Mitigations
There are several mitigations that can be employed to improve the security of AAD and protect against attacks such as enumeration, token theft, consent grant attacks, PTA, and SSO attacks. One way to start is by enabling security defaults in your AAD tenant, which provides a baseline level of security for all users, including requiring MFA and blocking legacy authentication protocols. Please also have a look into the quick security wins that Microsoft recommends:
- https://learn.microsoft.com/en-us/azure/active-directory/fundamentals/concept-fundamentals-mfa-get-started
- https://learn.microsoft.com/en-us/azure/active-directory/fundamentals/identity-secure-score
- https://learn.microsoft.com/en-us/azure/active-directory/fundamentals/concept-secure-remote-workers
- https://learn.microsoft.com/en-us/azure/active-directory/fundamentals/five-steps-to-full-application-integration-with-azure-ad
- https://learn.microsoft.com/en-us/azure/active-directory/fundamentals...