rules/findings/entra/conditional_access/eid-ensure-phishing-resistant-mfa-for-high-privileged-users-missing-cap.json
|
{
"provider": "EntraID", "serviceType": "Conditional Access", "serviceName": "Microsoft Entra ID", "displayName": "Ensure that a phishing-resistant Multi-factor Authentication Policy Exists for High-Privileged Users", "description": "For designated users, they will be prompted to use their phishing-resistant multi-factor authentication (MFA) process on logins.", "rationale": "Enabling multi-factor authentication is a recommended setting to limit the potential of accounts being compromised and limiting access to authenticated personnel.", "impact": "There is an increased cost, as Conditional Access policies require Microsoft Entra ID Premium. Similarly, this may require additional overhead to maintain if users lose access to their MFA.", "remediation": { "text": "###### From Azure Console\r\n\t\t\t\t\t1. From Azure Home open the Portal Menu in top left, and select Microsoft Entra ID\r\n\t\t\t\t\t2. Scroll down in the menu on the left, and select `Security`\r\n\t\t\t\t\t3. Select on the left side `Conditional Access`\r\n\t\t\t\t\t4. Click the `+ New policy`", "code": { "powerShell": null, "iac": null, "terraform": null, "other": null } }, "recommendation": null, "references": [ "https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/howto-conditional-access-policy-admin-mfa", "https://learn.microsoft.com/en-us/azure/active-directory/roles/security-emergency-access", "https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/troubleshoot-conditional-access-what-if", "https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/plan-conditional-access", "https://learn.microsoft.com/en-us/security/benchmark/azure/security-controls-v3-identity-management#im-7-restrict-resource-access-based-on--conditions" ], "compliance": [ { "name": "CIS Microsoft 365 Foundations Benchmark", "version": "6.1.0", "reference": "5.2.2.5", "profile": [ "E3 Level 2", "E5 Level 2" ] } ], "level": "medium", "tags": [ ], "rule": { "path": "aad_conditional_access_policy", "subPath": null, "selectCondition": { }, "query": [ { "filter": [ { "conditions": [ [ "state", "eq", "enabled" ], [ "conditions.applications.includeApplications", "eq", "All" ] ], "operator": "and" } ] }, { "connectOperator": "and", "filter": [ { "conditions": [ [ "MicrosoftAdminPortals", "notin", "conditions.applications.excludeApplications" ], [ "Office365", "notin", "conditions.applications.excludeApplications" ] ], "operator": "or" } ] }, { "connectOperator": "and", "filter": [ { "conditions": [ [ "grantControls.operator", "eq", "OR" ], [ "grantControls.authenticationStrength.id", "imatch", "00000000-0000-0000-0000-000000000004" ] ], "operator": "and" } ] }, { "connectOperator": "and", "filter": [ { "include": "_ARG_0_" } ] } ], "shouldExist": "true", "returnObject": null, "removeIfNotExists": null }, "output": { "html": { "data": { "properties": { "displayName": "Name", "state": "Status", "conditions.applications.includeApplications": "Applications", "conditions.users.includeUsers": "Users", "grantControls.operator": "Operator", "grantControls.authenticationStrength.displayName": "Authentication Strength" }, "expandObject": null }, "table": null, "decorate": [ ], "emphasis": [ ], "actions": { "objectData": { "properties": [ "*" ], "expandObject": null, "limit": null }, "showGoToButton": false, "showModalButton": false, "directLink": null } }, "text": { "data": { "properties": { }, "expandObject": null }, "status": { "keyName": [ "displayName" ], "message": "The {displayName} policy is not configured to require phishing-resistant MFA for high privileged users", "defaultMessage": null }, "properties": { "resourceName": "displayName", "resourceId": "id", "resourceType": "EntraConditionalAccess" }, "onlyStatus": true } }, "idSuffix": "aad_cap_force_phishing_resistant_mfa_high_priv_users", "notes": [ ], "categories": [ ], "immutable_properties": [ "id" ], "id": "entraid_1120" } |