Information
Ensure that users are notified on their primary and alternate emails on password resets.
Rationale:
User notification on password reset is a proactive way of confirming password reset activity. It helps the user to recognize unauthorized password reset activities.
Impact:
Users will receive emails alerting them to password changes to both their primary and alternate emails.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.
Solution
Remediate from Azure Portal
From Azure Home select the Portal Menu
Select Microsoft Entra ID
Under Manage, select Users
Under Manage, select Password reset
Under Manage, select Notifications
Set Notify users on password resets? to Yes
Click Save
Default Value:
By default, Notify users on password resets? is set to 'Yes'.