1.6 Ensure that 'Number of days before users are asked to re-confirm their authentication information' is not set to '0' - 0

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Ensure that the number of days before users are asked to re-confirm their authentication information is not set to 0.

Rationale:

If authentication re-confirmation is disabled, registered users will never be prompted to re-confirm their existing authentication information. If the authentication information for a user, such as a phone number or email changes, then the password reset information for that user reverts to the previously registered authentication information.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

From Azure Console

Go to Azure Active Directory

Go to Users

Go to Password reset

Go to Registration

Set the Number of days before users are asked to re-confirm their authentication information to your organization defined frequency

Default Value:

By default, the 'Number of days before users are asked to re-confirm their authentication information' is set to '180 days'.

See Also

https://workbench.cisecurity.org/files/3459