Identity Innovation for a More Secure Nation
With more than 1000 identity attacks occurring each second1, government agencies are tasked with serving the public amidst the most challenging cybersecurity environment in history. Protecting the freedom of citizens makes them a prime target for bad actors across the cyberthreat ecosystem, from nation-state attacks on our infrastructure to identity compromise. Expanding security threats put federal agencies and their most critical data at risk.
With recent innovations like phishing-resistant multifactor authentication (MFA) from Azure Active Directory - part of Microsoft Entra - government customers can deliver on their policy objectives, while adhering to cybersecurity guidelines and regulatory compliance.
In January of last year, the National Security Memo (NSM-8) was issued to direct civilian agencies to use passwordless and phishing-resistant multifactor authentication (MFA). Agencies hit their deadlines for compliance last month. We are delighted to help many of these agencies through key capabilities which help them meet their objectives, as they strive to serve the public.
Peace of mind through modern strong authentication
As a response to the NSM-8 and the Executive Order (EO 14028) on Improving the Nation's Cybersecurity, Microsoft has developed strong authentication methods that help agencies to do the following:
Remove the threat and costs of legacy, on-premises federated servers
Securely authenticate users with Certificate-Based Authentication (CBA) with certificates such as Common Access Card (CAC) and Personal Identity Verification (PIV) Card used by US Federal Agencies and the US Department of Defense. This supports CBA while reducing the attack surface and costs associated with legacy on-premises IT infrastructure.
Use the right MFA method for the right resources
Roll out modern, easy to use and phishing resistant authentication methods. Conditional Access Authentication Strengths helps you increase security while moving to phishing-resistant MFA and ensuring critical assets are protected.
Facilitate cross-agency collaboration
Combine phishing-resistant authentication (such as Azure Active Directory CBA, FIDO2, Windows Hello for Business) with Conditional Access Authentication Strengths with Cross-Tenant Access Policies to fully realize secure collaboration with other government agencies and commercial partners/contractors in any Microsoft cloud, while maintaining compliance.
Microsoft can help
Public servants deserve the flexibility to do their jobs using modern identity tools and modern mobility, maximizing productivity while still achieving the highest level of security – so they can focus on serving the public without worrying about identity attacks.
We’re proud to continue our partnership with government agencies to leverage strong authentication identity solutions that can help ensure data and identities are protected against even the most severe security threats.
To learn more about Microsoft’s work in implementing Executive Order 14028 and phishing-resistant MFA, please read more here:
US Government sets forth Zero Trust architecture strategy and requirements.
Best regards,
Alex Weinert (@Alex_T_Weinert)
VP Director of Identity Security, Microsoft
1 According to Microsoft Azure Active Directory (Azure AD) authentication log data. 2022.
Learn more about Microsoft identity:
- Get to know Microsoft Entra – a comprehensive identity and access product family
- Return to the Microsoft Entra (Azure AD) blog home
- Join the conversation on Twitter and LinkedIn
- Share product suggestions on the Entra (Azure AD) forum
Published on:
Learn moreWe can help you with Identity Innovation for a More Secure Nation
If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.
Related posts
Sync identities from Rippling to Microsoft Entra ID
Today, we’re thrilled to announce that customers using Rippling HCM can now automatically provision users to on-premises Active Directory and ...
Microsoft Entra ID Governance for government
I’m pleased to announce that as of November 1, 2024, Microsoft Entra ID Governance is available for federal agencies, state and local governme...
Update to security defaults
As part of the Secure Future Initiative, we’ve evolved our security approach to align with three security principles: secure by design, secure...
Meet Microsoft Entra at Ignite 2024: November 18-22
Microsoft Ignite is just around the corner, taking place from Monday, November 18, 2024 through Friday, November 22, 2024, in Chicago, Illinoi...
Manage Microsoft Entra ID role assignments with Microsoft Entra ID Governance
I’m excited to announce that we now support Microsoft Entra role assignments in Microsoft Entra ID Governance's Entitlement Management feature...
The latest enhancements in Microsoft Authenticator
Hi folks, I'm thrilled to announce three major Microsoft Entra ID advancements that will help you protect your users with phishing-resi...
Microsoft Security announcements and demos at Authenticate 2024
The Microsoft Security team is excited to connect with you next week at Authenticate 2024 Conference, taking place October 14 to 16 in Carlsba...
What's new in Microsoft Entra - September 2024
We’re excited to announce the general availability of Microsoft Entra Suite—one of the industry’s most comprehensive secure access solutions f...
Explore the key benefits of Microsoft Entra Private Access
The traditional network security models are becoming increasingly ineffective in a world where remote work and cloud services are the norm. Co...
Join us at the Microsoft Entra Suite Showcase!
This fall, we are bringing the Microsoft Entra Suite Showcase to cities worldwide. Join us to explore how our latest advancements in secure id...