SV-270239r1085663_rule
V-270239
SRG-APP-000174
ENTR-ID-000610
CAT II
10
Change the default Entra ID password expiration time period to 60 days by using the Graph script located here:
https://learn.microsoft.com/en-us/powershell/module/microsoft.graph.users/update-mguser
Use the "Get-MgDomain" command, and update it to 60 days using the "Update-MgDomain -DomainId <DomainName>
-PasswordValidityPeriodInDays 60" command.
Note: For any PowerShell scripts that are Graph, note that Graph endpoints differ depending on where the tenant is located.
- For commercial tenants, graph endpoints are graph.microsoft.com.
- For GCC High tenants (IL4), graph endpoints are graph.microsoft.us.
- For DOD tenants (IL5), graph endpoints are dod-graph.microsoft.us.
Verify the Entra ID password expiration time period has been changed to 60 days.
Interview the site Entra ID system administrator and verify the script shown in the Fix has been run.
If the Entra ID password expiration time period is not 60 days or less, this is a finding.
Note: It is not possible to view the current value for the password expiration time (the Entra ID default is 90). An administrator can check the maximum password age of their Entra ID tenant by using the Graph PowerShell SDK module and the "Get-MgDomain" command by using the script located here:
https://learn.microsoft.com/en-us/powershell/module/microsoft.graph.identity.directorymanagement/get-mgdomain?view=graph-powershell-1.0
Note: For any PowerShell scripts that are Graph, note that Graph endpoints differ depending on where the tenant is located.
- For commercial tenants, graph endpoints are graph.microsoft.com.
- For GCC High tenants (IL4), graph endpoints are graph.microsoft.us.
- For DOD tenants (IL5), graph endpoints are dod-graph.microsoft.us.
V-270239
False
ENTR-ID-000610
Verify the Entra ID password expiration time period has been changed to 60 days.
Interview the site Entra ID system administrator and verify the script shown in the Fix has been run.
If the Entra ID password expiration time period is not 60 days or less, this is a finding.
Note: It is not possible to view the current value for the password expiration time (the Entra ID default is 90). An administrator can check the maximum password age of their Entra ID tenant by using the Graph PowerShell SDK module and the "Get-MgDomain" command by using the script located here:
https://learn.microsoft.com/en-us/powershell/module/microsoft.graph.identity.directorymanagement/get-mgdomain?view=graph-powershell-1.0
Note: For any PowerShell scripts that are Graph, note that Graph endpoints differ depending on where the tenant is located.
- For commercial tenants, graph endpoints are graph.microsoft.com.
- For GCC High tenants (IL4), graph endpoints are graph.microsoft.us.
- For DOD tenants (IL5), graph endpoints are dod-graph.microsoft.us.
M
5671