Back to category

Week 7

Review Authentication Methods and Sign-In Security Controls

Beginner
IAM Engineer
NIST 800-53
Microsoft Security Best Practices
Authentication

Client Background

The client wants an independent review of which authentication methods are permitted for employees, including legacy protocols that may bypass modern security controls.

Business Environment

Northgate Utilities (650 employees) is a public utility with on-prem AD synced to a single Microsoft Entra ID tenant, supporting office staff and field crews using tablets over cellular. After several reported phishing incidents and an internal audit finding on legacy protocols, the CISO wants an independent review before authorizing a remote-work expansion that widens the attack surface.

Security Incident

No confirmed breach; the trigger was a recent internal audit flagged 'legacy authentication protocols permitted and MFA methods not reviewed,' combined with an uptick in credential-phishing emails targeting SCADA engineers, prompting this preemptive authentication review.

Scope

Authentication methods policy and legacy protocol usage across the tenant.

Objectives

  • Inventory allowed authentication methods
  • Identify legacy authentication protocols still in use
  • Review sign-in risk and session controls
  • Recommend authentication hardening steps

Required Deliverables

Authentication Security Review Report
2 hrs estimated