Duo
Multi-factor authentication
MFA across remote access, VPN, servers and applications, including systems outside Microsoft 365. Useful where authentication has to cover more than the Microsoft tenant.
Cybersecurity
Identity is the modern perimeter. Mayer Networks implements multi-factor authentication, conditional access, privileged account separation and identity monitoring so a stolen password is not enough to enter your systems.
Security lifecycle
MFA is a Protect control and identity threat detection is a Detect control. Together they cover the attack path that begins with a working password rather than malware. See the full Mayer Networks cybersecurity approach.
What it is
Most compromises we are called into begin with a valid credential, not with malware. Passwords are phished, reused, bought from previous breaches and guessed. Once one works, the attacker is inside as a legitimate user and much of the security stack has no reason to object.
Multi-factor authentication adds a second verification factor, so a stolen password on its own does not open email, remote access or administrative systems. Identity threat detection and response, or ITDR, watches identity behaviour after sign-in: suspicious authentication, unexpected persistence, mailbox rule changes, privilege changes and account abuse.
Identity is the perimeter now. It deserves the same attention the firewall used to receive.
The problem it solves
These are the attack paths that a password alone cannot close.
How Mayer Networks uses it
Rollouts fail when they surprise people. The implementation detail is what decides whether the control holds.
Every account is identified, especially administrative and service accounts, along with where each is allowed to sign in from.
MFA is enforced in a communicated sequence with support available, so adoption succeeds instead of generating exceptions that hollow out the policy.
Legacy authentication protocols are blocked where possible, because they route around the requirement entirely, and number matching is used to counter approval fatigue.
Where the tenant supports it, sign-in is restricted by device, location or risk level so trusted work is smooth and risky sign-ins are challenged or blocked.
Administrative access is separated from daily accounts, break-glass access is documented and protected, and service accounts get restrictions rather than blanket exemptions.
Identity alerts feed the detection workflow, so an impossible-travel sign-in or a new forwarding rule is investigated rather than logged.
Platform
Which platform fits depends on what the organization already licenses and what needs protecting beyond Microsoft 365.
Multi-factor authentication
MFA across remote access, VPN, servers and applications, including systems outside Microsoft 365. Useful where authentication has to cover more than the Microsoft tenant.
Identity in the Microsoft tenant
MFA and conditional access policies inside Microsoft 365, configured against the licensing the organization holds. Frequently the right starting point for Microsoft-centric environments.
Identity threat detection and response
Detection of suspicious identity behaviour in Microsoft 365, including unexpected persistence and account abuse, feeding the same investigation workflow as endpoint detections.
Duo is a Cisco product. Microsoft and Entra are trademarks of Microsoft Corporation. Mayer Networks is not affiliated with or endorsed by these vendors.
Layered defence
MFA removes the largest single category of incident. It does not cover the others.
Identity is the highest-value single control on most roadmaps, and it is still one layer of several.
Lifecycle stage: Protect and Detect
The layers most closely connected to this one. Each covers a front this control does not.
We can review where MFA is enforced today, which accounts are exempt, and whether legacy authentication is still leaving a way around it.
Review Identity and MFA CoverageMost compromises we are called into begin with a valid credential rather than malware. Multi-factor authentication on email, remote access and administrative accounts removes the majority of that category, and it is inexpensive relative to almost anything else on a security roadmap.
Implementation detail decides whether it holds. Legacy authentication protocols must be blocked or they bypass the requirement entirely; service and shared accounts need a plan rather than an exemption; break-glass administrative access must exist and be documented before it is needed; and push fatigue is countered with number matching rather than by asking people to be more careful.
A well-planned rollout keeps prompts infrequent for trusted devices while still protecting risky sign-ins.
It is far better than nothing, but app-based or hardware methods resist interception and are preferred.
Where those applications support modern authentication, yes. Where they do not, other controls such as network restrictions apply.
Service accounts are inventoried, restricted, given strong credentials and monitored, since they usually cannot use MFA.
Tell us what you are running and what is not working. We will tell you plainly what we would do about it.