Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Three Layers of Power Pages Security: CAPTCHA, WAF, and Azure DDoS Protection

When designing a public-facing Microsoft Power Pages website, three security controls frequently appear: CAPTCHA, Web Application Firewall (WAF), and Azure DDoS Protection. Although all three help address malicious traffic, they operate at different layers, have different scopes, and cannot replace one another.

How to Disable 2FA in Microsoft Entra ID

Author: Forrest Zhang

Disabling two-factor authentication in Microsoft Entra ID is not always a single-setting change. In many tenants, MFA can be enforced from several different places, so turning off one control does not necessarily stop sign-in prompts.

The practical issue is that administrators often disable Security Defaults and still see users prompted to register Microsoft Authenticator or complete MFA. Based on Microsoft documentation, that usually means another enforcement path is still active, such as the registration campaign, Conditional Access, per-user MFA, authentication method settings, or Microsoft’s mandatory MFA requirements for certain admin portals.