If i have a CA Rule that says you need to be on a compliant device to access, and you Get phished on a compliant device. Will they be able to login? Since in signin the stolen token is logging in without the compliant device
Also, this is why we apply branding! We drive it into our users that if they enter their email address (nothing else) and their logo or background doesn't appear, it's not the right landing page. And hey, it's looks good anyway. So glad this has the attention of many, now. We've fought this for a while ourselves with other tenants we manage.
Lastpass??? Ugh
@BenatSaaSAlerts