Information
The Microsoft 365 platforms allow a user to reset their password in the event they forget it. The self-service password reset activity report logs each time a user successfully resets their password this way. You should review the self-service password reset activity report at least weekly.
Rationale:
An attacker will commonly compromise an account, then change the password to something they control and can manage.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.
Solution
To review the report, perform the following steps using the Azure Portal:
Go to https://portal.azure.com.
Search for the Azure AD Authentication methods blade.
Click on Activity under Monitoring.
Click on the 'Usage' tab.
Review the list of users who have reset their passwords in the last seven days in the Number of password changes and resets chart.