5.2.2.6 Enable Identity Protection user risk policies

Information

Microsoft Entra ID Protection user risk policies detect the probability that a user account has been compromised.

Note: While Identity Protection also provides two risk policies with limited conditions, Microsoft highly recommends setting up risk-based policies in Conditional Access as opposed to the "legacy method" for the following benefits:

- Enhanced diagnostic data
- Report-only mode integration
- Graph API support
- Use more Conditional Access attributes like sign-in frequency in the policy

With the user risk policy turned on, Entra ID protection detects the probability that a user account has been compromised. Administrators can configure a user risk conditional access policy to automatically respond to a specific user risk level.

Solution

To remediate using the UI:

- Navigate to the Microsoft Entra admin center https://entra.microsoft.com.
- Expand Entra ID > Conditional Access and select Policies.
- Create a new policy by selecting New policy.

- Under Users or agents (Preview) choose All users
- Under Target resources choose All resources (formerly 'All cloud apps')

- Under Exclude exclude any break-glass accounts.

- Under Conditions choose User risk then Yes and select the user risk level High.
- Under Grant select Grant access then check Require multifactor authentication or Require authentication strength . Finally check Require password change.
- Under Session set Sign-in frequency to Every time.
- Click Select.

- Under Enable policy set it to Report-only.
- Click Create.
- After allowing the policy to run in Report-only mode for at least one week, review the Sign-in logs for any unexpected impact, then return to the policy and set Enable policy to On.

Impact:

Upon policy activation, account access will be either blocked or the user will be required to use multi-factor authentication (MFA) and change their password. Users without registered MFA will be denied access, necessitating an admin to recover the account. To avoid inconvenience, it is advised to configure the MFA registration policy for all users under the User Risk policy.

Additionally, users identified in the Risky Users section will be affected by this policy. To gain a better understanding of the impact on the organization's environment, the list of Risky Users should be reviewed before enforcing the policy.

See Also

https://workbench.cisecurity.org/benchmarks/24620

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-6, 800-53|AU-6(1), 800-53|AU-7(1), CSCv7|16.13

Plugin: microsoft_azure

Control ID: 82f08175fd7c6ac3ddf2b379a44c07c58c1c56f33322482885aa8293c2461812