CTD-000102

Microsoft Entra tenant with unsecure configuration of sign-in risk policy

Medium
Entra ID
Credential Access
v19

Signature Identity

CTD-000102
Threat ID
19
Version
IOE
Indicator Type

Threat Description

Sign-in risk policy in Conditional Access allows mitigation of sign-in risks preventing threat actors from getting access to user accounts. Organizations must decide the level of risk they want to require access control on balancing user experience and security posture. Microsoft recommends requiring Microsoft Entra multifactor authentication when sign-in risk level is Medium or High, allowing users to prove it’s them by using one of their registered authentication methods, remediating the sign-in risk.

MITRE ATT&CK: Attack Tactics

Credential Access

D3FEND: Defend Tactics

Application Configuration Hardening

Remediation

To create sign-in risk policy in Conditional Access:

  1. Sign in to the Microsoft Entra admin center as at least a Conditional Access Administrator.
  2. Browse to Protection > Conditional Access.
  3. Select New policy.
  4. Give your policy a name. We recommend that organizations create a meaningful standard for the names of their policies.
  5. Under Assignments, select Users.
    1. Under Include, select All users.
    2. Under Exclude, select Users and groups and choose your organization’s emergency access or break-glass accounts.
    3. Select Done.
  6. Under Target resources > Include, select All cloud apps.
  7. Under Conditions > Sign-in risk, set Configure to Yes. Under Select the sign-in risk level this policy will apply to. (This guidance is based on Microsoft recommendations and may be different for each organization)
    1. Select High and Medium.
    2. Select Done.
  8. Under Access controls > Grant.
    1. Select Grant accessRequire multifactor authentication.
    2. Select Select.
  9. Under Session.
    1. Select Sign-in frequency.
    2. Ensure Every time is selected.
    3. Select Select.
  10. Confirm your settings and set Enable policy to Report-only.
  11. Select Create to create to enable your policy.

After confirming your settings using report-only mode, an administrator can move the Enable policy toggle from Report-only to On.

Frequently Asked Questions

What does Microsoft Entra tenant with unsecure configuration of sign-in risk policy mean?

A Microsoft Entra tenant with an unsecure sign-in risk policy configuration in Conditional Access lacks a requirement for multifactor authentication at Medium or High risk levels, enabling users to access accounts without additional verification. This setting can be exploited by attackers using compromised credentials.

The issue is rated medium severity because it allows attackers to bypass multifactor authentication, enabling them to access user accounts without additional verification. This can lead to lateral movement within the organization and potential access to sensitive data or systems.

Attackers can use a compromised account to access other user accounts without multifactor authentication when the sign-in risk policy is misconfigured. This allows them to move laterally within the organization and potentially access sensitive data or systems.

Cayosoft Guardian continuously monitors Conditional Access settings in the Microsoft Entra admin center to detect misconfigured sign-in risk policies. When a security issue is detected, Guardian flags it for administrators to review and correct.

Cayosoft Guardian helps reduce the risk by alerting administrators to review and correct Conditional Access settings, ensuring multifactor authentication is required for Medium or High risk levels. This prevents attackers from exploiting the misconfigured policy.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID
Themes
Conditional Access Tenant-wide
Attack Tactics
Credential Access
Defend Tactics
Application Configuration Hardening
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical