Entra ID (Azure AD) Account Lockdown (RUX)
FAQ for Entra ID account lockdown in RUX, including availability, behavior, and response workflows.
Overview
What is Entra ID (AAD) Account Lockdown?
Why is disabling of an Entra ID/M365 account necessary during a security investigation?
Requirements
General Requirements
Vectra Required Permissions
Configuration of Entra ID (AAD) Account Lockdown:
Using Entra ID Account Lockdown:
Vectra Roles Automatically Enabled for Entra ID Lockdown
Configuration
Frequently Asked Questions
What is the name of the app added to Entra ID (AAD)?
What permission in required in Microsoft for the Vectra AI app?
How is the required permission in Microsoft configured?
Does the consent app link ever change?
Can I setup Entra ID Account Lockdown for more than one tenant?
Usage FAQs
What enforcement options does Entra ID (AAD) Account Lockdown provide?
How do I manually lock down an account?

How can I utilize Automatic Entra ID (AAD) Account Lockdown?
Where can I check the Lockdown status of an account?

Once an AAD/M365 account has been disabled, how can it be re-enabled?
Why is it preferred to re-enable an account through the Vectra UI?
Are there any account types that cannot be disabled?
Is there API support for AAD Account Lockdown?
Notification
Will the end user be notified when an account is locked down?
How can administrators know if an account has been locked down through Vectra?
Are logs available of Lockdown related actions?

Disabling
If I no longer wish to use Entra ID (AAD) Account Lockdown, what are the steps to turn it off?
How do I remove consent for the App if I wish to completely remove the integration?
Technical Note
Last updated
Was this helpful?



