Warning:You must be a Tenant Administrator to manage users in the Compromised Accounts delegation and MFA Authentication Policies.
Whenever an account has been found compromised by a SafeID breached accounts scan, that user will show up in an automatically created Compromised Accounts delegation in the People module.
- Notify the Affected User(s) by Email and/or SMS
In the Compromised Accounts delegation, select the user(s) and choose to Send Email or Send SMS depending on the desired method for that user. The instructions configured within the theme will show in the message that is sent.
- Navigate to Configuration > Security > SafeID
- Locate the email and SMS templates
- Click Edit on the template
- Check the Enabled box to activate the template
Note:More templates can be set up to address different user types with different messages if needed.
- Reset the Affected User's Password
Once a user has been flagged as compromised, any method of changing that user's password will clear the flag. This can be done by the user through Self-Service, Delegations, or Connect. Compromised users who change their passwords through any method will immediately be removed from the Compromised Accounts delegation.
- Disable the Affected Account(s) if needed
If the account(s) cannot be resolved for any reason, select the account(s) in the Compromised Accounts delegation. Then click Disable in the bottom action bar.
- Enroll the User(s) in MFA
Create an Authentication Policy for compromised users to prevent future breaches.