Week 7
Review Authentication Methods and Sign-In Security Controls
Client Background
The client wants an independent review of which authentication methods are permitted for employees, including legacy protocols that may bypass modern security controls.
Business Environment
Northgate Utilities (650 employees) is a public utility with on-prem AD synced to a single Microsoft Entra ID tenant, supporting office staff and field crews using tablets over cellular. After several reported phishing incidents and an internal audit finding on legacy protocols, the CISO wants an independent review before authorizing a remote-work expansion that widens the attack surface.
Security Incident
No confirmed breach; the trigger was a recent internal audit flagged 'legacy authentication protocols permitted and MFA methods not reviewed,' combined with an uptick in credential-phishing emails targeting SCADA engineers, prompting this preemptive authentication review.
Scope
Authentication methods policy and legacy protocol usage across the tenant.
Objectives
- Inventory allowed authentication methods
- Identify legacy authentication protocols still in use
- Review sign-in risk and session controls
- Recommend authentication hardening steps
Required Deliverables