EIDTNT-013: Notification Settings Audit

Platform
Entra ID / M365
Category
Entra ID Tenant Configuration
Severity
Medium
Zero Trust pillar
Governance (weight 1)
Golden fixtures
3
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

Entra ID notification settings control who receives alerts for critical security events such as users at risk, weekly digest reports, and administrative notifications. Misconfigured notification settings may result in security alerts being sent to inactive mailboxes, former employees, or not being sent at all. Proper notification routing ensures that security-relevant events reach the appropriate personnel for timely investigation and response.

Recommended value

All security notifications routed to active, monitored mailboxes belonging to current security operations personnel

Remediation

Review notification settings across Entra ID including Identity Protection notification recipients, password reset notification settings, and technical notification contacts. Verify that all notification recipients are current employees with actively monitored mailboxes and update any references to former employees or inactive distribution lists. Configure notifications to be sent to a security operations distribution list rather than individual users to ensure continuity when personnel changes occur.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for EIDTNT-013
ScenarioExpected verdict
cleanPASS
known-badWARN
no-dataNot Assessed

Framework mappings

NIST SP 800-53
AU-5