CTD-000100

Entra ID tenant without policy to show geographic location context in Microsoft Authenticator notifications

Medium
Entra ID
Credential Access
v18

Signature Identity

CTD-000100
Threat ID
18
Version
IOE
Indicator Type

Threat Description

By default, Microsoft Authenticator notifications do not include geographic location context, so users do not know what exactly they confirm. A threat actor might use this to compromise an account by sending authentication requests that users might confirm by mistake. A policy can be configured to improve the security of user sign-in by adding the application name and geographic location of the sign-in to Microsoft Authenticator passwordless and push notifications.

MITRE ATT&CK: Attack Tactics

Credential Access

D3FEND: Defend Tactics

Application Configuration Hardening

Remediation

To enable geographic location in the Microsoft Entra admin center, complete the following steps:

  1. Sign in to the Microsoft Entra admin center as at least an Authentication Policy Administrator.
  2. Browse to Protection > Authentication methods > Microsoft Authenticator.
  3. On the Enable and Target tab, toggle the switch to Enable position.
  4. On the Enable and Target tab, click All users to enable the policy for everyone.
  5. Change Authentication mode to Any.
    Only users who are enabled for Microsoft Authenticator here can be included in the policy to show the application name or geographic location of the sign-in, or excluded from it. Users who aren’t enabled for Microsoft Authenticator can’t see application name or geographic location.
  6. On the Configure tab, for Show geographic location in push and passwordless notifications, change Status to Enabled.
  7. Choose whom to include or exclude from the policy.
  8. Click Save.

Frequently Asked Questions

What does Entra ID tenant without policy to show geographic location context in Microsoft Authenticator notifications mean?

When the default setting for Microsoft Authenticator notifications doesn't include the application name and geographic location, users can't verify authentication requests accurately, making it easier to fall victim to phishing attacks.

This issue is rated medium severity because it increases the risk of users confirming malicious authentication requests due to a lack of contextual information, which can lead to account compromise. Although this doesn't grant administrative control directly, it supports an attacker's ability to plan and execute more serious attacks by exploiting user trust.

Attackers can exploit the lack of geographic location context in Microsoft Authenticator notifications by sending authentication requests that users may confirm by mistake, thereby gaining unauthorized access. This tactic relies on user trust and can be particularly effective against users who are unfamiliar with the application or its security features.

Cayosoft Guardian detects this issue by continuously monitoring the configuration of Microsoft Authenticator policies across your Entra ID tenant and identifying when the policy is not configured to include geographic location context, providing administrators with clear visibility into a setting that can impact user authentication security.

Cayosoft Guardian helps reduce the risk by providing visibility into this critical setting and alerting administrators so they can configure the policy to include geographic location context, thereby improving user authentication security. Guardian also supports ongoing monitoring to ensure that this setting remains properly configured.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID
Themes
Tenant-wide
Attack Tactics
Credential Access
Defend Tactics
Application Configuration Hardening
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical