5.2.2.7 Enable Identity Protection sign-in risk policies

Information

Microsoft Entra ID Protection sign-in risk detects risks in real-time and offline. A risky sign-in is an indicator for a sign-in attempt that might not have been performed by the legitimate owner of a user account.

Note: While Identity Protection also provides two risk policies with limited conditions, Microsoft highly recommends setting up risk-based policies in Conditional Access as opposed to the "legacy method" for the following benefits:

- Enhanced diagnostic data
- Report-only mode integration
- Graph API support
- Use more Conditional Access attributes like sign-in frequency in the policy

Turning on the sign-in risk policy ensures that suspicious sign-ins are challenged for multi-factor authentication.

Solution

To remediate using the UI:

- Navigate to the Microsoft Entra admin center https://entra.microsoft.com.
- Expand Entra ID > Conditional Access and select Policies.
- Create a new policy by selecting New policy.

- Under Users or agents (Preview) choose All users.
- Under Target resources choose All resources (formerly 'All cloud apps').

- Under Exclude exclude any break-glass accounts.

- Under Conditions choose Sign-in risk then Yes and check the risk level boxes High and Medium.
- Under Grant click Grant access then select Require multifactor authentication.
- Under Session select Sign-in Frequency and set to Every time.
- Click Select.

- Under Enable policy set it to Report-only.
- Click Create.
- After allowing the policy to run in Report-only mode for at least one week, review the Sign-in logs for any unexpected impact, then return to the policy and set Enable policy to On.

Impact:

When the policy triggers, the user will need MFA to access the account. In the case of a user who hasn't registered MFA on their account, they would be blocked from accessing their account. It is therefore recommended that the MFA registration policy be configured for all users who are a part of the Sign-in Risk policy.

See Also

https://workbench.cisecurity.org/benchmarks/24620

Item Details

Category: AUDIT AND ACCOUNTABILITY, IDENTIFICATION AND AUTHENTICATION

References: 800-53|AU-6, 800-53|AU-6(1), 800-53|AU-7(1), 800-53|IA-2(1), 800-53|IA-2(2), CSCv7|16.13

Plugin: microsoft_azure

Control ID: e24121672662bd465ce5905446c996d960b69d179b0db5c68dfeda03c7fe3ea4