CTD-000099

Entra ID tenant without policy to show application name context in Microsoft Authenticator notifications

Medium
Entra ID
Credential Access
v20

Signature Identity

CTD-000099
Threat ID
20
Version
IOE
Indicator Type

Threat Description

By default, Microsoft Authenticator notifications do not include additional application context, so users do not know what exactly they confirm. A threat actor might use this to compromise an account by sending authentication requests that users might confirm by mistake. A policy can be configured to improve the security of user sign-in by adding the application name and geographic location of the sign-in to Microsoft Authenticator passwordless and push notifications.

MITRE ATT&CK: Attack Tactics

Credential Access

D3FEND: Defend Tactics

Application Configuration Hardening

Remediation

To enable application name or geographic location in the Microsoft Entra admin center, complete the following steps:

  1. Sign in to the Microsoft Entra admin center as at least an Authentication Policy Administrator.
  2. Browse to Protection > Authentication methods > Microsoft Authenticator.
  3. On the Enable and Target tab, toggle the switch to Enable position.
  4. On the Enable and Target tab, click All users to enable the policy for everyone.
  5. Change Authentication mode to Any.
    Only users who are enabled for Microsoft Authenticator here can be included in the policy to show the application name or geographic location of the sign-in, or excluded from it. Users who aren’t enabled for Microsoft Authenticator can’t see application name or geographic location.
  6. On the Configure tab, for Show application name in push and passwordless notifications change Status to Enabled.
  7. Choose whom to include or exclude from the policy.
  8. Click Save.

Frequently Asked Questions

What does Entra ID tenant without policy to show application name context in Microsoft Authenticator notifications mean?

When an Entra ID tenant lacks a policy to display application name context in Microsoft Authenticator notifications, it means that these notifications do not include the specific application name. This can make it more difficult for users to verify the authenticity of authentication requests.

This vulnerability is rated medium severity because, although it does not grant administrative access, attackers can exploit this by sending authentication requests with misleading or generic names that users might inadvertently confirm.

Attackers can use the lack of application context in Microsoft Authenticator notifications to send authentication requests with misleading or generic names, which users might inadvertently confirm. This can lead to account compromise.

Cayosoft Guardian continuously monitors the configuration settings for Microsoft Authenticator notifications within the Entra ID tenant. When it detects a lack of application context, Guardian flags this as a security issue and provides administrators with clear visibility into the potential vulnerability.

Cayosoft Guardian helps reduce the risk by alerting administrators to enable application name or geographic location in the Microsoft Entra admin center. This proactive monitoring and alerting mechanism supports ongoing change management and ensures that unnecessary vulnerabilities are promptly addressed.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID
Themes
Tenant-wide
Attack Tactics
Credential Access
Defend Tactics
Application Configuration Hardening
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical