ការអភិវឌ្ឍ / កំណត់ចំណាំវាល
ការចូលប្រើតាមលក្ខខណ្ឌ ដែលមនុស្សអាចរស់នៅបាន
សុវត្ថិភាពអត្តសញ្ញាណបរាជ័យ នៅពេលវាតស៊ូនឹងអ្នកប្រើរបស់វា។ ចាប់ផ្តើមពីហានិភ័យ ដាក់ឱ្យដំណើរការជាដំណាក់កាល និងរក្សា break-glass មួយ។
កំណត់ចំណាំវាលនេះត្រូវបានផ្សព្វផ្សាយជាភាសាអង់គ្លេស។
Multi-factor authentication everywhere is the right destination, but switching it on for everyone on a Monday morning is how you get a helpdesk queue and a quiet campaign to bypass it. Conditional access works better as a phased rollout ordered by risk.
Privileged accounts first
Global administrators, service principals with broad roles and anyone touching finance or customer data. These accounts get phishing-resistant MFA and compliant-device requirements before anyone else — the blast radius justifies the friction.
Then the everyday estate
Roll MFA to the rest of the organisation in groups, with a clear support path and a documented exception process. Report-only mode first: watch who would have been blocked for a week before enforcing anything.
Keep a break-glass
Two emergency accounts, long random passwords in sealed storage, excluded from every policy, monitored with alerts on any sign-in. They are the fire exit — never used in normal operation, checked regularly so they work when needed.
Review access on a rhythm
Access reviews every quarter for privileged roles, twice a year for everything else. People change teams, contractors leave, service principals outlive their purpose. The review is the control; conditional access is just the enforcement.
Further reading: Microsoft Entra conditional access documentation.