EIDCA-017: High-Risk User Notification to Administrators

Plataforma
Entra ID / M365
Categoría
Entra ID Conditional Access
Severidad
Medium
Pilar de Zero Trust
Identity (peso 3)
Fixtures de referencia
1
Cobertura de ramas
Observada: los fixtures prueban los veredictos que ejercitan
Procedencia
baseline

Qué comprueba

Identity Protection can email administrators when users are flagged as high-risk, enabling proactive investigation and containment of likely account compromise as it occurs. SCuBA recommends that such a notification be sent to administrators when high-risk users are detected. The Identity Protection 'Users at risk detected' notification recipient configuration is not exposed through a stable read-only Microsoft Graph endpoint, so an agentless assessment cannot positively confirm it; this check surfaces the requirement honestly and reports whether the supporting risk-detection telemetry is even available in the tenant rather than asserting compliance it cannot verify.

Valor recomendado

Identity Protection configured to email administrators when high-risk users are detected

Remediación

Configure the high-risk user notification, satisfying SCuBA MS.AAD.2.2. In Entra ID go to Protection > Identity Protection > Notifications and set 'Users at risk detected' alerts to email the appropriate security administrators or a monitored security operations distribution list. This control requires Entra ID P2 (Identity Protection). Because the notification recipient list is not readable agentlessly via Microsoft Graph, verify the setting manually in the portal.

Veredictos probados con fixtures

Cada veredicto de esta tabla está probado por un fixture de referencia en la suite de pruebas que valida el módulo. La tabla se deriva de la última ejecución en verde; no puede editarse a mano.

Escenarios de veredicto de EIDCA-017
EscenarioVeredicto esperado
not-implementedNot Assessed

Mapeos a marcos de referencia

CISA SCuBA
MS.AAD.2.2v1
NIST SP 800-53
SI-4, IR-6, AU-6
MITRE ATT&CK
T1078.004