Information
Ensure that users are notified on their primary and alternate emails on password resets.
User notification on password reset is a proactive way of confirming password reset activity. It helps the user to recognize unauthorized password reset activities.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.
Solution
Remediate from Azure Portal
- From Azure Home select the Portal Menu
- Select Microsoft Entra ID
- Under Manage select Users
- Under Manage select Password reset
- Under Manage select Notifications
- Set Notify users on password resets? to Yes
- Click Save
Impact:
Users will receive emails alerting them to password changes to both their primary and alternate emails.