Some interesting comments in the the thread here;
TOP @azuread policy recommendations:
— Yusuf Dikmenoglu (@YusufsDSBlog) July 6, 2019
1. Azure MFA for Admins -
2. Risk-based MFA for users -
3. Require compliant PCs -
4. Mobile app protection -
5. Require approved app - https://t.co/k5kfEmDdKy
MS link;
Identity and device access configurations - Microsoft 365 for enterprise - Office 365
Describes Microsoft recommendations and core concepts for deploying secure email, docs, and apps policies and configurations.
