rules/findings/entra/conditional_access/eid-cap-block-legacy-authentication-not-enabled.json

{
    "provider": "EntraID",
    "serviceType": "Conditional Access",
    "serviceName": "Microsoft Entra ID",
    "displayName": "Enable Conditional Access policies to block legacy authentication",
    "description": "\r\n\t\tEntra ID supports the most widely used authentication and authorization protocols including legacy authentication. This authentication pattern includes basic authentication, a widely used industry-standard method for collecting username and password information. The following messaging protocols support legacy authentication: \r\n\t\t* Authenticated SMTP - Used to send authenticated email messages. \r\n\t\t* Autodiscover - Used by Outlook and EAS clients to find and connect to \r\n\t\tmailboxes in Exchange Online. \r\n\t\t* Exchange ActiveSync (EAS) - Used to connect to mailboxes in Exchange Online. \r\n\t\t* Exchange Online PowerShell - Used to connect to Exchange Online with remote \r\n\t\tPowerShell. If you block Basic authentication for Exchange Online PowerShell, \r\n\t\tyou need to use the Exchange Online PowerShell Module to connect. For \r\n\t\tinstructions, see Connect to Exchange Online PowerShell using multifactor \r\n\t\tauthentication. \r\n\t\t* Exchange Web Services (EWS) - A programming interface that\u0027s used by \r\n\t\tOutlook, Outlook for Mac, and third-party apps. \r\n\t\t* IMAP4 - Used by IMAP email clients. \r\n\t\t* MAPI over HTTP (MAPI/HTTP) - Primary mailbox access protocol used by \r\n\t\tOutlook 2010 SP2 and later. \r\n\t\t* Offline Address Book (OAB) - A copy of address list collections that are \r\n\t\tdownloaded and used by Outlook. \r\n\t\t* Outlook Anywhere (RPC over HTTP) - Legacy mailbox access protocol \r\n\t\tsupported by all current Outlook versions. \r\n\t\t* POP3 - Used by POP email clients. \r\n\t\t* Reporting Web Services - Used to retrieve report data in Exchange Online. \r\n\t\t* Universal Outlook - Used by the Mail and Calendar app for Windows 10. \r\n\t\t* Other clients - Other protocols identified as utilizing legacy authentication. \r\n ",
    "rationale": "\r\n\t\tLegacy authentication protocols do not support multi-factor authentication. These protocols are often used by attackers because of this deficiency. Blocking legacy authentication makes it harder for attackers to gain access. \r\n\t\t**NOTE** : As of October 2022 Microsoft began disabling basic authentication in all tenants, except for those who requested special exceptions it should no longer be available in most tenants beyond Dec 31, 2022. Despite this CIS recommends the CA policy to remain in place to act as a defense in depth measure. \r\n ",
    "impact": "\r\n\t\tEnabling this setting will prevent users from connecting with older versions of Office, ActiveSync or using protocols like IMAP, POP or SMTP and may require upgrades to older versions of Office, and use of mobile mail clients that support modern authentication. \r\n\t\tThis will also cause multifunction devices such as printers from using scan to e-mail function if they are using a legacy authentication method. Microsoft has mail flow best practices in the link below which can be used to configure a MFP to work with modern authentication: \r\n\t\thttps://learn.microsoft.com/en-us/exchange/mail-flow-best-practices/how-to-set-up-a-multifunction-device-or-application-to-send-email-using-microsoft-365-or-office-365 \r\n ",
    "remediation": {
        "text": "###### From Azure Console\r\n\t\t\t\t\t1. From Azure Home open the Portal Menu in top left, and select Microsoft Entra ID\r\n\t\t\t\t\t2. Scroll down in the menu on the left, and select `Security`\r\n\t\t\t\t\t3. Select on the left side `Conditional Access`\r\n\t\t\t\t\t4. Click the `+ New policy`",
        "code": {
            "powerShell": null,
            "iac": null,
            "terraform": null,
            "other": null
        }
    },
    "recommendation": null,
    "references": [
        "https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/howto-conditional-access-policy-admin-mfa",
        "https://learn.microsoft.com/en-us/azure/active-directory/roles/security-emergency-access",
        "https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/troubleshoot-conditional-access-what-if",
        "https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/plan-conditional-access",
        "https://learn.microsoft.com/en-us/security/benchmark/azure/security-controls-v3-identity-management#im-7-restrict-resource-access-based-on--conditions"
    ],
    "compliance": [
        {
            "name": "CIS Microsoft 365 Foundations Benchmark",
            "version": "5.0.0",
            "reference": "5.2.2.3",
            "profile": [
                "E3 Level 1",
                "E5 Level 1"
            ]
        }
    ],
    "level": "medium",
    "tags": [
         
    ],
    "rule": {
        "path": "aad_conditional_access_policy",
        "subPath": null,
        "selectCondition": {
             
        },
        "query": [
            {
                "filter": [
                    {
                        "conditions": [
                            [
                                "state",
                                "eq",
                                "enabled"
                            ],
                            [
                                "conditions.users.includeUsers",
                                "eq",
                                "All"
                            ],
                            [
                                "conditions.applications.includeApplications",
                                "eq",
                                "All"
                            ]
                        ],
                        "operator": "and"
                    }
                ]
            },
            {
                "connectOperator": "and",
                "filter": [
                    {
                        "conditions": [
                            [
                                "conditions.clientAppTypes",
                                "contains",
                                "exchangeActiveSync"
                            ],
                            [
                                "conditions.clientAppTypes",
                                "contains",
                                "other"
                            ]
                        ],
                        "operator": "and"
                    }
                ]
            },
            {
                "connectOperator": "and",
                "filter": [
                    {
                        "conditions": [
                            [
                                "grantControls.builtInControls",
                                "eq",
                                "block"
                            ]
                        ]
                    }
                ]
            }
        ],
        "shouldExist": true,
        "returnObject": null,
        "removeIfNotExists": null
    },
    "output": {
        "html": {
            "data": {
                "properties": {
                    "displayName": "Name",
                    "state": "Status",
                    "conditions.clientAppTypes": "Client App Types",
                    "grantControls.operator": "Operator",
                    "grantControls.builtInControls": "BuiltIn Controls"
                },
                "expandObject": null
            },
            "table": "default",
            "decorate": [
                 
            ],
            "emphasis": [
                 
            ],
            "actions": {
                "objectData": {
                    "properties": [
                        "*"
                    ],
                    "expandObject": null,
                    "limit": null
                },
                "showGoToButton": "True",
                "showModalButton": "True",
                "directLink": null
            }
        },
        "text": {
            "data": {
                "properties": {
                    "displayName": "Name",
                    "state": "Status",
                    "conditions.clientAppTypes": "Client App Types",
                    "grantControls.operator": "Operator",
                    "grantControls.builtInControls": "BuiltIn Controls"
                },
                "expandObject": null
            },
            "status": {
                "keyName": [
                    "displayName"
                ],
                "message": "The {displayName} policy is not configured to block legacy authentication",
                "defaultMessage": null
            },
            "properties": {
                "resourceName": "displayName",
                "resourceId": "Id",
                "resourceType": "EntraConditionalAccess"
            },
            "onlyStatus": true
        }
    },
    "idSuffix": "eid_cap_block_basic_auth",
    "notes": [
         
    ],
    "categories": [
         
    ],
    "immutable_properties": [
        "id"
    ],
    "id": "entraid_1116"
}