EIDAUTH-012: SSPR Methods and Requirements

Platform
Entra ID / M365
Category
Entra ID Authentication Methods & MFA
Severity
Medium
Zero Trust pillar
Identity (weight 3)
Golden fixtures
1
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

The specific methods allowed for SSPR and the number required directly impact the security of the password reset process. Allowing weak methods such as security questions or requiring only a single method creates opportunities for attackers to reset passwords through social engineering or OSINT. Organizations should require at least two strong methods for all password resets.

Recommended value

Two or more strong authentication methods required for password reset, security questions disabled

Remediation

Navigate to Entra ID > Protection > Password reset > Authentication methods. Set the number of methods required to 2 and remove security questions from the allowed methods list. Prioritize mobile app notification and mobile app code as the primary SSPR methods to ensure strong verification.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for EIDAUTH-012
ScenarioExpected verdict
not-implementedNot Assessed

Framework mappings

NIST SP 800-53
IA-5(1)
CIS M365 Benchmark
5.2.4