{"id":13498,"date":"2025-04-21T12:01:11","date_gmt":"2025-04-21T00:01:11","guid":{"rendered":"https:\/\/kinetics.co.nz\/?p=13498"},"modified":"2025-04-21T12:01:11","modified_gmt":"2025-04-21T00:01:11","slug":"kinetics-kare-foundation-security-notice","status":"publish","type":"post","link":"https:\/\/new.kinetics.co.nz\/?p=13498","title":{"rendered":"Kinetics KARE Foundation Security Notice"},"content":{"rendered":"<p>[et_pb_section fb_built=&#8221;1&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_row _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; hover_enabled=&#8221;0&#8243; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221; sticky_enabled=&#8221;0&#8243;]<\/p>\n<h2>KARE Security Update Change Notice<\/h2>\n<p>In response to increased cyber-activity, Kinetics is planning to roll out two changes across all KARE Foundation subscribers.\u00a0\u00a0This change only impacts subscribers on <a href=\"https:\/\/new.kinetics.co.nz\/cybersecurity\/\">KARE Foundation<\/a> or <a href=\"https:\/\/new.kinetics.co.nz\/kare-security-plus\/\">KARE Security Plus<\/a> plans.<\/p>\n<p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<\/p>\n<h2>1. Multifactor Authentication (MFA) <span style=\"font-size: 14px; color: #666666; font-family: 'Helvetica Neue', Helvetica, Arial, sans-serif; font-weight: 500;\">\u00a0 <\/span><strong style=\"font-size: 14px; color: #666666; font-family: 'Helvetica Neue', Helvetica, Arial, sans-serif;\"><\/strong><\/h2>\n<p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<\/p>\n<p>Most subscribers are already using these settings but there are a few that have opted for a reduced level of MFA security.\u00a0 We are now increasing the setting for all clients unless we are specifically asked not to.\u00a0 \u00a0<strong>In the week commencing May 12th, we will be turning on &#8216;geo-locking&#8217; and &#8216;number matching&#8217; for ALL Multi-Factor Authentication (MFA) use, subject to your version of 365 supporting these options.\u00a0 We expect it will take us just over a week to roll this change out across all subscribers.<\/strong><\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row column_structure=&#8221;1_2,1_4,1_4&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; background_enable_color=&#8221;off&#8221; custom_padding=&#8221;20px|20px|20px|20px|false|false&#8221; border_radii=&#8221;on|20px|20px|20px|20px&#8221; border_width_all=&#8221;2px&#8221; border_color_all=&#8221;#222222&#8243; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_column type=&#8221;1_2&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<\/p>\n<p>These have been options and many of our clients have already opted to turn them on.\u00a0 It is our intent to now make this our default setting. For what it is worth, we understand that Microsoft might be about to do the same.<\/p>\n<p>There will be no cost for this change, but this will limit users to only accessing their systems in New Zealand and Australia. Any users travelling overseas\u00a0 beyond Australia will need to contact us to have their access relaxed for the period of their travel and their destination and this will incur a small charge.\u00a0 If your organisation does a lot of overseas travel, then we can setup a self-service function for you on request.<\/p>\n<p>if you have staff based permanently overseas, we will adjust their geo-lock for the country in which they work.\u00a0 We have a number of clients with staff based in North America, Europe or Asia and understand the need to look out for them.<\/p>\n<p><strong>If you do not wish it to be turned on for you, please let us know.<\/strong><\/p>\n<p>[\/et_pb_text][\/et_pb_column][et_pb_column type=&quot;1_4&quot; _builder_version=&quot;4.27.4&quot; _module_preset=&quot;default&quot; global_colors_info=&quot;{}&quot; theme_builder_area=&quot;post_content&quot;][et_pb_image src=&quot;https:\/\/new.kinetics.co.nz\/wp-content\/uploads\/2022\/12\/2022Authenticator.jpg&quot; title_text=&quot;2022Authenticator&quot; align=&quot;center&quot; _builder_version=&quot;4.27.4&quot; _module_preset=&quot;default&quot; max_height=&quot;350px&quot; border_radii=&quot;on|20px|20px|20px|20px&quot; border_width_all=&quot;2px&quot; border_color_all=&quot;#222222&quot; border_style_all=&quot;ridge&quot; global_colors_info=&quot;{}&quot; theme_builder_area=&quot;post_content&quot;][\/et_pb_image][\/et_pb_column][et_pb_column type=&quot;1_4&quot; _builder_version=&quot;4.27.4&quot; _module_preset=&quot;default&quot; global_colors_info=&quot;{}&quot; theme_builder_area=&quot;post_content&quot;][et_pb_image src=&quot;https:\/\/new.kinetics.co.nz\/wp-content\/uploads\/2022\/12\/MFAUpdates.png&quot; title_text=&quot;MFAUpdates&quot; align=&quot;center&quot; _builder_version=&quot;4.27.4&quot; _module_preset=&quot;default&quot; max_height=&quot;350px&quot; global_colors_info=&quot;{}&quot; theme_builder_area=&quot;post_content&quot;][\/et_pb_image][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=&quot;4.27.4&quot; _module_preset=&quot;default&quot; custom_padding=&quot;|||1px||&quot; global_colors_info=&quot;{}&quot; theme_builder_area=&quot;post_content&quot;][et_pb_column type=&quot;4_4&quot; _builder_version=&quot;4.27.4&quot; _module_preset=&quot;default&quot; global_colors_info=&quot;{}&quot; theme_builder_area=&quot;post_content&quot;][et_pb_text _builder_version=&quot;4.27.4&quot; _module_preset=&quot;default&quot; global_colors_info=&quot;{}&quot; theme_builder_area=&quot;post_content&quot;]<\/p>\n<h2><span style=\"font-size: 14px; color: #666666; font-family: 'Helvetica Neue', Helvetica, Arial, sans-serif; font-weight: 500;\">We appreciate that MFA can be an inconvenience.\u00a0 Nonetheless, it has become one of the most effective tools to protect you from cyber-crime.\u00a0<\/span><\/h2>\n<p>However, MFA is not infalliable.\u00a0 Please remain on your guard and report anything that seems suspicious.\u00a0\u00a0<\/p>\n<p>Geo-locking can be overcome by VPNs, and hackers can steal your MFA token with a &#8216;man-in-the-middle&#8217; attacks.\u00a0 These are where they have a fake 365 login page and try to trick you into entering your details including your MFA code.\u00a0 KARE Foundation includes an<a href=\"https:\/\/new.kinetics.co.nz\/breaking-news-new-protections-added-to-kinetics-kare-foundation\/\"> AI-powered browser scanner<\/a> that works to detect these fakes.\u00a0 Nonetheless, security is all about layers or protection, and <strong>you are one of those layers<\/strong>!\u00a0\u00a0<\/p>\n<p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; custom_padding=&#8221;10px|10px|10px|10px|false|false&#8221; border_width_all=&#8221;1px&#8221; border_color_all=&#8221;#222222&#8243; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<\/p>\n<p><strong>Finally, a note from a recent customer experience.\u00a0 If you experience many MFA prompts in a short time, and you know you aren&#8217;t trying to access your system, please don&#8217;t hit &#8216;accept&#8217;.\u00a0 Instead contact us for help.\u00a0 \u00a0Remember that you can put your phone on &#8216;silent&#8217; or flight mode, albeit that makes it harder for us to call you back.<\/strong><\/p>\n<p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<\/p>\n<p><strong>For more info, refer to<\/strong> <a href=\"https:\/\/learn.microsoft.com\/en-us\/entra\/identity\/authentication\/how-to-mfa-number-match\">How number matching works in MFA push notifications for Authenticator &#8211; Microsoft Entra ID | Microsoft Learn<\/a><\/p>\n<p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<\/p>\n<h2>2. Restricting Enterprise Applications in 365<\/h2>\n<p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<\/p>\n<p>To ensure the safety in your Microsoft tenant, Kinetics are planning to adjust the application permission settings in line with best practice.\u00a0 This means that either Kinetics, onsite IT or designated staff will be required to approve the application. This only needs to be done once per application.\u00a0 The approval prompt will look similar to the image below.<\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row column_structure=&quot;1_2,1_2&quot; _builder_version=&quot;4.27.4&quot; _module_preset=&quot;default&quot; global_colors_info=&quot;{}&quot; theme_builder_area=&quot;post_content&quot;][et_pb_column type=&quot;1_2&quot; _builder_version=&quot;4.27.4&quot; _module_preset=&quot;default&quot; global_colors_info=&quot;{}&quot; theme_builder_area=&quot;post_content&quot;][et_pb_image src=&quot;https:\/\/new.kinetics.co.nz\/wp-content\/uploads\/2025\/04\/EnterpriseAppsBlocked.png&quot; title_text=&quot;EnterpriseAppsBlocked&quot; _builder_version=&quot;4.27.4&quot; _module_preset=&quot;default&quot; border_radii=&quot;on|20px|20px|20px|20px&quot; border_width_all=&quot;1px&quot; border_color_all=&quot;#222222&quot; box_shadow_style=&quot;preset1&quot; global_colors_info=&quot;{}&quot; theme_builder_area=&quot;post_content&quot;][\/et_pb_image][\/et_pb_column][et_pb_column type=&quot;1_2&quot; _builder_version=&quot;4.27.4&quot; _module_preset=&quot;default&quot; global_colors_info=&quot;{}&quot; theme_builder_area=&quot;post_content&quot;][et_pb_text _builder_version=&quot;4.27.4&quot; _module_preset=&quot;default&quot; global_colors_info=&quot;{}&quot; theme_builder_area=&quot;post_content&quot;]<\/p>\n<p>If there is no designated staff member or IT staff on site, please raise an IT service request after requesting app approval.<\/p>\n<p>&nbsp;<\/p>\n<h3>Why are we making this change?<\/h3>\n<p>Microsoft have recommended the change because of the increasingly challenging security environment.\u00a0 These &#8216;enterprise applications&#8217; can act on behalf of users and can have the same access as the users.\u00a0 They are also able to bypass multifactor authentication.\u00a0 This means that if you consent to an &#8216;enterprise application&#8217; it could read all your data as well as send out mail as if it came you. It is scary to realise you could inadvertently give this access in just one click.<\/p>\n<h3>Existing Applications<\/h3>\n<p>Please note that this will have no impact on any applications that have already been added.\u00a0 It will only impact NEW requests.<\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>KARE Security Update Change Notice In response to increased cyber-activity, Kinetics is planning to roll out two changes across all KARE Foundation subscribers.\u00a0\u00a0This change only impacts subscribers on KARE Foundation or KARE Security Plus plans.1. Multifactor Authentication (MFA) \u00a0 Most subscribers are already using these settings but there are a few that have opted for [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":13517,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"on","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[4],"tags":[],"class_list":["post-13498","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"_links":{"self":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts\/13498","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=13498"}],"version-history":[{"count":0,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts\/13498\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/"}],"wp:attachment":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=13498"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=13498"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=13498"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}