EIDAUTH-012: SSPR Methods and Requirements

Plataforma
Entra ID / M365
Categoría
Entra ID Authentication Methods & MFA
Severidad
Medium
Pilar de Zero Trust
Identity (peso 3)
Fixtures de referencia
1
Cobertura de ramas
Observada: los fixtures prueban los veredictos que ejercitan
Procedencia
baseline

Qué comprueba

The specific methods allowed for SSPR and the number required directly impact the security of the password reset process. Allowing weak methods such as security questions or requiring only a single method creates opportunities for attackers to reset passwords through social engineering or OSINT. Organizations should require at least two strong methods for all password resets.

Valor recomendado

Two or more strong authentication methods required for password reset, security questions disabled

Remediación

Navigate to Entra ID > Protection > Password reset > Authentication methods. Set the number of methods required to 2 and remove security questions from the allowed methods list. Prioritize mobile app notification and mobile app code as the primary SSPR methods to ensure strong verification.

Veredictos probados con fixtures

Cada veredicto de esta tabla está probado por un fixture de referencia en la suite de pruebas que valida el módulo. La tabla se deriva de la última ejecución en verde; no puede editarse a mano.

Escenarios de veredicto de EIDAUTH-012
EscenarioVeredicto esperado
not-implementedNot Assessed

Mapeos a marcos de referencia

NIST SP 800-53
IA-5(1)
CIS M365 Benchmark
5.2.4