EIDCA-017: High-Risk User Notification to Administrators

Platform
Entra ID / M365
Category
Entra ID Conditional Access
Severity
Medium
Zero Trust pillar
Identity (weight 3)
Golden fixtures
1
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

Identity Protection can email administrators when users are flagged as high-risk, enabling proactive investigation and containment of likely account compromise as it occurs. SCuBA recommends that such a notification be sent to administrators when high-risk users are detected. The Identity Protection 'Users at risk detected' notification recipient configuration is not exposed through a stable read-only Microsoft Graph endpoint, so an agentless assessment cannot positively confirm it; this check surfaces the requirement honestly and reports whether the supporting risk-detection telemetry is even available in the tenant rather than asserting compliance it cannot verify.

Recommended value

Identity Protection configured to email administrators when high-risk users are detected

Remediation

Configure the high-risk user notification, satisfying SCuBA MS.AAD.2.2. In Entra ID go to Protection > Identity Protection > Notifications and set 'Users at risk detected' alerts to email the appropriate security administrators or a monitored security operations distribution list. This control requires Entra ID P2 (Identity Protection). Because the notification recipient list is not readable agentlessly via Microsoft Graph, verify the setting manually in the portal.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for EIDCA-017
ScenarioExpected verdict
not-implementedNot Assessed

Framework mappings

CISA SCuBA
MS.AAD.2.2v1
NIST SP 800-53
SI-4, IR-6, AU-6
MITRE ATT&CK
T1078.004