| Identity as a Perimeter and Modernization Program Microsoft Entra ID, Windows Hello for Business, Passkeys, and Conditional Access 1. Project Overview CenterPoint Energy seeks to modernize enterprise identity security through the deployment and enforcement of phishing-resistant authentication across the Microsoft Entra ID environment. The initiative will establish Windows Hello for Business (WHfB) as the primary enterprise authentication method and implement passwordless authentication through Passkeys, Microsoft Authenticator Passwordless, and FIDO2 security keys where appropriate. The project will further strengthen Zero Trust identity controls through Conditional Access optimization, Continuous Access Evaluation (CAE), device trust validation, Identity Protection integration, and administrative security hardening. 2. Project Objectives The objectives of this engagement are to: - Eliminate reliance on passwords for daily authentication.
- Reduce phishing, MFA fatigue, token theft, and credential compromise risks.
- Establish phishing-resistant authentication as the enterprise standard.
- Improve identity security posture consistent with NIST CSF 2.0 and Zero Trust principles.
- Enhance Conditional Access governance and policy enforcement.
- Strengthen administrator authentication requirements.
- Improve contractor and B2B identity controls.
- Leverage device health and compliance signals as authentication controls.
- Enable Continuous Access Evaluation (CAE) for near real-time access revocation.
- Establish operational processes for passwordless onboarding, recovery, and lifecycle management.
3. Scope Phase 1 Rapid assessment and planning Review current state: - Microsoft Entra ID tenant configuration
- Authentication methods policy
- Passwordless readiness
- Existing Conditional Access policies
- MFA deployment status
- Identity Protection configuration
- Device compliance posture
- Enrollment processes
- Administrative account architecture
- B2B config settings
Deliverables - Current-state assessment
- Gap analysis
- Passwordless config
- Deployment plan
Phase 2 Windows Hello for Business Enforcement (Under progress now, we need some light touch here) Windows Hello for Business Deployment Configure and enforce WHfB for all CNP devices using GPO and InTune: - Employees
- Corporate laptops
- Microsoft-managed endpoints
- Hybrid and cloud-joined devices
Configuration Activities - GPO
- TPM-backed credential enforcement
- Biometric authentication enablement
- PIN policy standardization
- Intune policy deployment
- Enrollment automation
- Compliance reporting
Deliverables - Deployment configuration
- Enrollment procedures
- Support documentation
Phase 3 Enterprise Passwordless Authentication Microsoft Authenticator Passwordless Deploy: - Passwordless phone sign-in
- Phish-resistant MFA controls
- Authentication method policies
Passkey Deployment Enable and enforce passkeys for: Employees - Microsoft Authenticator Passkeys
- Device-bound passkeys
- Cross-platform passkeys (approved scenarios)
Privileged Administrators (A accounts) - Passkeys required
- Hardware-backed authenticators preferred
- Dedicated administrative accounts
- Phishing-resistant authentication enforcement
Contractors - Passkeys where mobile devices are supported
- FIDO2 security keys for shared workstation environments
- Strong authentication onboarding process
B2B Users - Trust external MFA and require phishing-resistant authentication
- Passkey registration
Temporary Access Pass (TAP) Implement TAP process for: - New hires
- Authentication recovery
- Device replacement
- Lost passkeys
- Lost security keys
Phase 4 FIDO2 Security Key Program Security Key Deployment Implement FIDO2 security keys for specific users such as: - Privileged administrators
- Break-glass accounts
- Contractors
Deliverables - Develop the process for lifecycle management
- Lost/stolen key process, ordering and replacement
- FIDO2 inventory process
4. Conditional Access Modernization Conditional Access Policy Review Implement CA Policy Standards Require: Block: - Legacy authentication and High-risk authentication methods
- Weak MFA methods including SMS and Phone Calls
User-Based Policies Improve CA Policy controls for: - Employees
- Contractors
- B2B users
- Privileged administrators
- Service accounts
Application Policies Protect: - Microsoft 365 - for example - review mailbox sharing permissions to prevent excessive sharing (including company-wide access). Process to prevent this reoccurring.
- Azure Portal
- Service accounts to be protected and allow sign-in access from approved/trusted IP addresses only.
- Privileged applications
- SaaS platforms
Session Controls Configure: - Sign-in frequency
- Risk-based access
- Continuous access evaluation
Deliverables - CA policy cleanup for clarity and consistency
- Optimize and enhance CA policies
5. Device Trust and Health Controls Intune and Device Compliance Enhancement Implement Conditional Access enforcement based on: Device Health Require: - Entra registered/joined devices
- Managed devices
- Compliant devices
Compliance Signals Validate: - BitLocker enabled
- TPM available
- Defender active
- CrowdStrike EDR active (primary)
- Domain joined and OS supported
- Secure Boot enabled
- Palo Alto VPN enabled
Deliverables - Device compliance configuration and rollout
- Compliance policies
- Reporting dashboard
6. Continuous Access Evaluation (CAE) CAE Enablement Implement and validate: - Continuous Access Evaluation
- Real-time session revocation
- Token invalidation upon risk events
- Location change enforcement
- Privilege change enforcement
Deliverables - CAE configuration
- Validation and operational procedures
7. Reporting Develop: - Authentication adoption metrics
- Passwordless enrollment metrics
- CA compliance reporting
- Device health reporting
- Executive dashboards
Example KPIs - % WHfB Enrollment
- % Passkey Adoption
- % Passwordless Authentication Usage
- % CA Coverage
- % Compliant Devices
- Privileged Account Passwordless Adoption
- High-Risk Sign-In Reduction
8. Change Management, Knowledge Transfer & Operational Hand-off Provide: - IAM Administrative training
- Service Desk training
- IAM operational procedures
- User communications
|