1.1.9 Enable Azure AD Identity Protection sign-in risk policies

Information

Azure Active Directory Identity Protection sign-in risk detects risks in real-time and offline. A risky sign-in is an indicator for a sign-in attempt that might not have been performed by the legitimate owner of a user account.

Rationale:

Turning on the sign-in risk policy ensures that suspicious sign-ins are challenged for multi-factor authentication.

Impact:

When the policy triggers, the user will need MFA to access the account. In the case of a user who hasn't registered MFA on their account, they would be blocked from accessing their account. It is therefore recommended that the MFA registration policy be configured for all users who are a part of the Sign-in Risk policy.

Solution

To configure a Sign-In risk policy, use the following steps:

Sign-on to your Azure portal as global administrator by going to https://portal.azure.com

In the Azure portal, click Services and search for and click on Azure AD Identity Protection.

Under Configure click on Sign-in risk policy.

Under Assignments ensure that policy is applied to All users or the scope of users appropriate

Under Assignments choose Conditions and the appropriate Sign-in risk level

Under Controls, select Access and choose Allow access and Require multi-factor authentication

Ensure that Enforce Policy is set to On

See Also

https://workbench.cisecurity.org/files/3433