Description:

Verifies that reporting suspicious authentication requests is enabled.

Why:

Allows users to report suspicious activities if they receive an authentication request that they did not initiate. This control is available when using the Microsoft Authenticator app and voice calls. Reporting suspicious activity will set the user's risk to high. If the user is subject to risk-based Conditional Access policies, they may be blocked.

Configured: Reporting suspicious authentication requests is enabled.

Not Configured: Reporting suspicious authentication requests is disabled.

Scoring: Contributes up to 1 point to the Posture Recommendations score.

Category: Identity

Microsoft Licensing: Works with Basic licensing

Remediation in Augmentt: No in-product remediation — remediate in the Microsoft admin portals.

Compliance Frameworks: None mapped for this check.

Microsoft documentation: