Mobile Device Management - Ensure Mobile Devices Are Set To Wipe On Multiple Sign-in Failures To Prevent Brute Force Compromise

 








Summary

Require mobile devices to wipe on multiple sign-in failures.

Reason

Devices without this protection are generally vulnerable to being accessed physically by attackers who can then steal account credentials, data, or install malware on the device. 

What If?

This setting should not cause any noticeable impact, however, if a user mistypes their password multiple times and causes their device to wipe, then, it will have high user impact. 

How to?

To set mobile device management profiles, use the Microsoft 365 Admin Center:
  1. Under Admin Centers pick Endpoint Management.
  2. Select Devices and then under Policy select Configuration profiles
  3. Select Create Profile
  4. Set a Name for the policy, choose the appropriate Platform and select Device restrictions.
  5. In the Password section, make sure that Number of sign-in failures before wiping devices is set to 10.  

Monitor:

To verify mobile device management profiles, use the Microsoft 365 Admin Center:
  1. Under Admin Centers pick Endpoint Management.
  2. Select Devices and then under Policy select Configuration profiles
  3. Review the list of profiles. Ensure that a profile exists for each Platform.
  4. Review the Password section under Device restrictions and verify Number of sign-in failures before wiping devices is set to 10.  



Comments

Popular posts from this blog

Query, Visualize, & Monitor Data in Azure Sentinel

Planning for Implementing SAP Solutions on Azure (Part 2 of 5)

Work with String Data Using KQL Statements