question

Rahul-7230 avatar image
0 Votes"
Rahul-7230 asked DerrickShaffer-1422 answered

Route notification and email alert sent to Admin Account (no mailbox for Admin accounts) to mail enabled id's.

Hi Team,

As you know as per security best practices we are using Azure AD Admin ID's which are not having any mailbox to prevent any phishing attacks.

Now I want to know if we are using any such account how do we receive Azure AD alert and notification to our mailbox. I mean if we can get these alerts to our id's which are having mailboxes.

One more use case is if some password getting expire O365 send alert to user id 14 days before so can we configure or add our mail enabled id's so that we receive the notification on that id's.

Note: If I add mail attribute to Admin account than it might conflict with my mail enabled id.

Any suggestions here how to associate an exiting email id ( individual or DL group) to ADMIN Accounts to get notified for any Azure AD admin notifications sent to these ADMIN accounts e.g PIM notification / License renewal etc which are send out to Global admins who are not having any mailbox.


azure-active-directory
· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Is there a solution for this yet? Microsoft is making it difficult to follow best practices of keeping a separate admin account from our everyday work accounts. Seems like it would be easy to just have an option to enable admin/security notifications for non-admin mailbox accounts.

1 Vote 1 ·
michev avatar image
0 Votes"
michev answered ATRIPP-5058 commented

You will receive them on the alternative email you provide as part of the provisioning process/elevating a user.

There are no password expiration emails in Office 365, if you want to generate such, you have to use your own custom solution.

· 2
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

@michev : Ok Yeah no email notification but it alerts you when you open any Microsoft Apps (e.g. Outlook , OneDrive , SharePoint etc.). Alert appears when the user's password expires, they'll get a notification that appears in the lower right corner of their screen.

Thanks for the Quick suggestion.



0 Votes 0 ·

I am NOT receiving any notification to my alternate email.
My account is GA and has a mailbox as primary which is receiving notifications such as PIM.
Any ideas?

0 Votes 0 ·
JamesHeathcoteADM-0290 avatar image
0 Votes"
JamesHeathcoteADM-0290 answered EibaHaddad-8208 commented

Doesnt work for us either, I don't want to licenses 365 for exchange just to get mail notifications for Azure Admin accounts when we are following best practise and not using admin accounts for email etc.

Alternative email only seems to get used when Microsoft want to send you a bill!

· 2
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Yes shocking let me know if you get the answer!

0 Votes 0 ·

I found that if an the Admin account was mail-enabled ( say the licenses was assigned then removed) then PIM notifications don't get sent to the alternate email address,however, if the admin account was created and never been mail-enabled then PIM emails are sent to the alternate email address

0 Votes 0 ·
DerrickShaffer-1422 avatar image
0 Votes"
DerrickShaffer-1422 answered

Microsoft needs to just add an option to send admin alerts/notifications to a distribution group.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

DerrickShaffer-1422 avatar image
0 Votes"
DerrickShaffer-1422 answered

Mail-enabled admin accounts is a bad practice. Microsoft needs to fix this.

https://github.com/cisagov/bad-practices/discussions/14

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.