EIDSCA-AM04: EIDSCA AM04: Authentication Method - Microsoft Authenticator - Included users/groups of number matching for push notifications
- Platform
- Entra ID / M365
- Category
- EIDSCA Baseline
- Severity
- High
- Zero Trust pillar
- Identity (weight 3)
- Golden fixtures
- 3
- Branch coverage
- Observed: fixtures prove the verdicts they exercise
- Provenance
- baseline
What it checks
Entra ID security-configuration control (EIDSCA AM04): evaluates 'featureSettings.numberMatchingRequiredState.includeTarget.id' on the MicrosoftAuthenticator authentication method against the recommended secure value.
Recommended value
eq all_users
Remediation
Configure the MicrosoftAuthenticator authentication method so 'featureSettings.numberMatchingRequiredState.includeTarget.id' is set to all_users. (Entra ID security-configuration baseline, control EIDSCA AM04.)
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| fail | FAIL |
| no-data | Not Assessed |
| pass | PASS |
Framework mappings
- EIDSCA
- AM04