The more important the system, the worse Microsoft’s MFA security is.
Their strongest protection is for XBox accounts.
Because they know that their users value their personal Minecraft skins more than billions of dollars worth of their employer’s stuff.
Microsoft can get away with it in Xbox because they can set the terms for how an individual gets to access the service.
An individual consumer doesn't have much of a choice but trying to force the same terms on business users could cause them to not use it at all or jump vendors.
https://docs.microsoft.com/en-us/azure/active-directory/auth...
https://docs.microsoft.com/en-us/azure/active-directory/auth...
Use additional context -- Preview
Awesome. Let me just convince my enterprise customer where I'm not even an employee to mass enable two PREVIEW features for 35K users. That'll go down well.
Users cannot opt in to more secure authentication options individually.
The default is woefully insecure, almost pointless security theatre.
The secure option is unsupported in production.
Hardware token-based security is disabled by default, and carefully hidden behind dark patterns to boost the numbers of the MS Authenticator app so that some manager at Microsoft can meet his personal KPIs and get his bonus.
Customers using features like Azure AD multi-tenant applications cannot enforce MFA themselves -- Microsoft reserves this capability for their own applications only.
Even if I enforce hardware token MFA in my own personal Azure AD tenant, if I get invited to some other tenant as a Guest (e.g.: to a Teams meeting), then I'm forced to sign in using their MFA policy, which is more than likely the default MS Authenticator app with all optional features like this disabled.
To say that Enterprise customers have lots of options is patently false.
Microsoft only cares about security when it affects their own systems.
I don't think even that's true. Unlike at Google and to some extent Apple, I don't sense that Microsoft's internal corporate culture wants security per se. Both Google and Apple seem comfortable with the idea that if you can solve a security problem for $15 you have one option, "Secure" and it costs $15 and the only question is whether "Not secure" should be available for $0 (OK at Apple maybe "Secure" inexplicably costs $30 because it's a premium product but equally maybe "Secure" was "free" with your $1000 premium Apple product, for this argument either outcome is fine).
Microsoft seems excited about offering "Somewhat secure" for $5 and "A bit more secure" for $10 and if just "Secure" is an option at all, it needs to be priced at $100 to show what a bargain the "Somewhat secure" option is. This is a reasonable mindset if you make padlocks or something, but a crummy attitude for digital security where we can so often just solve the problem full stop. Remember how Intel couldn't persuade people the Pentium FDIV bug wasn't a big deal? Nobody wants a computer that sometimes gets arithmetic wrong "a little bit" they want the correct answers and anything less is unacceptable.
Or because the XBox team isn't beholden to corporate clients, so they're much more free to make changes which affect user workflows.