Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update MS.AAD.3.3v1 Policy name and description now that the policy has been decoupled with MS.AAD.3.1v1 #1584

Open
1 task done
ahuynhMITRE opened this issue Feb 19, 2025 · 0 comments · May be fixed by #1588
Open
1 task done
Assignees
Labels
baseline-document Issues relating to the text in the baseline documents themselves
Milestone

Comments

@ahuynhMITRE
Copy link
Collaborator

ahuynhMITRE commented Feb 19, 2025

💡 Summary

What is the work, as a high-level summary?
Rego checks were updated to test MS.AAD.3.3v1 with authenticator found in issue #1484, as a result the policy has been decoupled from MS.AAD.3.1v1 and needs to update the policy and description.

Motivation and context

Why does this work belong in this project?

This would be useful because the baseline policy needs to be aligned with the implementation of the new rego checks.

Implementation notes

New policy name:
If Microsoft Authenticator is enabled, it SHALL be configured to show login context information.

New policy description:
Rationale: This policy helps protect the tenant when Microsoft Authenticator is used by showing user context information, which helps reduce MFA phishing compromises.

Acceptance criteria

How do we know when this work is done?

  • Policy name and description match the suggested text above
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
baseline-document Issues relating to the text in the baseline documents themselves
Projects
None yet
1 participant