2:33OK, so we see those are there.
2:36So that's our management of MFA.
2:39Now, let's look at troubleshooting.
2:41Let's go over here to NuggetLabz.
2:44And we're going to go down and click on--
2:46where'd it go?
2:47Sign-in logs, there we go.
2:49And it's going to take this a minute to load.
2:51There we go, excellent.
2:52So these are our sign-in in logs, pretty straightforward.
2:55But if someone's having problems logging in with MFA,
2:58this is where we can come to get some clues to troubleshoot.
3:01So let's look at me.
3:02Now here, I logged into the portal.
3:05And I'm using MFA.
3:07I see success, success, interrupted, failure.
3:10Failure, hmm, failure-- all right.
3:12OK.
3:13So let's look at success real quick.
3:14We're going to click on this.
3:16It's going to open this up.
3:17I'm going to go over to the authentication details page.
3:20There we go.
3:21And here we go.
3:23It says here under result detail--
3:24let's see if I can't spread this out a little bit--
3:28the other direction, there we go.
3:30MFA requirement satisfied by the claim in the token.
3:33So MFA was successful.
3:35That tells me that when I logged in, MFA was used
3:38and it was successful.
3:39OK.
3:40But what if it wasn't successful?
3:41Let's go take a look at a failure.
3:43So let's open this one up, and the authentication details.
3:47First major-- result detail, that's
3:50what I'm looking at here.
3:51And there we go--
3:52MFA requirement satisfied, requirement satisfied, OK.
3:56So the MFA stuff, I'm not seeing an error or anything.
4:00But if I go over to the basic info,
4:02failure region is right here.
4:04Password changes required due to account risk.
4:08OK, so there was something going on with my account risk.
4:10And we're going to actually get into that at a later point.
4:14But this is where we can find a failure reason.
4:18So there we go.
4:19This is how we can troubleshoot MFA logins.
4:22If we're having people failing to log in, usually
4:25a specific user, we come in here, look at the reason,
4:27and figure out, well, why is this happening?
4:30How can I fix this?
4:32So there's that one.
4:33There's also this one, this interrupted one.
4:34Let's take a look at that one.
4:36Let's see-- go to authentication details,
4:41it says MFA requirements were satisfied.
4:43So let's go back to the basic info--
4:45status was interrupted, additional details--
4:48this is an expected part of the login flow, when
4:52user is asked if they want to remain signed into this browser
4:55and make further logins easier.
4:57So when you see something like this,
4:59evidently it's not a big problem, right?
5:01It says it's normal.
5:02But here is actually a way to launch a sign-in diagnostics
5:07tool, which is really cool.
5:09So we can troubleshoot the event.
5:11So this is additional troubleshooting.
5:12There is a sign-in diagnostics tool.
5:14Let's go ahead and click that, open it in a new tab,
5:17and take a quick peek at this sign-in diagnostics tool.
5:21So diagnose and solve problems, sign-in diagnostics review,
5:25sign-ins.
5:26And this is the one that I had clicked, the interrupted.
5:30And it's actually running diagnostics, and it finished.
5:33It says, sing-in error details.
5:35It says, this occurred due to keep
5:38me signed in is interrupted when the user was signing in.
5:41OK, so what happened is I re-signed in again
5:43on top of myself because I had opened an incognito window.
5:47And that's what caused that interruption.
5:50But this is an additional tool that you
5:52can use to troubleshoot, sign-in diagnostics-- pretty handy.
5:55So that's how we manage our day-to-day MFA activities,
5:58and troubleshoot MFA signings.
6:01I hope it's been informative for you,
6:02and I'd like to thank you for viewing.
User Authentication Options
0:06We know that using usernames and passwords
0:09alone isn't really all that secure anymore.
0:12And hey, MFA came to the rescue and is
0:15able to help us with that.
0:17But is that our only option?
0:19Well, the answer to that is--
0:21well, you'll see shortly.
0:24All right, teaser is, is that the only option?
0:27The answer is no, because we know passwords--
0:31they're weak.
0:32They're always being fished, they're compromised,
0:34they're put out there on the dark web
0:37for everybody to look at.
0:39And it's just not that good.
0:41So MFA made us do something-- made
0:45us smile because it brought security to our authentication.
0:48But is that the only option?
0:51No-- an astounding no.
0:54Now I'm going to throw something at you.
0:56Ready?
0:57Passwordless.
1:01Passwordless?
1:02Passwordless?
1:02Hmm.
1:04No matter how you say it, it's kind of confusing, right?
1:07Well, how can I log in without a password, even with MFA?
1:10I had to put in a username and then a password,
1:14and then some type of other authentication mechanism--
1:20a third part of this.
1:22But if I'm not using a password, well how does this even work?
1:26Well, you're about to find out, and it's pretty cool.
1:30So Microsoft provides us with three passwordless options,
1:34and you've already heard of some of these.
1:36You might not have realized, though,
1:38that they can be used in this way.
1:40The first one is Windows Hello for Business.
1:46So Windows Hello for Business can be used.
1:50What about the Microsoft Authenticator app?
1:52We've been talking about that.
1:55So there's our Microsoft Authenticator app.
1:57And something else we can use is, like we
1:59had mentioned, a YubiKey.
2:01Well, that is part of FIDO.
2:03And we're talking here FIDO2.
2:06And FIDO as Fast Identity Online.
2:09It's an open standard used for passwordless authentication.
2:12So Windows let's just use all of these things.
2:17All right, way to go.
2:19Now let's talk about each of these a little more in depth.
2:22Not too crazy-- just a little bit though.
2:24All right, starting off--
2:25Windows Hello for Business.
2:27Now this is built into Windows 10 and later.
2:33So if you're using Windows 10 and later, then, hey,
2:36you are good to go.
2:37And this allows us to use biometrics.
2:40That's what Windows Hello allows us to do.
2:43I like saying it like that--
2:44Hello.
2:45It allows us to use biometrics, so we can do things
2:49like a facial scan or a fingerprint scan,
2:51and once you authenticate with Windows Hello for Business,
2:54Azure AD, what it does is-- so we'll put your computer down
2:58here, and we'll put a big smiling face,
3:00because you did a facial rec ID, and you
3:04did that out there to our Azure appear in the cloud.
3:08And what happens is Azure then gives your device
3:11this cool little token.
3:13And there we go, that's our little token there.
3:15And with that token, you can continue to authenticate
3:18to Microsoft's Cloud Resources.
3:20So that is how it works, in a very simplified manner.
3:24But Windows Hello for Business is your first option.
3:28Then we [INAUDIBLE] Microsoft Authenticator app,
3:30and again, that's when we have our phone here,
3:32and we get that MS Authenticator app.
3:34And a couple of different ways we can use it-- number one,
3:37we can use what's kind of like a push message.
3:40So when we need to authenticate, a message
3:42is pushed to our phone, and it says,
3:44do you want to accept this login or approve the login?
3:48You're going to say approve or disapprove.
3:50Or you can use the PINs, the rotating PINs,
3:54that are in here-- that's P-I-N, there we go.
3:56And remember, those rotate every so often, like 60
4:00to 90 seconds, they'll rotate.
4:01So you can enter that PIN into an application for the field
4:04there.
4:05So again, this is another way that we can go passwordless.
4:09You don't need a password because you
4:10can use either the push notification or the PIN,
4:13and away we go.
4:14And then lastly, our FIDO2 security keys--
4:16this is kind of what they look like.
4:18It is a little USB--
4:20looks like a USB thumb drive, really--
4:22and you just plug it in, and it has some digital certificates
4:25on there that authenticate you as who you are.
4:28So what we do, then, is in our computer,
4:30we have to plug that thing in, and once it's plugged in,
4:33we go to authenticate.
4:35It can be used to authenticate us,
4:37but we don't have to necessarily plug it in.
4:41They also work via Bluetooth and NFC.
4:45NFC is Near Field Communication.
4:47So there are a couple of wireless options
4:49for some of these FIDO2 keys.
4:51But again, this comes down to something you have--
4:54remember, we talked about that, something you are,
4:56something you know, something you have?
4:58This is something you have, and I actually have one of these,
5:01and it actually has a little box here,
5:04and it allows you to do fingerprint reading.
5:07So not only is it something that you have,
5:10it's also something that you are.
5:12So this is like a dual-purpose FIDO2 key.
5:15So that's pretty interesting.
5:16You can use those as well.
5:18Now the thing about this is the authenticator app-- guess what?
5:21The authenticator-- we'll put that up here.
5:23Authenticator app-- it is how much?
5:26That's right, it's free to use, free to download for use.
5:30When we come up with our Windows Hello--
5:32so our Windows Hello, well, guess what?
5:35It is free to use.
5:37It's built into the operating system.
5:38But when it comes to these keys, they're not free,
5:42and they range in price.
5:43So they could be anywhere from, if you
5:45buy in bulk from like 12 bucks, but they
5:47can go up to like 40 bucks.
5:49So when you're deploying this solution,
5:52if you want to use these keys, well,
5:54if you've got 1,000 employees, that's going to be pricey.
5:58And guess what?
5:59People lose keys.
6:00You have to replace them.
6:01You have to manage them.
6:03Are they a good way to increase security?
6:05Yes.
6:05But guess what?
6:06So is, like, the authenticator app,
6:09and it's not going to cost you anything.
6:11So that is a downside of the FIDO2 keys--
6:13it's something else to manage, and they do cost.
6:17So there you go.
6:19So that is how we can use passwordless authentication--
6:23well, at least what it is and some options we have.
6:26In the next Nugget, we're going to see
6:28exactly how do we turn this on in Azure AD so our users can
6:33use passwordless.
6:35I hope this has been informative for you,
6:36and I'd like to thank you for viewing.
Implementing Passwordless Authentication in Azure AD
0:06Now that we know what passwordless is,
0:09and how we can use it, how it can help us further
0:11secure our environments.
0:13And we even know some of the options
0:14that we can use such as Windows Hello, our authenticator
0:18app, or FIDO2 keys within Azure Active Directory.
0:21So now that we know this stuff, let's
0:23put our knowledge to work.
0:25Let's go set this up.
0:28All right.
0:28Here we are.
0:30And we are in Microsoft Endpoint Manager.
0:34What are we doing in here?
0:36All right, here we go.
0:37Here's the down low folks.
0:39When you want to use Windows Hello for Business,
0:42well, that's part of a device.
0:43That's part of the operating system living on that device.
0:47So in order to use Windows Hello for Business,
0:49you need to have Intune licenses.
0:51And Intune is the device management product
0:55from Microsoft.
0:56So that's why we are in the Endpoint Manager Admin Center.
1:00Now we're going to set up Hello for Business.
1:04That's right.
1:05So here we go.
1:06We're going to click on Devices over here.
1:08There we go.
1:09Then we're going to scroll down to Enroll Devices.
1:12And where is it?
1:13There it is under Device Enrollment, Enroll Devices.
1:16And here we go.
1:17Now that we're in here, on the right over here,
1:20look for Windows Hello for Business.
1:22And here it is.
1:23So replace passwords with strong two-factor authentication.
1:27If we don't have a password, we are using passwordless.
1:31That's right.
1:31So we're replacing passwords with this strong two-factor
1:35authentication.
1:35I'm going to click on that.
1:37All right.
1:38Here's how we enable this.
1:40So what we're doing is really creating a Windows Hello
1:42for Business kind of policy.
1:44We're going to set some options down here.
1:46So I'm going to go ahead and go down here to Configure Windows
1:51Hello for Business.
1:51And it is enabled.
1:53And then I want to-- now, I could
1:56say disabled or not configured, but it's enabled
1:59because I want to enable it.
2:00Use a TPM, a Trusted Platform Module.
2:04You say required or preferred.
2:06Now, what is a TPM?
2:07Now, a TPM module is an actual chip or module
2:12on the motherboard of computers.
2:14And what it does is it stores cryptographic information
2:16like certificates.
2:18And these are used to verify and validate software
2:21running on computers.
2:23And so I don't know if it says anything
2:24in here about what they do, but what they do is they sit there.
2:27They got certs on them, right, certificates and digital keys.
2:30And what it does is it will check
2:33to make sure that prior to the operating system loading,
2:36that the pre-boot firmwares and softwares running are
2:40legitimate.
2:41So you don't have things like rootkits running.
2:44And also, some TPM modules will offload
2:47cryptographic operations to help save CPU cycles.
2:51But the idea is they're there to make sure
2:53that is a trusted firmware and software
2:56that's running on there.
2:58OK.
2:59There we go.
2:59So we're going to go ahead and say
3:01required because TPM modules are on most computers these days.
3:05Then we're going to come up with a PIN length.
3:08So we've got to have a PIN number.
3:09So this PIN, it's not just a number.
3:11It's a PIN because there are also
3:13characters and digits and letters and such.
3:16So we need to define the complexity characteristics
3:19of our PIN.
3:20So our minimum and maximum PIN length,
3:22I don't think I want 127-character PIN,
3:24let me tell you.
3:26Lowercase letters, says not allowed, allowed.
3:28You can say allowed or required.
3:30We can say required, we can day required.
3:32We can make this thing as complex
3:35as could be if you wanted to.
3:37Or you don't have to.
3:39And then the PIN expiration in days,
3:41how long do you want the PIN to be good for?
3:44And then as we scroll down here, the next one
3:47is remember PIN history.
3:48And if you've ever configured a password complexity
3:50requirements group policy in an on-premise domain controller,
3:55you'll see many of these are the same kind of thing.
3:57So your expiration of days, the history,
3:59so people can't reuse their PINs.
4:01Allow biometrics for authentication,
4:03so here's if you want to use a fingerprint
4:04scan or a facial recognition.
4:07Yeah, why not?
4:08And then, use enhanced spoofing when available.
4:11Yes.
4:11And this is a feature for Microsoft.
4:13Don't know if this is a whole lot about it.
4:14But it uses some intelligence like machine
4:18learning kind of thing, AI.
4:20And what it does is it tries to identify spoofing,
4:22and it'll block spoof attempts.
4:24If this is set to yes.
4:25Well, of course, I want the additional protection.
4:28Allow phone sign in.
4:30And this is a way for users to use their phone as a companion
4:35for their desktop.
4:36And they can actually use their phone
4:38as part of the authentication process
4:40if you want them to allow that.
4:42Now, one thing about that, though, if you do
4:45allow it, what if somebody loses their phone?
4:47You've got to go through the setup process again.
4:49It's just something to consider.
4:51And then lastly, use security keys for signing.
4:54And either yes or no.
4:56And the security key, that's those FIDO keys.
4:58That little USB plug-in key.
5:00It could also do Bluetooth.
5:02But that's what those security keys are.
5:04So that's how we would go through.
5:06And we'd have to click on Save at that point.
5:09And then we would have Windows Hello for Business enabled.
5:13Now, again, for this to work, the device
5:15has to be an Azure AD-joined device,
5:17and the user logging in must have an Intune license.
5:22So there you go.
5:24All right.
5:24We'll close that out and say, OK.
5:26And that's how we go through enabling
5:28Windows Hello for Business.
5:30Now, we're going to take a look at using security keys.
5:33It's our FIDO2, those USB keys.
5:35And we do this from within the Azure AD portal.
5:38So I'm going to jump over there.
5:39Here's our Azure AD portal.
5:41Now, what we're going to do is we're
5:43going to go down to Security we're going to click on that,
5:47then we're going to click on Authentication Methods
5:49right here.
5:50And here we have some options that we can enable,
5:53FIDO2 security keys, Microsoft Authenticator.
5:57That's what we're going to do next actually.
5:59So first, we're going to do FIDO2 two security keys.
6:01We're going to click on that.
6:03And it's really simple.
6:05All we're going to do is say, yeah,
6:07you can use them if you want to.
6:08All users can use them or only select users.
6:11And then we go up to the top to configure.
6:14We'll click on that.
6:15And allow self-service setup so the users can set
6:18their own keys up if you would.
6:19Enforce attestation, this enforces
6:23that you can only use FIDO2 Alliance-approved keys.
6:28So it basically does a validation
6:30to make sure their FIDO2 Alliance-approved keys
6:33and they're not some brand of key that isn't FIDO2-approved
6:37because there are security features and standards that
6:40have to be met.
6:41So yeah, that I definitely do.
6:42And yeah, let him self-service set up.
6:44Why not?
6:45Now, if you want to enable a key restriction policy, meaning it
6:49restricts the keys to the ones that have their IDs,
6:53and these keys have what's called an AAGuid.
6:56And that is a global unique ID that's on these keys.
7:00And what we would do is, do you want to use this?
7:04OK, yes.
7:04Well, then we have to either block or allow.
7:08So here, we're going to create a Guid list,
7:11and we're going to say restrict specific keys.
7:14I'm going say yes.
7:14I'm going to block specific keys,
7:17and I can create a list here or I can say only
7:19allow specific keys.
7:21So I would click on this.
7:22And I would go in there and put in the key ID.
7:26And actually, it's too big.
7:28So I wonder if I could just copy this if it would take that.
7:31Let's see.
7:32Hey, sure did.
7:33And I say, OK.
7:34So this is a key that I'm going to allow.
7:36But I'm only allowing these.
7:39So this way, I could deploy certain keys to users.
7:43But as an admin, I'd have to come in here
7:45and put all these IDs in.
7:46And really, I don't think this is really necessary.
7:49I probably wouldn't do that.
7:51Now, the self-service, yes.
7:52And enforce attestation, yes.
7:54It's going to make sure you don't have some junk
7:56unsecure keys in there.
7:57There you go.
7:58So that's how to set up FIDO security keys,
8:00and you just click on Save.
8:01Then we're going to look at how to set up the Microsoft
8:05Authenticator app.
8:06So let's go back here and say, OK, we're
8:08back to our security authentication methods
8:12right here.
8:13And we're looking at our policy.
8:15So next, I'm going to click on Microsoft Authenticator.
8:17Do you want to enable this?
8:19Well, yes, I would like to enable that.
8:20You want to do it for all users or only select users?
8:23It's up to you.
8:24Then we're going to come over here to these three dots
8:27and click on this and go to Configure.
8:29Now, here we go, Authentication Mode.
8:32If we click on that, we could say password list or push.
8:36And password list, if we wanted to enter a PIN number.
8:40Require number matching.
8:43Now, number matching increases the security
8:46of Microsoft Authenticator.
8:48And how it works is--
8:49I don't have a screenshot of this, I wish I did--
8:52basically, when you're logging into an app
8:55if you're using this, it's going to actually instead of just
8:58sending you a push message to approve, when we turn this on,
9:02it's actually going to show you when you're logging
9:04in on the screen a number.
9:06It might be two digits or four digits.
9:08But it's going to give you a number.
9:09And you have to type that number in to your Microsoft
9:13Authenticator app.
9:15So you're not only just clicking Approve button,
9:17but you're also entering that number.
9:19And it just increases the security by another level.
9:23And then down here, we have show additional context
9:26in notification preview.
9:28And what notification context does
9:32is provides additional information.
9:34So on your login screen, you would not only
9:37get the Approve or Deny.
9:38It would show you who is logging in, the username, what
9:42apps they're logging into.
9:43And actually, even their location.
9:46So it's additional information so
9:48that you can make an informed decision on whether to approve
9:51or deny the connection request.
9:53And then we would say Done.
9:55And if we go back here to authentication methods,
9:58say, OK.
9:59That's how we turn on FIDO2 keys and the Microsoft Authenticator
10:03for passwordless authentication.
10:06I hope this has been informative for you,
10:08and I'd like to thank you for viewing.
Self-Service Password Reset
0:05Did you know that, according to Garner Research,
0:09a password reset call to a help desk cost,
0:12on average, about $70 to reset a password, and that 20% to 50%
0:18of all the calls into a help desk are for password resets?
0:21Well, wouldn't it be great if there was a way
0:24that we could allow our users to reset
0:26their own password so they don't have to call this?
0:28Well, guess what?
0:29There is.
0:31It is a self-service password reset, SSPR,
0:35and let's see how that works in Azure.
0:38All right, here we are in Nugget Labz tenant.
0:40We're going to go up here to our users.
0:43Now in general, the way this would
0:45work-- let's say Bill calls in, and he says, yeah, about that,
0:51I forgot my password.
0:54So what would have to do is click
0:55on Bill Lumbergh come in here, and click on Reset Password,
0:58and go ahead and reset Bill's password.
1:01So let's click on that and let's see what happens.
1:03Oh, no.
1:04"Unfortunately, you cannot reset this user's password
1:06because password writeback is not enabled in your tenant."
1:10Guess what?
1:12Whenever you set up your Azure AD Connect
1:15for your AD-synced users, in order to do password resets,
1:20we have to enable password writeback,
1:22and that was not done when this was set up.
1:25So let's close this out.
1:26Let's go back to another year.
1:28So that's something to keep in mind.
1:29Let's find one that's not Directory synced.
1:32Let's go with Annie.
1:33All right, Annie, let's reset your password.
1:36OK, says here the user oracle@nuggetlabz.com
1:41will be assigned a temporary password that must be
1:45changed next time they sign in.
1:46So to display the temporary password, click on Reset
1:49Password-- bloop, there we go.
1:51It's going to reset it, and there's the temporary password.
1:54So now that's how we go through a manual password reset.
1:58But we want to avoid that, don't we?
2:01Absolutely.
2:02So we're going to close that out.
2:04So we're going to enable SSPR, or self-service password reset.
2:08So to do that, we are going to go back here to Users.
2:14So basically, we just went to our Azure Active Directory
2:17portal as our main page in our Nugget Labz tenant.
2:20We went to Users, we want to come down here
2:22to Password Reset.
2:25That's right, this is where the good old SSPR lives.
2:29Now I do want you to see this message here--
2:32says, "These settings only apply to end users
2:34in your organization.
2:35Admins are always enabled for SSPR."
2:40Aha, so this is already enabled for all admins.
2:44It just does that by default, which
2:46is really nice because things happen and we
2:50know that we don't want our admins locked out because they
2:53don't know the password.
2:54So here we go.
2:55All right, so what we want to do is self-service password
2:58reset--
2:59I've already got this turned on.
3:00But basically, it might be set to None, Selected, All--
3:04I turned it to All and clicked Save.
3:06That's it for turning it on.
3:10But there is a couple of configurations
3:12that we should look at.
3:13Let's go down here to Authentication Methods.
3:16All right, there we go.
3:17So a number of methods required to reset.
3:20Do you want to allow a single method of authentication
3:23in order to reset a password or multiple?
3:26Then, I would like multiple, thank you.
3:28And then which methods should users be able to use?
3:31Mobile app notification, mobile app code, definitely email,
3:36mobile phone, office phone, security questions.
3:39Now if you click Security Questions,
3:41you have a couple options down here.
3:43Number of questions required to register--
3:46so when somebody registers for this,
3:48how many security questions do they have to answer.
3:51Let's say four.
3:53That sounds good to me.
3:54Number of questions required to reset a password--
3:58aha, three.
4:00Now the thing is down here it says,
4:01under Select Security Questions, you
4:04have to go through and select some questions.
4:07It says please select at least four questions.
4:10So let's do that.
4:11Let's click on this.
4:13You could write your own custom security questions,
4:16or go to the predefined.
4:17I like the predefined.
4:19So let's see-- how about that one.
4:21In what city did you meet your first spouse or partner?
4:24In what city did your parents meet?
4:26What city was your father born?
4:27Which city was your first job?
4:29What's your favorite food?
4:30I mean, you could select lots.
4:31And the thing is, when you select these,
4:33when they go through and answer these,
4:36they have the choice of which one of these to answer.
4:39So really, you could say mother's middle name,
4:42you could just select all these.
4:43And this way, when they come in here to set this up and answer
4:47the questions, well, they get to choose what questions they
4:50want to answer.
4:51You're just giving them a choice at that point.
4:53But if you don't want to give them a choice,
4:55only select four, and then move on.
4:57So we could say, OK, there we go.
5:00We have 11 security questions.
5:02But you don't have to do 11.
5:03You could do all of them, or you could do the minimum of four.
5:06Or if you change this to five, it's a minimum of five.
5:08You have to match at least the number of questions
5:10required to register.
5:12All right, so that is our authentication methods
5:16and there we go.
5:17Now we would just click on Save, and away we go.
5:20So that's how we set up our SSPR, or self-service password
5:23reset.
5:23We come under Property, and we say, OK, [INAUDIBLE]..
5:25Come into Properties, we turn it on for just selected
5:28users or all users, then we come under Authentication Methods,
5:32and we go through and set this up as well.
5:34I hope this has been informative for you,
5:36and I'd like to thank you for viewing.
Password Protection and Smart Lockouts
0:00[MUSIC PLAYING]
0:06So we're on the topic of usernames and password
0:09and passwordless and all of these types of authentication.
0:13Well, we also need to protect our credentials
0:15and our accounts.
0:16We need to do things like enable password expiration.
0:20We need to do account lockout settings and all
0:24of those good things that we're going to talk about right now.
0:28All right, here we are in our Azure Active Directory.
0:30We're in our NuggetLabz tenant.
0:32And what we're going to start with is password protection.
0:36So we're going to go down here to Security.
0:38Down here-- let me scroll up a little bit.
0:40There we go, Security.
0:41And we're going to go to Authentication Methods.
0:44And here we go, Authentication Methods.
0:46Excellent.
0:47And then to Password Protection.
0:50All right.
0:51There we go.
0:52So this is our password protection.
0:54Here, we can set the number of failed logins before an account
0:57lockout.
0:57So there's our lockout threshold.
0:59Well, it defaults to 10.
1:00That seems kind of high to me.
1:02Let's go with 5.
1:03Then, our lockout duration in seconds.
1:06So if an account locks out, it's only locked out
1:08by default for 60 seconds.
1:10All right.
1:11I'm going to stick with that for now.
1:13Then, we can have a custom banned passwords.
1:17So if we want to ban passwords, like commonly guessed
1:20passwords, let's say, yes.
1:22So it'd be like Summer22 and maybe even exclamation.
1:26And Fall2022-- there we go--
1:30and maybe a Shift-1, 2, 3.
1:32Whatever-- P@SSW0rd.
1:37All those kinds of passwords-- we
1:38can Google it and find the 1,000 most common passwords and put
1:42them in here.
1:42And this will prevent users from using those passwords.
1:45That's awesome.
1:47Now, there's a word up here I want to talk about
1:50before we go on-- smart.
1:52Why is this a custom smart lockout?
1:55Hmm, interesting.
1:57I wonder what this says.
1:58Well, what this does is it uses some intelligence.
2:02So if we read here, it says, how many
2:04failed sign-ins are allowed on an account
2:06before it's first locked out?
2:07And we set it to 5.
2:08All right.
2:08Now, if the first sign-in after a lockout also fails,
2:13the account locks out again.
2:15So that means we don't have to wait
2:17five failed logins each time.
2:20So if we had five failed logins, the account
2:22locks out for 60 seconds.
2:24After that 60 seconds, the account's no longer locked out.
2:26If the first login is a failure, it immediately locks it again.
2:31All right.
2:32So there's some intelligence built into that.
2:34Well, what about a lockout duration?
2:35Check this out.
2:37The minimum length in seconds after each lockout-- yep,
2:39we know that.
2:40But if an account locks repeatedly,
2:43this duration increases.
2:46A-ha.
2:46So there is intelligence built into this lockout,
2:50and that's why it's referred to as smart lockout.
2:54That's pretty cool.
2:56All right.
2:56So we've got our custom banned password list.
2:58We talked about that.
3:00And then here we have Password protection for Windows Server
3:03Active Directory.
3:04What?
3:05So this isn't Azure Active Directory.
3:07This is actually your on-premise Windows servers,
3:11your Active Directory servers on-premise,
3:14or they could be running in the cloud.
3:16But basically, your servers running Active Directory,
3:19not Azure Active Directory.
3:21So what this does, it enables password protection
3:24on those servers.
3:25So it's taking these features, and it's
3:27pushing them down to your servers on-premise
3:31or if they're running as a VM in the cloud.
3:33Now, the thing is, you must install the Azure AD Password
3:37Protection Proxy Service as an agent on those servers for this
3:42to work.
3:43And then lastly, we have Mode.
3:46And this is for all these settings.
3:47Do you want to just audit this so it will
3:50log what would have happened?
3:51Or do you want to enforce it?
3:54So that's your options there.
3:56But I do want you to remember, this is pretty interesting.
3:59I just find this really interesting
4:00because they want you to allow you
4:02to push these settings and the intelligence in these settings
4:06down to your on-premise servers, your Active Directory
4:09servers, if you want to.
4:11We'll say no for now.
4:12All right, there we go.
4:14So this is our password protection and smart lockout
4:19threshold.
4:20But wait, there's more.
4:22That's right.
4:23We're also going to talk about password expiration policy.
4:26Now, I don't see password expiration in here anywhere.
4:30Hmm, interesting.
4:31It must be somewhere else.
4:33Well, it sure is.
4:34It's actually located in the Microsoft 365 Admin Center.
4:38So let's jump over there.
4:39There we go.
4:40Here we are at Microsoft 365 Admin Center.
4:43Now, in order to make this change,
4:45basically we're setting a password expiration policy.
4:48We're going to go under--
4:50down here under Settings.
4:51We're going to go to Org settings.
4:53There we go.
4:55And then we're going to click on Security and Privacy tab
4:58up here.
4:59There we go.
4:59And then we're going to go down here and select
5:01Password expiration policy.
5:04There we go.
5:05And this is setting the password policy
5:07for all users in your organization.
5:10So we clicked on that.
5:12And it says-- right now, it's Set passwords to never expire.
5:16I'm going to uncheck that.
5:17And here, I can set the number of days
5:21before a password expires.
5:22So we could set this to 90 days, 180 days.
5:25Maybe you want to change twice a year.
5:26Whatever that might be.
5:28And then you would go down here and click on Save.
5:31And that's all there is to it.
5:33It's fairly simple.
5:34And there you go.
5:35Those are some settings that help
5:37us increase the security of our passwords,
5:40allowing us to do password rotation,
5:42do a password expiration policy, using those smart passwords,
5:46using password protection and smart lockout thresholds.
5:50I hope this has been informative for you,
5:52and I'd like to thank you for viewing.
Certificate-Based Authentication in Azure AD
0:00[MUSIC PLAYING]
0:06Most people use passwords as a form of authentication.
0:10We have a user account and we have a password.
0:12But there's another way to do it.
0:15We can also use certificates.
0:16And guess what?
0:17Microsoft Azure now natively supports
0:20certificate-based authentication or CBA.
0:24So let's jump in and talk about certificate-based
0:27authentication.
0:29So is this new in Azure?
0:31That might be a question you're asking.
0:33Well, the truth is, no, not really.
0:35It's been around for many years.
0:37However, within Azure ID, in order
0:39to use certificate-based authentication or CBA,
0:43we had to use something like Active Directory Federated
0:46services, or ADFS, or some other technology to make that happen.
0:51But now, we have the opportunity to use
0:55cert-based authentication, natively.
0:58So that is a cool thing, natively within Azure.
1:03So that's pretty darn cool.
1:05So now, we can implement this, and use
1:08certificates to authenticate to Microsoft Azure.
1:11But that's a little different than using a password, right?
1:15Absolutely.
1:16And it requires a PKI infrastructure.
1:20So that's a public key infrastructure.
1:22So that means you're going to have
1:23to have some type of certificate server.
1:25So within the Microsoft environment,
1:29maybe in on premise environment, you're
1:32going to have your Active Directory domain.
1:34You've got your domain controller over here.
1:36And you're going to need to spin up
1:37a server that is a member server of the domain.
1:41And on that member server, you're
1:43going to install certificate services.
1:47In that certificate services, is your PKI infrastructure.
1:51And as part of this, you're going
1:53to have what's called a CA, or a certificate authority.
1:57And that CA is going to allow you to generate certificates.
2:03And then, you're going to be able to use those certificates
2:06to authenticate to Azure.
2:10Now, you don't have to stand up your own CA.
2:13You could obviously go and purchase public certificates
2:17from a public CA.
2:18However, that's going to be pretty pricey.
2:20So this is a pretty good setup here
2:23to set up your own certificate services within your domain.
2:28So once you generate the certificates, well,
2:31one question is, where do these user certificates reside?
2:35And there's a couple of options.
2:37Number one, you could install those certificates
2:39on the user's computer, and that way it's always there.
2:43So as long as they have their computer, well, guess what?
2:45They've got their certificate as well.
2:48Another option is to use something
2:50like a YubiKey, which is a USB security device.
2:55And you can install the certificates on those,
2:57and then protect the device with a PIN.
3:00So you have to enter a PIN before the device will mount
3:03and you can read the data on it.
3:05You could also use a smart card, which
3:08is a credit card sized card that has a microchip on it.
3:12And you can store them on there as well.
3:14And this also leads into the idea
3:17of using Multifactor Authentication
3:20with certificates.
3:20Because if I have a YubiKey here, and it has my cert on it,
3:26well, guess what?
3:27This is something that I have.
3:30And if I have to use a PIN in order to access it,
3:33that's something that I know.
3:36And there are two different types
3:38of authentication mechanisms.
3:40Therefore, it is Multifactor Authentication.
3:43But I have a USB security key like a YubiKey.
3:47But on that key, we've got it looking like this here.
3:51It actually has a fingerprint reader right on it.
3:55So in order to access the data, I have to use a fingerprint.
3:59So that's something that I am.
4:02So again, that, in combination with what I have here,
4:06in this instance, is Multifactor Authentication.
4:09So you don't have to use multifactor,
4:11but you can, and that's an option.
4:13And we're actually going to look at configuring that later on.
4:16So let's talk about some key benefits
4:19of using certificate-based authentication.
4:22So number one is going to be user experience.
4:26And here we're talking about a good user experience.
4:30Because well, number one, we don't
4:33have to go and set up an ADFS, or Active Directory Federated
4:37Services.
4:37So it's easier on our admins in the setup, and complexity.
4:41Also, for our users, guess what?
4:43You don't have a password that you have to remember.
4:46You just need to have the certificate.
4:48So it is an increased user experience, or an improved user
4:52experience.
4:53Number two, it's easy to deploy and administer.
4:58So again, we're not needing an ADFS.
5:01We can use policies to set up some rules, such as MFA,
5:06whether it's required or not.
5:07And we can also directly authenticate against Azure,
5:13meaning we don't need a third party in the middle,
5:15or a proxy, or anything.
5:17And then, of course, no complex setups like we have with ADFS.
5:23And we're actually going to go through and set this up.
5:25So you'll get to see how simple it is.
5:28And then lastly, secure.
5:30Because it's more secure to use a certificate than a password.
5:34We also have no need to store passwords in the cloud,
5:41because we're going to put a public key in the cloud that
5:45allows Azure to authenticate our users
5:48through their certificates.
5:49And there's no need for us to store our on-premise passwords
5:52in the cloud.
5:53And of course, secure, it allows for MFA, or Multifactor
5:59Authentication, which we had just talked about.
6:02So those are three key benefits to using
6:05certificate-based authentication.
6:07Improved user experience is easy to deploy and administer.
6:10And it's secure.
6:14So let's talk about the process here.
6:16So how do we go about deploying this?
6:18Well, number one, we need to set up a PKI infrastructure
6:23within our environment.
6:25All right.
6:26So-- or we could use a public PKI.
6:28It doesn't matter, either way.
6:29You need a PKI so that you can generate certificates.
6:33And that is step 1.
6:35Step 2 is going to be, deploy certificates,
6:39so that our users have those certificates,
6:42whether it's on a computer, on a smart card,
6:44or a USB security device, our users
6:46have to have them, so that they can use them.
6:49Number 3 is to configure certificate-based
6:53authentication policies within Azure,
6:57'cause these are going to be our individual settings
6:59and policies about it.
7:00Then number 4, basically just turn it on.
7:04Turn on CBA in Azure.
7:09And at this point, we have a PKI.
7:11So we can generate, distribute certificates to our users.
7:14We set up our policies that we want to use.
7:16And then, we turn it on.
7:17And then lastly, well, we simply use it and manage it.
7:23There we go.
7:23So that is the process that we are going to go through.
7:26Next up, is a question you may have.
7:29Well, what are the licensing requirements
7:31to use certificate-based authentication?
7:33Do I have to have an E-3 or an E-5?
7:36Do I have to have a certain level of Azure ID?
7:40And the answer to that is, it doesn't matter.
7:42As long as you have an Azure ID account,
7:45and you've set up your tenant, you can use it.
7:48So there are no special licensing requirements.
7:54And that is pretty darn cool.
7:57And lastly, why should we even consider
8:01using certificate-based authentication?
8:03Well, it comes down to enhanced security, and usability.
8:08And when it comes to passwords that we've
8:11used for so long now, well, passwords can be cracked.
8:15We know that.
8:16So you can use dictionary text to try to crack passwords.
8:20And that's being done all the time.
8:22We end up with password re-use and weak passwords.
8:28It happens.
8:30So really it comes down to bad password hygiene.
8:36So if we were to use CBA, and we do away with passwords,
8:40we do away with these weaknesses as well.
8:43And certificates are created using strong encryption.
8:46So when we do that, it's very unlikely
8:49that they could ever be cracked.
8:51It would take a very, very, very, very, very, very
8:53long time and lots of processing power.
8:57And with certificate authentication,
8:59our users don't have to remember those pesky passwords, which
9:03also means hey, for us admins, no password reset.
9:07Hey.
9:08So overall, CBA is easier to use and more secure.
9:13So it comes down to security and usability.
9:17So that is certificate-based authentication,
9:20what it is, what the requirements are, licensing,
9:24what type of setup it is, and the process to go through that.
9:27And of course, well, why even use it?
9:30So now that we know about CBA, it's
9:33time to jump in to our environment
9:36and set this up already.
9:37So I will see you in the next Nugget.
9:39I hope this has been informative for you,
9:41and I'd like to thank you for viewing.
Setting Up Our PKI
0:00[MUSIC PLAYING]
0:06So now that we're all excited about certificate based
0:08authentication in Microsoft Azure,
0:11it's time to perform step 1 in our setup,
0:14and that's to set up our PKI in our environment.
0:17So I've got a lab environment set up.
0:19We're going to jump onto one of the servers,
0:21and we're going to set up our certificate authority
0:23in PKI infrastructure.
0:24So here we go.
0:26All right, here I am on my server.
0:28This is a member server.
0:30So I'm going to install certificate services.
0:33So I'm going to go over here to Manage.
0:36I'm going to go to Add Roles and Features.
0:39Let that load up here.
0:41All right, there we go.
0:43We'll say Next.
0:44And this is role based.
0:46There we go.
0:47Select a browser, select the server.
0:50I'm going to select that one right there.
0:51It's the one we're on.
0:52Next.
0:53And we're going to select Certificate Services right
0:56there at the top, say Add Features.
0:58Excellent.
0:59Perfectamundo.
1:01So now that we've selected that, we're going to say Next, Next,
1:07and Next one more time.
1:08All right, now we have options to install additional features.
1:12So if you wanted your users to enroll themselves
1:15in certificates, you'd probably select
1:17the-- let me cancel that real quick --the Certificate
1:20Authority Web Enrollment so they could do that.
1:22You'd click this, and then it's going to also install
1:24the is IIS Web Services.
1:26So I'm going to say Add Features because that's
1:28what I'm going to do here in the lab environment.
1:31But otherwise, you could just install
1:33that, the original Certificate Authority.
1:36You could use group policies to push this out so
1:38that the certificates would automatically
1:40get pushed to all the users once they log in on their computers.
1:44But if you do the Web Enrollment,
1:46the users could then also copy that to a YubiKey
1:49or something like that, just depends on your setup.
1:51But for the lab, we're going to go ahead and do the Web
1:53Enrollment.
1:53So I'd say Next, Next again.
1:56Go ahead and Next again.
1:58And go ahead and say Restart if Required.
2:01We'll say Yes and go ahead and install there.
2:06And it's going to take this a few minutes
2:07to go through and install.
2:08So we will continue once it's finished.
2:11All right, this installation is finished.
2:12It did not reboot.
2:13So what we're going to do now is click
2:15on Configure Active Directory Certificates
2:17Services on the destination server, right here.
2:20Or you could say Close and go up to this icon
2:22up here, under notifications, and you can also click on it
2:26there, so either way.
2:27So what we're going to do, go ahead and click on it here,
2:30and it'll open this window right here.
2:32So what we want to do is provide credentials.
2:34Make sure that you are using your domain administrator
2:39or an account with the proper credentials
2:41because if you don't have proper credentials here,
2:43our next step won't quite work.
2:45So we'll say Next, and we want to go ahead and select
2:49Certificate Authority, and give it
2:51a minute to check things out.
2:53Then select Certificate Authority Web Enrollment
2:56and say Next.
2:57Now if you don't have proper credentials,
3:00you won't be able to select Enterprise CA.
3:02It'll be grayed out.
3:03You'll have to select Standalone CA.
3:05That's not going to work in this instance.
3:07So we're going to have an Enterprise CA.
3:09So make sure you select that.
3:10Go ahead and say Next.
3:12And we're going to say is a Root CA.
3:15It's a Root Certificate Authority in the PKI hierarchy.
3:20So this is the top of the food chain as you might say.
3:23We'll say Next.
3:24Create New Private Key, yes please.
3:27Next again, select your cryptographic settings here.
3:31We're going to go with a key length of 2048 SHA256.
3:35All right, super duper.
3:36Create a name for the key.
3:38You can just leave the default if you want.
3:40That's what I'm doing.
3:41Now specify the validity period.
3:43How long do you want this certificate to be valid for?
3:46So you're going to need to check with your company
3:49or organizational policies to find out or check
3:52with the security folks.
3:54All right, there we go.
3:55And maybe you are the security folks,
3:56so you get to make this decision.
3:58I'm going to leave it at 5 years.
4:00We'll say Next and go ahead and specify database location.
4:04You can leave that up to default and go ahead
4:07and click Configure.
4:08Now it's going to go through and configure these,
4:10and it does it pretty darn quick.
4:12There you go.
4:12Configuration succeeded.
4:14So I can go ahead and close that out, close this out.
4:18And now I could come over here to Tools,
4:20Certificate Authority.
4:22Let that open up, right here.
4:24There we go.
4:25And we can expand that.
4:27And we see that we now have a CA.
4:29We've got Certificate Templates down here.
4:31And we're going to be using user certificates
4:36to authenticate our users.
4:37But then you can come in here and look
4:39at Revoked Certificates, issued, pending,
4:42and failed requests, all of that good old stuff
4:45because you may at some point have
4:47to go and approve a request depending
4:49on how you set things up.
4:51So now we have our CA up and running.
4:53It's our PKI infrastructure, and that was step 1.
4:56So in the next Nugget, we're going
4:58to set up step 2, which means we're
5:00going to basically issue a certificate for one
5:03of our users.
5:04I hope this has been informative for you,
5:06and I'd like to thank you for viewing.
Generating a User Certificate
0:00[AUDIO LOGO]
0:06Now that we've got our PKI set up
0:08in our lab environment, whoa, it's time for step 2.
0:11And that's where we make sure that our user has a user
0:14certificate so that they'll be able to use that later on.
0:17So let's make that happen.
0:19All right.
0:20Here we are.
0:21I'm on a Veeam machine here, my lab environment.
0:24And it's a Windows 10 Enterprise workstation.
0:28So what I'm going to do is go through the Web Enrollment
0:30process to grab a user certificate.
0:33So I'm going to go over here.
0:34And since I'm using self-signed certificates in this,
0:36I'm going to use Internet Explorer.
0:38I'm sure many of you are not a fan of that.
0:40But because of the security settings
0:43within like Google and Edge, it--
0:46Well, let's just say this is what I could get to work.
0:50So we're going to go out to our certificate authority.
0:53I'm going to go ahead and put in the URL here.
0:55That's at our nuggetlabz-ca.local/certsrv.
1:03That certsrv is the Web Enrollment page.
1:06So we'll hit Enter.
1:07Should ask us to log in here momentarily.
1:10More Information, Go on to Page.
1:13There we go.
1:13And log in.
1:14And I'm logging in as Johnny Appleseed, johnaseed--
1:18there we go-- @nuggetlabz.com There we go.
1:25Excellent.
1:26Now what I go do is go to Request a Certificate,
1:29say User Certificate.
1:31And this is a Security warning, saying, hey, they're
1:34trying to do stuff--
1:36digital certificate operations on your behalf.
1:38Say Yes.
1:39There we go.
1:40Expand More Options.
1:42Select your options in here.
1:43I'm going to leave it at the defaults.
1:45Say Submit.
1:47It's generating.
1:48And say Yes again.
1:50And there we go.
1:51The certificate you requested was issued to you.
1:53So you can click Install the Certificate,
1:55but I've already done that.
1:57So I'm not going to do it again.
1:58But what I want to show you is if we go down here to mmc, go
2:03ahead and hit Enter.
2:04We're going to go up here to File, Add/Remove Snap-in,
2:07we're going to select Certificates, Add.
2:11There we go.
2:12Current User.
2:13Excellent.
2:14Go ahead and click OK.
2:17Now, if I expand this, I'll go under my Personal Certificates,
2:21I should see my John Aseed Nuggetlabz certificate.
2:27And that's what I have right there.
2:29So I know that I now have my certificate.
2:32But I could always just click over here back on this page
2:36and install it.
2:36Like the first time I did this, I
2:38would install the certificate.
2:39And it would just go ahead and put it in there for me.
2:41So now Johnny has his certificate.
2:44So that wraps up our step 2.
2:47In the next Nugget, we're going to jump into the Azure portal
2:50and begin configuring CBA, or Certificate-Based
2:54Authentication.
2:55I hope this has been informative for you,
2:56and I'd like to thank you for viewing.
Configuring CBA In Azure
0:00[MUSIC PLAYING]
0:06All right, now it's time for us to jump into the Azure portal
0:10and start configuring CBA or Certificate-Based
0:13Authentication.
0:14So let's get started.
0:16All right, here we are.
0:17We're actually on our certificate authority server.
0:20And I've brought up the NMC here, and I want to go to File.
0:24And I'll show you why here shortly.
0:25I add or remove snap-in.
0:27We're going to select Certificates.
0:29Say Add, and we're going to select Computer account
0:32because I need to export the certificate authorities
0:36certificate, so I can import it into Azure
0:39so it will trust my certificates.
0:42So we'll say Next.
0:43Go ahead and Finish.
0:45OK, there we go.
0:46So let's go ahead and expand this.
0:47It's very important that when you see certificates here,
0:50it says local computer.
0:52Next, we're going to expand Personal.
0:53Go to Certificates.
0:54This is the CA's certificate.
0:57We're going to right-click on that
0:59and go to All Tasks and Export.
1:03There we go.
1:03We've got an Export Wizard.
1:04We'll say Next.
1:06Say no, do not export the private key.
1:10Say Next.
1:11We want this in a CER format.
1:14Then we'll say Next again.
1:16Give it a location.
1:17We'll go to our Desktop.
1:19There we go, and we'll give it a name.
1:22Let's drag a little further up.
1:23There we go.
1:24We'll call this our Ca-Cert.
1:28How about that?
1:29Enter, and say Next and Finish.
1:34And there we go.
1:35There's our Ca-Cert over there.
1:37Go ahead and close that out and excellent.
1:40There we go.
1:41We're finished with that, so I'm going to minimize that.
1:43Now, here we go.
1:44We're in our Azure portal here.
1:46We're going to jump into Azure Active Directory.
1:48Click on that.
1:51Excellent.
1:51Now, we're going to scroll on down to Security on the left.
1:54Click on that security.
1:56You can open this up.
1:57Now, we need to find certificate authorities.
1:59Here under Manage, we're going to click on
2:00that because we have to import our certificate in here
2:04so that it will be trusted.
2:06And I've actually already done that here.
2:08But the idea is you come up here.
2:10Click Upload.
2:12It's going to open this slide out here.
2:14You're going to browse.
2:15You're going to select your certificate.
2:18Here we go.
2:19Say Open.
2:20And is this a root CA?
2:21Yes, it is.
2:22Then you can provide your URL for your Certificate Revocation
2:26List or your CRL.
2:28And that's where a CA will--
2:31if it identifies a compromised certificate,
2:34admins can go ahead and revoke that certificate,
2:36so it's no longer valid.
2:38And if you provide this, it allows
2:40Microsoft to go out and check to make sure
2:42that a certificate has not been revoked.
2:44So it helps increase security.
2:46And then we'd come down here and click Add.
2:49And it's that simple.
2:50So you go ahead and add our certificate authority.
2:52I'm going to cancel that because I had already added it in here.
2:56So now that Microsoft trusts our certificate,
3:01it will allow our users to authenticate once we
3:03finish the configurations.
3:06So the next step is to configure some binding policies.
3:09Now, binding policy helps determine
3:11if this is going to be single factor or multifactor
3:14authentication.
3:15So let's go ahead and configure that.
3:17So what we're going to do is come over here and select
3:22Authentication Methods here.
3:24It's going to open this up.
3:25And at the bottom, we see certificate-based
3:27authentication.
3:28We're going to open that up there.
3:31Excellent.
3:32Now, when you first come in here,
3:34this is going to be turned off.
3:35So what are you going to need to do?
3:37Well, you're going to need to turn it on.
3:39There we go.
3:39Then default is all users.
3:42So this is going to be turned on for all users by default.
3:45But you don't have to do that, and I
3:47didn't because I want to do some testing.
3:48So I say selected users, and I put Johnny Appleseed
3:51there in there as the only user who
3:55this certificate-based authentication will apply to.
3:57And this is-- when we're going through and setting this up,
3:59you want to test it to make sure it works and such.
4:01Then you can come in here and change it to all users,
4:04but you need to make sure all of your users have certificates.
4:08Keep that in mind.
4:08And then you're going to go ahead and click
4:10Save so to the save that.
4:13There you go.
4:13It's going to drop you back out.
4:14So now we have to configure our policies.
4:16We're going to go back in here.
4:18I'm going to go to the Configure tab.
4:20And here's our policy.
4:22So by default, your protection level
4:23is single factor authentication.
4:26But you could always move it to multifactor if you want to.
4:29And you can also add rules down here.
4:32So let's take a look at the add rules.
4:34So what this does, it allows us to get a little more granular.
4:37So what you can do is you can add a rule because these here,
4:41this protection level, single-factor, multifactor,
4:43that's global.
4:44So no matter how many different CAs and certificates you have,
4:47it all applies to everyone.
4:49But you can create rules in here for specific certificate
4:53issuers, so specific CAs, or by a policy OID, either way.
4:58But if you wanted to, you could select a certificate
5:02from a certificate authority like that and then say
5:06they're going to use multifactor,
5:07but everybody else uses single factor.
5:09So I'd have single factor over here,
5:11and then I can say multifactor for any certificates
5:13from this certificate authority or certificate issuer.
5:17So you could do that.
5:18So that allows us to be more granular,
5:20and you can set those rules.
5:22So I'm going to cancel that.
5:23I'm going to leave it at single factor for now.
5:25All right, and the next thing we need to do
5:27is set up username binding policies.
5:29And that's right here.
5:30And it's actually pretty simple.
5:33And what this does, this is within the certificate field.
5:36It is the attribute principal name here,
5:39and there's RFC822Name.
5:41And then we have to map that to a user attribute within Azure.
5:46So if it sees that certificate come in,
5:49it knows that the principal name attribute
5:51needs to match the user principal name attribute.
5:53And this was this way by default.
5:55I didn't have to change anything.
5:57And that's how we want it.
5:59So since I didn't actually make any changes,
6:01I don't have to save anything because I'm only
6:04using single-factor authentication,
6:05and these are going to work for me out of the box.
6:09So there we go.
6:10So now that we've got it turned on, we've got our policies,
6:14and we had set up our trusted certificate authority
6:19under here, where we imported our certificate,
6:21well, hey, it should work.
6:24So what do you say, we test it out?
6:26So let's go ahead and do that.
6:27Let me jump over to here, back on my Johnny Appleseed machine.
6:33And what I'm going to do is open up-- actually,
6:35it's already on the desktop.
6:36I'm going to open up Google here,
6:38and I'm going to go to myapps.microsoft.com.
6:43There we go.
6:44And It should ask me to log in, and log in.
6:48Pick an account.
6:49So I'm going to pick my Johnny Appleseed.
6:51Trying to sign you in, and now I could enter my password.
6:54But we're using certificates, remember?
6:56So I'm going to come down here to sign in with a certificate.
6:59I'm going to click on that.
7:01It's going to pop this up.
7:02It sees that I only have one user
7:04certificate on this computer.
7:05So it basically it selects that by default, and I just say, OK.
7:10And now, it logs me in.
7:12Hey, do you want to stay signed in?
7:14Not this time.
7:15Thank you very much.
7:16But it's going to go ahead and sign me in.
7:18And you see that is a passwordless authentication
7:21using certificate-based authentication.
7:24So that is pretty darn cool.
7:26So we saw that whole process, all the way
7:28about talking about what CBA is, all the way
7:31into setting up our PKI infrastructure,
7:34getting a certificate for our Johnny Appleseed user,
7:38and then setting it up within Microsoft Azure,
7:41which is actually pretty darn simple.
7:43So that's the entire process.
7:44I hope this has been informative for you,
7:46and I'd like to thank you for viewing.
Configure Azure AD User Authentication for Azure Windows VMs
0:00[INTRO SOUND]
0:06For years, I wondered when I deploy
0:09an Azure virtual machine, why can't I log in
0:12with my Azure AD credentials?
0:14Wouldn't that be really cool and super
0:16handy to be able to do that?
0:17Well, guess what?
0:18Now you can.
0:19That is right.
0:20You can now deploy Azure VMs, Windows, and Linux,
0:25and log into them with your Azure AD credentials,
0:27as long as you deploy these properly,
0:31and of course, you set up the proper permissions or roles
0:34for specific users.
0:36And that's what we're going to look at right now.
0:38All right.
0:39We're starting off with Windows Azure VMs,
0:42because this new feature of logging
0:44into your VMs with your Azure AD credentials
0:47works for Windows and Linux.
0:49But we're going to do these in two separate videos.
0:51So we're starting off with Windows.
0:53So when we're logging into Windows virtual machines
0:55in Azure by using your Azure AD credentials,
0:58there are some things that we need to know about.
1:01Let's first start with some of the benefits.
1:03We're just going to take a look at a couple of them right out
1:06of the Microsoft documentation.
1:08And the idea is that we're actually
1:11using federated and managed domain user
1:14accounts, because we're able to manage them
1:15all through Azure AD.
1:18Now a key one is right here, reduced reliance
1:21on local administrator accounts, because instead
1:24of having local administrator accounts for everybody that
1:27needs to login and use it, well, we
1:29can just use the proper role within Azure AD,
1:33and assign that role to our Azure AD account.
1:36And we can manage local administrators that way.
1:40So we don't have to worry about local admins on the box
1:43so much.
1:43We can also control password complexity and password
1:46lifetime through our policies in Azure AD.
1:48We can use our role-based access control
1:51to specify who can log into an Azure VM as a regular user,
1:56I just would say here.
1:57And as administrator.
1:58And we're going to look at that because there's actually
1:59two separate roles.
2:00There's a role for regular users and a role
2:03for administrative privileges.
2:05And then when somebody joins or leaves
2:07your organization or your team, well,
2:08you just simply go into that role
2:10and remove or add that person, and then they have that ability
2:14or no longer have that ability to log in to the VMs.
2:16So that's pretty cool.
2:17We can also use conditional access policies
2:20to require things like multifactor authentication.
2:22And take advantage of sign in risk.
2:25And that's when risky activities are
2:27happening with an account, or a user signing in.
2:31Well, it can require things like multifactor authentication
2:33or password reset, if there's risky activities going on
2:36with the specific account.
2:38So that's our conditional access policies.
2:40And we can also deploy and audit policies.
2:43And those are some of the really cool benefits
2:47of using your Azure AD credentials
2:49to log into your Azure AD VMs.
2:52Now here is the thing.
2:56If you do enable this, because what we're doing here
2:58is we are actually joining those VMs that we spin up
3:03to our Azure AD.
3:05So they are Azure AD joined.
3:06And once we do that, well, we can't join them
3:08to another domain, like an on-prem domain or something.
3:11So just keep that in mind.
3:13If you want to use this feature, then the VMs you spin up
3:16are going to be Azure AD joined only.
3:18So do keep that in mind.
3:20Now some requirements.
3:21Well, when it comes to Windows machines,
3:24there has to be of a couple of distributions--
3:26Server 2019 Datacenter or later, and Windows 10 1809 and later.
3:31So if you're wanting to spin up VMs with OS's earlier
3:34than this, this feature is not available.
3:37Now here's something that we're going to see later on.
3:40Once we spin this up, and we try to connect to these VMs,
3:43there are some restrictions, or we could just say requirements.
3:48And that is that the device you're
3:50trying to RDP from, it must be Windows 10 or later PCs, also
3:58servers as well, 2019 and later, that are Azure AD registered,
4:03Azure AD joined, or hybrid Azure AD joined.
4:07So this means if I try to RDP to a Windows host
4:12that I've spun up and set up properly
4:14so I use my Azure AD credentials,
4:16well, I can't do it, unless the device I'm on
4:19is Windows 10 or later, and is Azure AD registered,
4:23Azure AD joined, or hybrid Azure joined.
4:26So if I'm trying to do this from a device that is maybe
4:31a Mac computer, guess what?
4:32It's not going to work.
4:33Or a Windows computer.
4:34Maybe it's a early version of Windows 10, not going to work.
4:38Well, hey, maybe I use a Windows 11, so that's later, right?
4:42But it's not Azure AD registered, joined,
4:45or hybrid joined, it's not going to work.
4:47So keep that in mind.
4:49That's another requirement.
4:50And as we scroll down, last thing we look at here
4:53is the availability in the Azure cloud areas.
4:56It's available in Azure global government in China 21Vianet.
5:01There you go.
5:01And there's network requirements as well.
5:03And this simply means that on your host that you spin up,
5:08if you set up firewall rules, you
5:10have to allow outbound TCP 443 to these URLs.
5:15Keep that in mind.
5:16And if you set up network rules within your virtual environment
5:21that prevent communications outbound over TCP 443,
5:25you need to make exclusions for these, because this
5:27is how it's going to connect and authenticate your Azure AD
5:30credentials.
5:31All right.
5:31So that is documentation.
5:33It's time to jump into the portal and get started.
5:36So let's do that.
5:37Let's jump over here.
5:38Here we are in our portal.azure.com.
5:41I'm going to jump into Virtual Machines.
5:43I'm going to go to Create Azure Virtual Machine.
5:46There we go.
5:47And we're actually going to spin up a Server 2019 Datacenter.
5:50So I select my resource group.
5:52There we go.
5:53NuggetLabz is virtual machine name.
5:55I'm going to call this Win-Test1.
5:58Here we go.
5:59US East 2 is fine.
6:01No redundancy, security type standard.
6:03We're just doing some testing here.
6:05I'm not too concerned.
6:06Windows Server 2019 Datacenter.
6:08There we go.
6:09Excellent.
6:10I'm going to stick with this size.
6:11And I'm going to create a user account here.
6:14Bob.
6:15Put in a password here.
6:17Verify that password.
6:19All right.
6:20Excellent.
6:20Now I'm going to scroll down here.
6:22Public inbound ports, I need to allow 3389.
6:25And we're going to restrict that here shortly.
6:27So I'm going to go ahead and select that.
6:29Say Next for my disks.
6:32I'm just going to go with standard SSD.
6:34We're just doing some testing here.
6:36Definitely delete with VM because again, this is lab.
6:39So there we go next.
6:42All right.
6:42Networking, networking, networking.
6:45This all looks good.
6:46Just go with some default settings here.
6:48I'm not too worried about this.
6:49But I do want to delete the public IP when
6:51the VM is deleted, because I'll be deleting these here shortly.
6:54Now this is the difference.
6:57This is key.
6:58When we get to the Management tab
7:00here, in order to enable Azure AD credential authentication,
7:05you need to come under Azure AD.
7:07And you'll see here, log in with Azure AD.
7:10Well, we need to turn that on.
7:12And then by default, it also turns on identity.
7:15This enables system assignment managed identity.
7:18And you need to make sure that does get checked,
7:21and it does that on its own.
7:22But just double check to make sure.
7:24All right, cool.
7:25So that is the key right there.
7:27We have to enable Azure AD log in with Azure AD.
7:31That's the key to enabling this feature in here.
7:35So go ahead and scroll down here.
7:37Everything there looks good.
7:38Go into Advance.
7:39Don't need anything there.
7:40Tags, I'm good there.
7:41Review and create, I'm going to let this go ahead
7:43and do a review.
7:44And then we'll click on Create.
7:46So we can go ahead and create this machine for us.
7:49So go ahead and click Create.
7:50And now it's going to start into the creation process.
7:53Now while it's spinning this up, it's
7:55time to talk about identity and access
7:57management and our role-based access control, RBAC
8:01when we're talking about our roles and security.
8:04So what's happening is, right?
8:05Well, right now it's deploying this.
8:07We're going to jump to another tab.
8:09All right, there is something we need to do here.
8:11We need to go into resource groups.
8:13We need to select the resource group in which we spun up
8:15that VM, which was NuggetLabz.
8:17So let's go in there.
8:18What we need to do in here is set up some roles.
8:22Now the roles already exist.
8:23But we need to assign people to them.
8:25So let's go over here to access control, there IAM.
8:29I'm going to move this over a little bit.
8:30And what we need to do is we need to go ahead and click
8:33on Add, Role Assignment.
8:35There we go.
8:36And there are two roles in particular that we
8:38need to be familiar with when it comes to this feature.
8:41And that is virtual machine--
8:45let that load up there, administrator login.
8:48Now, if you give someone this role,
8:51it means that they can log into one of these Azure VMs
8:55as an administrator.
8:57So when they log in, they're logged in as an administrator.
9:00So they have those admin permissions.
9:03And that's where we come across that benefit of not
9:06needing to manage local admin accounts on those VMs.
9:09And the other role we need to look at
9:11is down here at the very bottom.
9:13And this is virtual machine user login.
9:16And this allows whoever has this role
9:19to log in to these virtual machines as a regular user,
9:23so that they're not an admin user, just a regular user.
9:26So what we're going to do, we're going
9:27to go into virtual machine login and click on that.
9:30We're going to say Next.
9:32Then we need to add members.
9:34So basically, we can select user group or service principal,
9:37or we can select a managed identity.
9:38I'm going to do user group or service principal.
9:41I'm going to say select members.
9:43There we go.
9:44And what I would do is just go in here and select somebody,
9:47like John Appleseed.
9:50So I can say that.
9:51Say select.
9:52And now John Appleseed.
9:54And I could do select members.
9:55Go ahead and add me in there as well.
9:58There we go.
9:59Select.
10:00There you go.
10:01So now if John or myself log in to one of these VMs,
10:04well, we're doing so as an administrator,
10:07so that we do review and assign and go ahead and review
10:11and assign.
10:12At which point, it'll go ahead and do that.
10:13But it failed, as you see up here,
10:15just because both of those accounts
10:17are already assigned to that role.
10:19I just wanted to show you the process of doing so.
10:21So there you go.
10:22But if you want someone to be able to log into VMs, but only
10:25as a regular user, then we're going to go in and go in here
10:28and select the virtual machine user login right there.
10:34This one right here.
10:35So when somebody has that role and they log in,
10:37they're logging in as a regular user, not an admin.
10:40So keep that in mind.
10:41So this was like step 2.
10:43Step 1 was to go through and create the VM.
10:45Step 2 was to enable the roles and assign members
10:48to those roles.
10:49So now that we've done that, hey,
10:52we should be about ready to log in.
10:54So let's jump back over and check on our VM.
10:57Well, it's still deploying.
10:59So we're going to pause this for a few minutes
11:01while this finishes deployment.
11:03All right, we are back.
11:05Our deployment is complete.
11:07So I'm going to click on here, is go to resource.
11:09It's going to bring us right into our Win-Test1.
11:11And the first thing I'm going to do
11:13is I'm going come over here to networking,
11:15and I have a rule here for remote desktop protocol, RDP.
11:18And it's open to anybody in the world to log into it.
11:21So we're going to click on that.
11:22And we're going to edit that rule.
11:23And I'm going to go over here and copy my address here.
11:29There we go.
11:29And we're going to come over here,
11:31and we're going to say source is IP address,
11:33and I'm going to stick in only my IP address.
11:37There we go.
11:38And we're going to click on Save.
11:39And we'll give that just a few seconds here to save.
11:42And that way, only my IP address can RDP into this host
11:46from outside the VM environment.
11:49So there we go, our source is updated.
11:52Perfect.
11:53There we go.
11:54Now, I don't have to worry about people
11:55trying to brute force via RDP into this host.
11:58All right, so now guess what time it is?
12:00Well, it's time to log into our host.
12:04So we're going to jump over to a VM here just a second.
12:07All right, here we are in our lab environment.
12:10And I'm on a virtual machine that
12:12is actually Azure AD joined.
12:14And I'm logged in as Johnny Appleseed.
12:16So let's go ahead and click on that icon right there
12:19and click Remote and Remote Desktop Connection.
12:23There we go.
12:24And let's go ahead and put our IP address in there,
12:2620.110.101.137.
12:29Let's double check, make sure that is correct.
12:31If I jump back here, 20.110.101.137.
12:35It looks good to me.
12:36We'll jump back over here.
12:38And that's the IP of our server out there.
12:40So now I'm going to say connect.
12:43And I need to put in my password is Johnny Appleseed.
12:49And hit Enter.
12:50And see if it works.
12:52It says, hey, it looks like it's going to work.
12:54Awesome.
12:55There we go.
12:56It's connecting to Win-Test1.
12:58We see there.
12:59Say go ahead and you want to connect despite the certificate
13:02error.
13:02Yes, I do.
13:04And there we go.
13:05We are officially connected into our Azure Windows VM
13:09using Azure AD credentials to log in.
13:13Super.
13:14And there we go.
13:15That is how we do it.
13:16Now as a quick recap, we need to create our virtual machine.
13:20And in the Management tab, we need
13:21to enable login with Azure AD.
13:25And then we had to go into our roles.
13:28And in the roles here, we were looking at virtual machine user
13:32login as a standard user login, and virtual machine
13:36administrator log in to log in as an administrator.
13:39And then lastly, when we come back over here,
13:42we have to log in from a Windows 10 or later computer that
13:46is Azure AD joined, Azure AD registered,
13:49or Azure AD hybrid joined.
13:52And there you go.
13:53That's how we make that happen using Azure AD credentials
13:55to log into Windows Azure VMs.
13:58In the next Nugget, we're going take a look at how to do this
14:00with Linux VMs in Azure.
14:03So stay tuned for that.
14:05I hope this has been informative for you,
14:06and I'd like to thank you for viewing.
Configure Azure AD User Authentication for Azure Linux VMs
0:00[MUSIC PLAYING]
0:06Now it's time for us to set up an Azure Linux VM
0:12and then set it up so that we can log in to that VM
0:14using our Azure AD credentials, which is a new feature.
0:18So let's get started.
0:19All right, here we are in the documentation.
0:21We're going to take a quick look at a couple of things
0:24when it pertains to log in to Linux VMs in Azure
0:27by using Azure AD and OpenSSH.
0:30All right.
0:31So first off, we're taking a look at some of the benefits,
0:35and you'll see that many of them overlap
0:37with the same benefits from logging
0:39in with Azure AD creds to Windows machines.
0:42Well, the first one is basically simple.
0:44You get to use your Azure AD creds to log in,
0:47makes it a little easier.
0:48It also helps with SSH key based authentication
0:51because you don't have to share those keys
0:53and move them around because you can have your own as your AD
0:58key.
0:58There we go.
0:59So the next step, reduce reliance on local administrator
1:02accounts.
1:03We saw that with the Windows Azure VMs as well.
1:06Help secure Linux VMs by configuring password
1:09complexity, password lifetime policies.
1:11The same thing we saw with the Windows VMs.
1:14And then you can use your role-based access control
1:16using those two roles that we looked at in the last Nugget.
1:20And we're going to look at those again as a quick review.
1:22And that was our virtual machines administrator login
1:26and virtual machines user login roles.
1:28And then we can also use conditional access policies,
1:31especially to enable things like multifactor authentication,
1:34and so on and so forth.
1:35So let's scroll down.
1:36Those are some of the benefits, keep in mind.
1:39But we are limited to specific Linux distributions.
1:43So which ones are supported?
1:44Well, they're right here.
1:46Take a look here.
1:47We are going to be deploying an Ubuntu 1804 LTS or Long-Term
1:54Support flavor today.
1:56So that is definitely one of those.
1:58So these are the supported distros.
2:01So if you want to use something else,
2:03it's not supported at this point in time.
2:05But that might change.
2:06And when it comes to which regions
2:07support this, Azure Global, Azure Government,
2:10Azure China 21Vianet.
2:12All right.
2:13And one more thing to look at, if we scroll down here,
2:16there are networking requirements
2:17just like there were with the Windows setups,
2:20and that's simply that we need to allow outbound TCP port
2:23443 to these locations.
2:25And remember, that could be your own Host firewall
2:28rules on your Linux host or in your network environment
2:32there within Azure.
2:33So keep that in mind.
2:34All right, so that wraps up our documentation.
2:37Time to get started.
2:38Let's jump into the Azure portal.
2:40Jump over to Virtual Machines.
2:41We're going to click on Create to create
2:43a new virtual machine.
2:45There we go, and there we go.
2:47Excellent.
2:47Select our resource group, NuggetLabz.
2:50Excellent.
2:50Virtual machine name, we're going to call this--
2:53let's see.
2:53Linux-Test1.
2:56US East 2 is fine.
2:57Availability option is fine, security type.
3:00Aha, image, definitely not Windows.
3:02We need to go with an Ubuntu 1804 LTS.
3:05Perfect, there we go.
3:07And the size is fine.
3:10Let's see.
3:11I'm going to actually set a password for this
3:13instead of a SSH public key.
3:15So what I'm going to do is set that up.
3:20There we go.
3:21Excellent.
3:22Let's see.
3:23Allow 22 for SSH, sounds good to me.
3:27Disks, delete disk with VM.
3:29Let's just go with standard SSD.
3:32And that works for me.
3:33I don't need anything else.
3:35Down here under networking, everything looks good.
3:39We do want to delete public IP with V machine.
3:42Excellent.
3:44All right, now, management.
3:46We have to do the exact same thing
3:47that we did in our Windows VM setup,
3:50and that is under Azure AD.
3:52Check the box for Login with Azure ID,
3:56and that automatically enables system assign managed identity.
3:59This is key.
4:00When we select these options, it's
4:02actually going to go in and install
4:04a couple of packages on our Linux VM
4:07to help this work properly.
4:09All right, there we go.
4:11Next to Advanced, there's nothing we need in there.
4:13I don't need to assign a tag.
4:15Excellent.
4:16We're going to let this finish its validation.
4:19Then we'll go ahead and click on the Create button.
4:21So let's do that.
4:22And that's going to start the creation
4:24of our virtual machine.
4:25And just like last time, we're going
4:27to jump over to our resource group
4:30and look at the permissions required
4:31because it's a good review, and you
4:34need to know this information.
4:35So under Resource Groups, we're going to go to our NuggetLabz.
4:38There it is.
4:40And let's slide that over.
4:41And under our Resource Group, we need to go into IAM.
4:45That's our access control area, and we're dealing with roles.
4:49So we can take a look at the roles that exist here.
4:51And what do we need to work with?
4:53That's right, virtual machine roles.
4:55Virtual machine, there's two of them-- administrator login.
5:00So if you assign someone this role,
5:03you make them a member of this role.
5:05They will be able to log in to either a Windows or Linux
5:09virtual machine in your Azure environment
5:12as an administrator.
5:13So when they log in, they have administrator privileges.
5:16The other option is user.
5:19So it is-- let me put it in login there because this
5:22will narrow it down.
5:24So it is this one here, Virtual Machine User Login.
5:28If you make someone a member of this role, when
5:30they log into a Windows or Linux VM
5:33within your Azure environment, they
5:34will log in with regular user permissions, not
5:38the administrator permission.
5:39So keep that in mind.
5:40Those are the two key roles that you really
5:42need to keep in mind because when we're
5:44talking about logging in with the two Azure VMs with Azure AD
5:47creds, you've got to have one of those two roles assigned
5:50to your account.
5:51So let's jump back over to our VM and check
5:55on its deployment progress, and it's still deploying.
5:58So we're going to pause for a minute and let this finish up.
6:01All right, our deployment has completed.
6:03So let's jump in and go to Resource.
6:06Go right into our Linux-Test1 VM and go over
6:08to Networking over here on the left.
6:10Click on that because I've got SSH
6:13open to the world for this host, not very good.
6:15So let's change that.
6:16Let's go to IP address, and let's paste in my IP address.
6:20There we go.
6:21Click Save.
6:23Excellent.
6:25Now that that's saved and we have
6:28roles assigned-- because we did that actually
6:30in the last Nugget.
6:31We assigned the proper roles so that Johnny Appleseed
6:35and my account both have the virtual machine administrator
6:40log in role.
6:41So we could log in.
6:42I should be able to SSH this thing now.
6:44So how can I do that?
6:46Or better yet, where can I do that from?
6:48So let's jump over to the documentation real quick
6:50and take a look.
6:52All right, here's the documentation.
6:53It says log in by using Azure AD user account to SSH
6:56into the Linux VM.
6:58You have two options really, using the Azure CLI.
7:01All right, that's what we're going to do.
7:02But you could also use the Azure Cloud Shell.
7:06OK, that's pretty cool.
7:07So you have to do it through either the Azure CLI or Azure
7:12Cloud server.
7:12You can't just open up an SSH tool or SSH
7:15from another Linux host or from maybe your Mac or something.
7:20You can't open up PuTTY and SSH out to this machine
7:24from your workstation.
7:24You've got to do it through Azure Cloud Shell or Azure
7:27CLI, at least for now.
7:29So we're going to use the Azure CLI.
7:30So that being said, I'm going to jump over here, go to-- here's
7:34a NIC public IP address.
7:35Let me copy that.
7:37There we go.
7:38I'm going to put it over here.
7:39There we go.
7:40Excellent, super duper.
7:42Now, let's jump over to our lab environment here.
7:46I'm on a server here.
7:48This is actually one of my domain controllers.
7:50I'm going to open up a PowerShell.
7:53Let's go ahead and open up PowerShell as an administrator.
7:57Excellent.
7:58There we go.
7:58So what are we going to do?
8:00Well, we're using the Azure CLI.
8:01So what I'm going to do first is az log in,
8:04and I'm going to have to log in.
8:08There it goes.
8:08It's opening a browser so I can log in.
8:12And then I'm going to select my account there.
8:15I need to enter my password here.
8:18There it goes.
8:19And I need to throw my MFA.
8:23Excellent.
8:24So I'm now logged into Azure.
8:25I'm just going to minimize this.
8:28There we go and bring my PowerShell back up.
8:30There we go.
8:31We are logged in right now.
8:33Excellent.
8:33So at this point, I'm going to clear the screen there,
8:37and we're going to type the command to connect to our host,
8:41and that is, az ssh vm, all right--
8:45that's pretty simple-- dash in.
8:46I provide the name of my VM.
8:49So that was Linux-Test1.
8:54There we go, and I type in the g, the resource group that is
8:58a part of, which is NuggetLabz.
9:02There we go and hit Enter.
9:04And now, it's going to go through the process of logging
9:06me in using my Azure AD credentials
9:09into the Linux-Test1 VM.
9:12And now it's asking me, do you want to accept the fingerprint?
9:14Because this is a self-signed certificate within the Linux
9:18host itself.
9:18Say yes, and excellent, and now it's
9:21going to connect me into my host.
9:25And look at there.
9:25I am now connected to Linux-Test1 using my Azure AD
9:32credentials, as you can see here,
9:34bob@nuggetlabz.o mnimicrosoft.com.
9:36So that is how we go through the process of setting up a Azure
9:41Linux VM to accept Azure AD user credentials to log in
9:47as either an administrator or as a regular user,
9:50depending on which role we select, and that's the process.
9:54I hope this has been informative for you,
9:55and I'd like to thank you for viewing.
Team training path
Turn this skill into assignable team training
This free skill is a preview of the courses your team can assign, track, and report on with CBT Nuggets.
$708
seat / year