CTD-000101

Microsoft Entra tenant with unsecure configuration of user risk policy

Medium
Entra ID
Credential Access
v15

Signature Identity

CTD-000101
Threat ID
15
Version
IOE
Indicator Type

Threat Description

  1. The Microsoft’s recommendation is to to require a secure password change when user risk level is High. Microsoft Entra multifactor authentication is required before the user can create a new password with password writeback to remediate their risk.
  2. Identity Protection analyzes signals about user accounts and calculates a risk score based on the probability that the user has been compromised. If a user has risky sign-in behavior, or their credentials have been leaked, Identity Protection will use these signals to calculate the user risk level. Administrators can configure user risk-based Conditional Access policies to enforce access controls based on user risk, including requirements such as:
    • Block access
    • Allow access but require a secure password change.
  3. A secure password change will remediate the user risk and close the risky user event to prevent unnecessary noise for administrators.

MITRE ATT&CK: Attack Tactics

Credential Access

D3FEND: Defend Tactics

Application Configuration Hardening

Remediation

To create a user risk policy in Conditional Access:

  1. Sign in to the Microsoft Entra admin center as at least a Conditional Access Administrator.
  2. Browse to Protection > Conditional Access.
  3. Select New policy.
  4. Give your policy a name. We recommend that organizations create a meaningful standard for the names of their policies.
  5. Under Assignments, select Users.
    1. Under Include, select All users.
    2. Under Exclude, select Users and groups and choose your organization’s emergency access or break-glass accounts.
    3. Select Done.
  6. Under Target resources > Include, select All cloud apps.
  7. Under Conditions > User risk, set Configure to Yes.
    1. Under Configure user risk levels needed for policy to be enforced, select High. (This guidance is based on Microsoft recommendations and may be different for each organization).
    2. Select Done.
  8. Under Access controls > Grant.
    1. Select Grant accessRequire multifactor authentication and Require password change.
    2. Select Select.
  9. Under Session.
    1. Select Sign-in frequency.
    2. Ensure Every time is selected.
    3. Select Select.
  10. Confirm your settings and set Enable policy to On.
  11. Select Create to create to enable your policy.

Frequently Asked Questions

What does Microsoft Entra tenant with unsecure configuration of user risk policy mean?

A Microsoft Entra tenant with an unsecure user risk policy has not enforced a secure password change requirement for high-risk users, allowing them to create new passwords without meeting security standards.

An unsecured user risk policy provides attackers with a foothold for information collection, enabling them to enumerate users and plan future malicious operations. This can lead to unauthorized access and data breaches.

Attackers can sign in using compromised credentials, gather information about accounts, perform reconnaissance against the tenant, and plan future malicious operations. This can also enable lateral movement within the tenant.

Cayosoft Guardian continuously monitors user risk policies across your Microsoft Entra tenant, flagging unsecured policies as security issues to alert administrators to unnecessary access risks and provide visibility into potential attack paths.

Cayosoft Guardian alerts administrators to review and update user risk policies, supports ongoing monitoring, catches changes to unsecured policies quickly, and provides visibility into attacker activity, limiting unnecessary access risks and reconnaissance opportunities.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID
Themes
Account protection Tenant-wide
Attack Tactics
Credential Access
Defend Tactics
Application Configuration Hardening
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical