James Valente
My feedback
-
3 votes1 comment · Office 365 Security & Compliance » Spam & Phishing · Flag idea as inappropriate… · Admin →
An error occurred while saving the comment James Valente supported this idea ·
-
3 votes
James Valente shared this idea ·
-
10,798 votes
Thank you to everyone taking the time to vote on this ask. Our security best practices recommend not making passwords expire and our focus is around this policy at the moment. You can read more about it in these two documents:
https://www.microsoft.com/en-us/research/publication/password-guidance/
An error occurred while saving the comment James Valente commented
Please. Many users in our organization are only checking email via a mobile client and logging into applications that aren't hitting our SSO (ADFS or Azure AD ) login.
We are currently using a third party tool on a standalone server that is querying AD and this creates a lot of management overhead (patching a windows server used solely to remind users about password expiry...) for something Azure could easily accomplish running a powershell command once per day.
James Valente supported this idea ·
-
2 votes0 comments · Office 365 Security & Compliance » Spam & Phishing · Flag idea as inappropriate… · Admin →
James Valente shared this idea ·
-
2 votes0 comments · Office 365 Security & Compliance » Advanced Security Management · Flag idea as inappropriate… · Admin →
James Valente shared this idea ·
I'd even expand this to intra-tenant protection. We've had multiple instances of compromised users phishing other users and it being completely ignored by EOP and ATP. When I raised this with MS Premier support I only got condescending suggestions to enable MFA for all users since the solution we're paying hundreds of thousands of dollars for didn't protect intra-tenant attacks.
MS needs to realize that if it's selling its platforms for Education it needs to account for use-cases within Education (what's MS's support suggestion for a MFA issue at 11PM when an assignment is due and there is a small helpdesk team for 10k+ students?) . Rather than dismissing the issue with a solution that isn't suitable, they should be addressing user concerns.