@@ -21,14 +21,14 @@ Accounts that are assigned administrative rights are targeted by attackers. Requ
21
21
22
22
Microsoft recommends you require MFA on the following roles at a minimum:
23
23
24
- * Global administrator
25
- * SharePoint administrator
26
- * Exchange administrator
24
+ * Billing administrator
27
25
* Conditional Access administrator
28
- * Security administrator
26
+ * Exchange administrator
27
+ * Global administrator
29
28
* Helpdesk (Password) administrator
30
29
* Password administrator
31
- * Billing administrator
30
+ * Security administrator
31
+ * SharePoint administrator
32
32
* User administrator
33
33
34
34
Organizations can choose to include or exclude roles as they see fit.
@@ -52,14 +52,14 @@ The following steps will help create a Conditional Access policy to require thos
52
52
1 . Give your policy a name. We recommend that organizations create a meaningful standard for the names of their policies.
53
53
1 . Under ** Assignments** , select ** Users and groups**
54
54
1 . Under ** Include** , select ** Directory roles (preview)** and choose the following roles at a minimum:
55
- * Global administrator
56
- * SharePoint administrator
57
- * Exchange administrator
55
+ * Billing administrator
58
56
* Conditional Access administrator
59
- * Security administrator
57
+ * Exchange administrator
58
+ * Global administrator
60
59
* Helpdesk administrator
61
60
* Password administrator
62
- * Billing administrator
61
+ * Security administrator
62
+ * SharePoint administrator
63
63
* User administrator
64
64
1 . Under ** Exclude** , select ** Users and groups** and choose your organization's emergency access or break-glass accounts.
65
65
1 . Select ** Done** .
0 commit comments