EIDCA-017: High-Risk User Notification to Administrators
- Platform
- Entra ID / M365
- Category
- Entra ID Conditional Access
- Severity
- Medium
- Zero Trust pillar
- Identity (weight 3)
- Golden fixtures
- 1
- Branch coverage
- Observed: fixtures prove the verdicts they exercise
- Provenance
- baseline
What it checks
Identity Protection can email administrators when users are flagged as high-risk, enabling proactive investigation and containment of likely account compromise as it occurs. SCuBA recommends that such a notification be sent to administrators when high-risk users are detected. The Identity Protection 'Users at risk detected' notification recipient configuration is not exposed through a stable read-only Microsoft Graph endpoint, so an agentless assessment cannot positively confirm it; this check surfaces the requirement honestly and reports whether the supporting risk-detection telemetry is even available in the tenant rather than asserting compliance it cannot verify.
Recommended value
Identity Protection configured to email administrators when high-risk users are detected
Remediation
Configure the high-risk user notification, satisfying SCuBA MS.AAD.2.2. In Entra ID go to Protection > Identity Protection > Notifications and set 'Users at risk detected' alerts to email the appropriate security administrators or a monitored security operations distribution list. This control requires Entra ID P2 (Identity Protection). Because the notification recipient list is not readable agentlessly via Microsoft Graph, verify the setting manually in the portal.
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| not-implemented | Not Assessed |
Framework mappings
- CISA SCuBA
- MS.AAD.2.2v1
- NIST SP 800-53
- SI-4, IR-6, AU-6
- MITRE ATT&CK
- T1078.004