සංවර්ධනය / ක්ෂේත්ර සටහන
මිනිසුන්ට ජීවත් විය හැකි කොන්දේසි සහිත ප්රවේශය
අනන්යතා ආරක්ෂාව තම පරිශීලකයන් සමඟ පොරබදන විට අසාර්ථක වේ. අවදානමෙන් ආරම්භ කරන්න, ක්රියාත්මක කිරීම අදියර කරන්න, සහ break-glass එකක් රඳවා ගන්න.
මෙම ක්ෂේත්ර සටහන ඉංග්රීසි භාෂාවෙන් පළ වේ.
Multi-factor authentication everywhere is the right destination, but switching it on for everyone on a Monday morning is how you get a helpdesk queue and a quiet campaign to bypass it. Conditional access works better as a phased rollout ordered by risk.
Privileged accounts first
Global administrators, service principals with broad roles and anyone touching finance or customer data. These accounts get phishing-resistant MFA and compliant-device requirements before anyone else — the blast radius justifies the friction.
Then the everyday estate
Roll MFA to the rest of the organisation in groups, with a clear support path and a documented exception process. Report-only mode first: watch who would have been blocked for a week before enforcing anything.
Keep a break-glass
Two emergency accounts, long random passwords in sealed storage, excluded from every policy, monitored with alerts on any sign-in. They are the fire exit — never used in normal operation, checked regularly so they work when needed.
Review access on a rhythm
Access reviews every quarter for privileged roles, twice a year for everything else. People change teams, contractors leave, service principals outlive their purpose. The review is the control; conditional access is just the enforcement.
Further reading: Microsoft Entra conditional access documentation.