STIGQter STIGQter: STIG Summary: Microsoft Entra ID Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 28 Feb 2025:

Microsoft Entra ID must initiate a session lock after a 15-minute period of inactivity.

DISA Rule

SV-270200r1085610_rule

Vulnerability Number

V-270200

Group Title

SRG-APP-000003

Rule Version

ENTR-ID-000030

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

1. Sign into entra.microsoft.us.
2. Navigate to the Gear icon (right) and select Settings >> Signing out + notifications.
3. Check the "Enable directory level idle timeout" box.
4. Populate the "Hours" field to "0" and the "Minutes" field to "15".
5. Click "Apply".

Check Contents

To verify the inactivity timeout is configured for 15 minutes or less, follow the steps outlined below:

1. Sign in to entra.microsoft.us.
2. Navigate to the Gear icon (right) and select Settings >> Signing out + notifications.
3. Check that the "Enable directory level idle timeout" is selected.
4. Verify the Signing out value is 15 minutes or less.

If the directory level idle timeout is not set to 15 minutes or less, this is a finding.

Vulnerability Number

V-270200

Documentable

False

Rule Version

ENTR-ID-000030

Severity Override Guidance

To verify the inactivity timeout is configured for 15 minutes or less, follow the steps outlined below:

1. Sign in to entra.microsoft.us.
2. Navigate to the Gear icon (right) and select Settings >> Signing out + notifications.
3. Check that the "Enable directory level idle timeout" is selected.
4. Verify the Signing out value is 15 minutes or less.

If the directory level idle timeout is not set to 15 minutes or less, this is a finding.

Check Content Reference

M

Target Key

5671