<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Your sign-in was blocked 1 | Cloud Engineer - Everton Collins</title>
	<atom:link href="https://evertoncollins.com/tag/your-sign-in-was-blocked/feed/" rel="self" type="application/rss+xml" />
	<link>https://evertoncollins.com</link>
	<description>Work by Everton Collins</description>
	<lastBuildDate>Wed, 27 May 2020 18:09:24 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://evertoncollins.com/wp-content/uploads/2015/06/logo1-150x150.png</url>
	<title>Your sign-in was blocked 1 | Cloud Engineer - Everton Collins</title>
	<link>https://evertoncollins.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Azure Identity Protection &#8211; Enterprise Mobility + Security</title>
		<link>https://evertoncollins.com/azure-identity-protection-enterprise-mobility-security/</link>
		
		<dc:creator><![CDATA[Everton]]></dc:creator>
		<pubDate>Thu, 14 Dec 2017 01:44:48 +0000</pubDate>
				<category><![CDATA[Enterprise Mobility + Security]]></category>
		<category><![CDATA[Azure Active Directory Premium]]></category>
		<category><![CDATA[Azure Identity Protection - Enterprise Mobility + Security]]></category>
		<category><![CDATA[Your sign-in was blocked]]></category>
		<guid isPermaLink="false">https://www.evertoncollins.com/?p=996</guid>

					<description><![CDATA[<p>Azure Identity Protection Azure Identity Protection is a feature of Microsoft Enterprise Mobility + Security and is a premium feature in EMS E5.  We conducted a test to see if a user would be blocked while trying to log in from 2 separate locations. We went to https://portal.azure.com/ and logged in with credentials normally from our [&#8230;]</p>
<p>The post <a href="https://evertoncollins.com/azure-identity-protection-enterprise-mobility-security/">Azure Identity Protection – Enterprise Mobility + Security</a> first appeared on <a href="https://evertoncollins.com">Cloud Engineer - Everton Collins</a>.</p>]]></description>
										<content:encoded><![CDATA[<h1>Azure Identity Protection</h1>
<p>Azure Identity Protection is a feature of Microsoft Enterprise Mobility + Security and is a premium feature in EMS E5.  We conducted a test to see if a user would be blocked while trying to log in from 2 separate locations.</p>
<p>We went to <a href="https://portal.azure.com/" target="_blank" rel="noopener noreferrer">https://portal.azure.com/</a> and logged in with credentials normally from our home office server.  I then created a 2012 Server virtual machine setting up and configuring Active Directory and <a href="https://www.evertoncollins.com/azure-ad-connect-sync-scheduler/">azure AD Connect.</a></p>
<p>Using the Tor browser I went to <a href="https://portal.azure.com/">portal.azure.com</a> to login with the same user a 2nd time.</p>
<h2>Our Results</h2>
<p><strong>Your sign-in was blocked</strong></p>
<div class="ca_section">
<div id="description"><em>We&#8217;ve detected something unusual about this sign-in.</em></div>
<div><em><br />
For example, you might be signing in from a new location, device, or app. </em></div>
<div><em>Before you can continue, we need to verify your identity.  Please contact your admin.</em></div>
<div></div>
<div><img fetchpriority="high" decoding="async" class="aligncenter wp-image-998 size-large" src="https://evertoncollins.com/wp-content/uploads/2017/09/azure-information-protection-01-1024x484.jpg" alt="" width="1024" height="484" /></div>
</div>
<div></div>
<div>After viewing more details we get a better picture of what scenario is; at this point to see that the user has tried to sign in a second time from an unknown location and has been blocked.</div>
<div></div>
<div></div>
<div><img decoding="async" class="aligncenter wp-image-999 size-large" src="https://evertoncollins.com/wp-content/uploads/2017/09/azure-information-protection-02-1024x531.jpg" alt="Azure identity Protection" width="1024" height="531" /></div>
<div></div>
<div>We can see from the message the sign-in was blocked.</div>
<div></div>
<div>
<div class="ca_header">
<div class="gianttext"><strong>Your sign-in was blocked</strong></div>
<div></div>
</div>
<div class="ca_section">
<div id="description"><em>We&#8217;ve detected something unusual about this sign-in. For example, you might be signing in from a new location, device, or app. </em></div>
<div><em>Before you can continue, we need to verify your identity. Please contact your admin.</em></div>
</div>
<div id="more_details_text" class="normaltext"><em> </em></div>
<div id="more_details_hiddenbydefault_text" class="">
<div id="contactadmin_text" class="normaltext">The following information might be useful to your administrator:</div>
<ul>
<li>App name: Azure Portal</li>
<li>App id: c44b4083-3bb0-49c1-b47d-974e53cbdf3c</li>
<li>IP address: 62.210.129.246</li>
<li>Device identifier: not available</li>
<li>Device platform: Windows 7</li>
<li>Device state: Unregistered</li>
<li>Signed in as rick.admin@nottstruckingltd.onmicrosoft.com</li>
<li>Correlation ID: 46d66b10-4f50-4e10-a5fb-15a11f06135a</li>
<li>Timestamp: 2017-09-18 20:29:55Z</li>
</ul>
</div>
<div id="switch_user_text" class="normaltext"><strong>Sign out and sign in with a different </strong><b>account</b></div>
</div>
<div></div>
<div>We will now create a sign-in risk policy.  Login to portal.azure.com -&gt; Azure AD Identity Protection -&gt;Sign-in risk policy</div>
<div></div>
<div></div>
<div><img decoding="async" class="aligncenter wp-image-1014 size-full" src="https://evertoncollins.com/wp-content/uploads/2017/09/risky-sign-in-policy.jpg" alt="risky-sign-in-policy" width="844" height="906" srcset="https://evertoncollins.com/wp-content/uploads/2017/09/risky-sign-in-policy.jpg 844w, https://evertoncollins.com/wp-content/uploads/2017/09/risky-sign-in-policy-279x300.jpg 279w, https://evertoncollins.com/wp-content/uploads/2017/09/risky-sign-in-policy-768x824.jpg 768w, https://evertoncollins.com/wp-content/uploads/2017/09/risky-sign-in-policy-300x322.jpg 300w" sizes="(max-width: 844px) 100vw, 844px" /></div>
<div>
<div class="container mainContainer" dir="ltr" lang="en-us" data-bi-name="body">
<div id="main">
<div>
<div class="content">
<h2 id="risky-sign-ins">Risky sign-ins</h2>
<p class="lf-text-block lf-block" data-lf-anchor-id="0fd0ada0e2b32ea83183f8e3637f6279:0">Azure Active Directory detects <a href="https://docs.microsoft.com/en-us/azure/active-directory/active-directory-reporting-risk-events#risk-event-types" target="_blank" rel="noopener noreferrer" data-linktype="relative-path">risk event types</a> in real-time and offline.</p>
<p class="lf-text-block lf-block" data-lf-anchor-id="0fd0ada0e2b32ea83183f8e3637f6279:0">Each risk event that has been detected for a sign-in of a user contributes to a logical concept called risky sign-in.</p>
<p class="lf-text-block lf-block" data-lf-anchor-id="0fd0ada0e2b32ea83183f8e3637f6279:0">A risky sign-in is an indicator of a sign-in attempt that might not have been performed by the legitimate owner of a user account.</p>
</div>
<p><a href="https://docs.microsoft.com/en-us/azure/active-directory/active-directory-identityprotection#what-is-a-user-risk-level" target="_blank" rel="noopener noreferrer">https://docs.microsoft.com/en-us/azure/active-directory/active-directory-identityprotection#what-is-a-user-risk-level</a></p>
</div>
</div>
</div>
</div><p>The post <a href="https://evertoncollins.com/azure-identity-protection-enterprise-mobility-security/">Azure Identity Protection – Enterprise Mobility + Security</a> first appeared on <a href="https://evertoncollins.com">Cloud Engineer - Everton Collins</a>.</p>]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
