EIDAUTH-018: Microsoft Authenticator Login Context (Application Name and Location)
- Plataforma
- Entra ID / M365
- Categoría
- Entra ID Authentication Methods & MFA
- Severidad
- Medium
- Pilar de Zero Trust
- Identity (peso 3)
- Fixtures de referencia
- 3
- Cobertura de ramas
- Observada: los fixtures prueban los veredictos que ejercitan
- Procedencia
- baseline
Qué comprueba
When the Microsoft Authenticator authentication method is enabled, displaying login context information (application name and geographic location) in push and passwordless notifications gives the user the situational awareness needed to recognize and reject MFA prompts they did not initiate. Without this context, users are far more likely to approve adversary-initiated push requests during MFA fatigue or real-time phishing attacks. This setting is controlled by the displayAppInformationRequiredState and displayLocationInformationRequiredState feature settings on the MicrosoftAuthenticator method configuration.
Valor recomendado
If Microsoft Authenticator is enabled, displayAppInformationRequiredState is enabled (application name shown); displayLocationInformationRequiredState is also recommended
Remediación
Navigate to Entra ID > Protection > Authentication methods > Policies > Microsoft Authenticator. Under the Configure tab, set 'Show application name in push and passwordless notifications' to Enabled for all users, and enable 'Show geographic location in push and passwordless notifications'. This satisfies SCuBA MS.AAD.3.3, which requires Microsoft Authenticator to be configured to show login context when it is enabled.
Veredictos probados con fixtures
Cada veredicto de esta tabla está probado por un fixture de referencia en la suite de pruebas que valida el módulo. La tabla se deriva de la última ejecución en verde; no puede editarse a mano.
| Escenario | Veredicto esperado |
|---|---|
| clean | PASS |
| known-bad | FAIL |
| no-data | Not Assessed |
Mapeos a marcos de referencia
- CISA SCuBA
- MS.AAD.3.3v2
- NIST SP 800-53
- IA-2(1), IA-2(2)
- CIS M365 Benchmark
- 5.2.3.2
- EIDSCA
- AM06, AM09
- MITRE ATT&CK
- T1621