We use Microsoft 365 Standard and have enabled Security Defaults ( -us/microsoft-365/admin/security-and-compliance/set-up-multi-factor-au... ) so thought that our accounts would be as secure as they could be without Conditional Access.
One of our users was Phished and emails were sent from their account. Checking the Interactive sign-in logs I can see the attacker attempted to login from Nigeria (we don't operate from Nigeria) using Chrome on Windows 10 and was denied login due to MFA (which is as expected - part log shown below)
Download File https://jfilte.com/2yMFfU
2 minutes after that attempt the attacker then tried using Safari on iOS 14 and this only asked for single factor authentication and let them in, which certainly wasn't expected! From there, they were able to monitor the email in this instance and send / modify emails until we detected them and locked them out. It could of been worse, we were lucky this time. The successful (part) log is shown below:
I have logged this with Microsoft but all they are concerned with is that the account is now secure and not the fact that with Security Defaults on and a phished account was accessed without MFA (and from a country we don't operate from).
I have since done some more testing with another account and after revoking sessions and MFA, they could login to the same PC they normally use and access www.office.com without MFA prompts only finally being asked when going into Security Settings in My Account. I can accept as the location this was from is the main office it might be flagged as safe by MS.
So then I used the same account to login from another clients office not associated with us (using a VM there) and again it was able to login to www.office.com without any MFA prompts, which again is quite concerning.
@Kat-UK I'm jumping in here too because I have been fighting this myself. I "thought" enabling security defaults would force all users to use MFA for all logins. That appears to not be the case. I help manage several small businesses that have Microsoft 365 Business Standard subscriptions. Over the past few months the admins of those accounts have been notified they needed to turn on Security defaults to protect their users because 99.9% of all compromises could have been prevented with MFA or something like that wording.
They all have enabled security defaults and yes, the admins are all forced through MFA. And yes, all users were forced to enroll in MFA. But in reviewing the login logs (7 day report in Entra) not a single 'normal' user has been forced through the MFA authentication. They all still get the single-authentication path.
Now none of them have the Premium or AAD P1 licenses so using conditional access isn't an option so I am assuming they are going to have to use per user MFA? Seriously, the whole Security Defaults documentation/recommendation stuff is misleading at best and down right confusing in reality.
The Accessibility Resources office is located on the ground floor of Capen Hall, in room 60, on the North Campus. Capen Hall is located adjacent to Flint Loop, on Mary Talbert Way. To get to our office:
Erin has worked extensively in the field of assistive technology, directing and managing projects related to assistive technology for persons of all ages. For more information about CAT services, visit -services.html
Stephanie meets with students to discuss their access requests and arrange academic accommodation and campus supports, working collaboratively with faculty and Accessibility Resources staff to explore equitable options for students.
Cassandra meets with students to discuss their access requests and arrange academic accommodation and campus supports, working collaboratively with faculty and Accessibility Resources staff to explore equitable options for students.
Francis Torres was appointed First Deputy Commissioner in February 2024.
Prior to this role, she served as Deputy Commissioner of the Division of Programs and Community Partnerships where she focused on the creation, implementation, and management of new educational, vocational, and programmatic opportunities for persons in custody while ensuring the well-being of staff. Ms. Torres has over 35 years of professional experience in the social services field. She joined the Department of Correction in 2002 as the Director of Educational Services and has risen through the ranks.
In this role, Ms. Torres will oversee and support the executive members leading care/wellness, facilities and fleet administration, health affairs, health management, programs and community partnerships, and the training and development division.
Ms. Torres earned her Master of Arts in Spanish Literature from the City University of New York.
Mr. Patrick Benn was appointed Deputy Commissioner of Facilities and Fleet Administration in May 2023.
Prior to joining DOC, Mr. Benn was the Director of Engineering and Construction at the New York City Health and Hospitals Corporation (HHC) where he directed, coordinated, evaluated, investigated, and recommended plans, and changes in various construction and renovation activities. He also prepared the scope and estimate costs of projects proposed, developed and updated cost estimates, and analyzed the construction phase and operating schedule to assure timely completion of projects with minimal disruption to surrounding activities. Prior to HHC, he was the Director of Facilities at SODEXO where he was responsible for budgets, staffing, short and long-term planning, program development, policy, and procedures for all facilities.
In his role, Mr. Benn will oversee a diverse team in facilities maintenance and repair, capital project/construction, and fleet management. He will also be responsible for developing and executing a framework to manage and schedule resources and staff to maintain all DOC jail and non-jail facilities to meet the operation priorities and standards of jail facilities in a state compliant with regulatory standards and aligned with best practices.
Mr. Benn studied facilities engineering and business at SUNY Maritime College. He is a licensed NYC Engineer. He is a member of several engineering associations including HSENY and ASHRAE.
Ms. Grey obtained her Bachelor of Arts in Political Science from the University of Pennsylvania and a Juris Doctor from the University of Virginia School of Law. She is also a member of various professional organizations such as the Nassau County Bar Association, the Queens Bar Association, and the Amistad Bar Association.
Yvonne Pritchett was appointed Deputy Commissioner of Investigations in August 2023.
Prior to this role, she was the Acting Deputy Commissioner of Investigations where she was responsible for performing highly confidential and sensitive work before transitioning to the Trials Division as an Associate Commissioner.
As the Deputy Commissioner, she will report directly to the Commissioner and will oversee the overall management of the department's investigations division. She will perform highly confidential and sensitive work in planning the start of departmental investigations. She will also be responsible for overseeing all facets of investigations and integrity control. She will serve as the liaison to the Departments of Investigation/Inspector General (DOI), the NYPD, and other law enforcement agencies.
Prior to joining DOC, Ms. Srinivasan served as the Executive Director of Budget Operations at the New York City Department of Social Services (DSS) where she was responsible for monitoring all budgetary issues affecting programs across the Department of Social Services, Human Resources Administration, and the Department of Homeless Services. She provided direction and technical guidance for the budget preparation process and ongoing activities to senior leadership. Prior to this, Ms. Srinivasan was the Director of the Office of Budget Administration at the New York City Human Resources Administration and a Budget analyst for the New York City Office of Management and Budget.
In this role, Ms. Srinivasan will lead several critical business units covering budget management and planning, financial management and budget administration, expense budget, capital budget, financial services, and the central office of procurement. She will be responsible for preparing and managing the agency budget testimonies and briefing materials for all public hearings with the NYC Council, NYC Board of Correction, NYS SCOS, and all other oversight entities. She will also provide leadership and guidance to planning and forecasting activities in critical areas of expenditures including uniform and civilian overtime, headcount/convergence planning, civilianization, and headcount management.
DC Young has delivered large-scale transformation initiatives in every major branch of the criminal justice system. DC Young brings a wealth of knowledge and experience that includes; developing technological solutions and evidence based strategies to improve jail operations and services. Before joining the department, DC Young was the Deputy Senior Vice President of Justice Initiatives for the Center for Policing Equity (CPE). DC Young was responsible for strategic planning, leading cross-functional initiatives, organizational design, and change management in this position.
Mr. Young also served as a police supervisor, SWAT Operator, and Undercover Detective in Southern California. DC Young was the first known line-level police officer to successfully integrate a major randomized controlled trial (RCT) within a policing organization. This mega-study was one of the largest multi-site RCTs in the history of criminal justice research.
Charlton Lemon was appointed Assistant Chief of Security in May 2024. He previously served in this capacity as Acting Assistant Chief since 2021. He began his career with the Department as a correction officer in 1987, assigned to the North Infirmary Command (NIC). In January 2001, he was promoted to the rank of captain and transferred to the George R. Vierno Center (GRVC).
Chief Lemon was subsequently promoted to Assistant Deputy Warden in April 2006, Deputy Warden in 2011 and served in the leadership of various facilities. In April 2015, Mr. Lemon was promoted to Wardenwhere he oversaw commands including the George Motchan Detention Center (GMDC), Security Operations Division (SOD), Manhattan Detention Complex (MDC), and the Vernon C. Bain Center (VCBC). Chief Lemon has dedicated over 36 years of his life as a uniformed member of service and leader at the New York City Department of Correction. He has an Associates and Applied Science Degree in Data Processing from the New York City Technical College.