> For the complete documentation index, see [llms.txt](https://docs.vectra.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.vectra.ai/configuration/response/lockdown/entra-id-azure-ad-account-lockdown-rux.md).

# Entra ID (Azure AD) Account Lockdown (RUX)

{% hint style="info" %}
**Please Note:**

Entra ID Account Lockdown is only available in Vectra's Respond UX. Account Lockdown is a different feature that can be used by both Respond UX and Quadrant UX users to Lockdown Active Directory accounts. If you are unsure of which UX you have, please see [Vectra Analyst User Experiences (Respond vs Quadrant)](/deployment/getting-started/analyst-ux-options-rux-vs-qux.md) for additional guidance. For details on the Account Lockdown feature, please see the [Account Lockdown FAQ](/configuration/response/lockdown/active-directory-account-lockdown.md).
{% endhint %}

Below is a brief demo video:

{% embed url="<https://www.youtube.com/watch?v=vDBzoW8hkjA&list=PLhNJuaqpgRTiHLLsDmCwWRHIc7nulF4DA&index=7>" %}

## Overview

#### What is Entra ID (AAD) Account Lockdown?

Entra ID Account Lockdown is a new feature that will give Respond UX users the ability to stop potentially malicious Entra ID and M365 accounts during a security investigation. This functionality enables enforcement action, via revoking active sessions, disabling the account and revoking active sessions, or resetting the account password and revoking active sessions. The enforcement action can be initiated manually by a Vectra user with the proper permissions or via Automatic Lockdown when an account crosses an Urgency score threshold that is configurable.

#### Why is disabling of an Entra ID/M365 account necessary during a security investigation?

Disabling an Entra ID/M365 account can prevent an attack from progressing further along the kill chain. It can stop the malicious user from logging into any additional systems, potentially limiting the blast radius of an on-going attack.

## Requirements

### General Requirements

* Entra ID Account Lockdown requires **Global Administrator** permissions for a user within the customer's Entra ID tenant to grant consent that Vectra be added as an application that will enable Respond UX users (who have the required permissions in Vectra) to perform Lockdown.
* A user with sufficient permissions in Vectra to configure Entra ID Account Lockdown.
* A user with sufficient permissions in Vectra to use Entra ID Account Lockdown.

### Vectra Required Permissions

There are two sets of permissions that are associate with AAD Account Lockdown:

#### Configuration of Entra ID (AAD) Account Lockdown:

Settings are found in *Configuration → RESPONSE → Lockdown → Azure AD Lockdown*.

* **View** for **Configuration - Azure AD Lockdown**
  * Allows viewing of Entra ID (AAD) Lockdown settings.
* **Edit** for **Configuration - Azure AD Lockdown**
  * Allows editing of Entra ID (AAD) Lockdown settings.

#### Using Entra ID Account Lockdown:

Entra ID Lockdown is available in the sidebar of an Entra ID (AAD)/M365 account entity page.

* **View** for **Azure AD Lockdown**
  * Allows viewing of Entra ID (AAD) Lockdown status of an Entra ID (AAD)/M365 account.
* **Edit** for **Azure AD Lockdown**
  * Allows a user to lock or unlock an Entra ID (AAD)/M365 account.
  * This includes all Lockdown options associated with the Entra ID Lockdown feature.

#### Vectra Roles Automatically Enabled for Entra ID Lockdown

* By default, all roles will be granted **View** permissions.
* By default, **Admin** and **Super Admin** roles will have **all** Entra ID Account Lockdown related permissions.
* Role permissions can be modified as desired at *Configuration → ACCESS → Roles.*

## Configuration

{% stepper %}
{% step %}

#### Ensure Vectra roles for admins and analysts have desired permissions

As per [Vectra Required Permissions](#vectra-required-permissions), please ensure that the roles used by your admins and analysts have permissions you desire set for them. Roles can be edited by any Vectra user with **Edit** rights for the **Configuration - Roles** permission.
{% endstep %}

{% step %}

#### Enable the feature

* Navigate to *Configuration → RESPONSE → Lockdown → Azure AD Lockdown.*
* Edit the setting to turn the feature **On**.

<figure><img src="/files/0l4M5BDanLY4BKvQJL6L" alt=""><figcaption></figcaption></figure>

* Copy the **Connection Setup Link** and open it to start the consent flow that will instantiate a copy of **Vectra AI - Azure AD Lockdown** as an Enterprise Application in Entra ID.

<figure><img src="/files/m5Rv8BEoAbxoAwC5jL8J" alt=""><figcaption></figcaption></figure>

Once you have completed the consent flow, you have configured Entra ID Account Lockdown but you still may want to made additional configuration changes such as automatic Lockdown.

<figure><img src="/files/VJn7bk7bVEBHkibdQa8V" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

#### Optionally configure automated Entra ID (AAD) Lockdown

After clicking the button to enable Automatic Entra ID (AAD) Account Lockdown, you can choose options.

<figure><img src="/files/xwp7uMWZIzmclmwX9Q6Q" alt=""><figcaption></figcaption></figure>

As you can see above, you can choose the default action to take and you can adjust the Urgency Score required for automatic account Lockdown.
{% endstep %}
{% endstepper %}

### Frequently Asked Questions

#### What is the name of the app added to Entra ID (AAD)?

The consent process above will create an app in **Entra ID** under **Enterprise Applications** called **Vectra AI - Azure AD Lockdown**.

#### What permission in required in Microsoft for the Vectra AI app?

API Name

* Microsoft Graph

Claim value

* `Directory.ReadWrite.All`
* `UserAuthenticationMethod.ReadWrite.All`

Permission display name

* Read and write directory data
* Read and write all users' authentication methods

Permission description

* Allows the app to read and write data in your organization's directory, such as users, and groups, without a signed-in user. Does not allow user or group deletion.
  * Vectra requires this to revoke and disable accounts.
* Allows the app to read and write authentication methods of all users in your organization, without a signed-in user. Authentication methods include things like a user's phone number and Authentication app settings. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.
  * Vectra requires this to reset passwords.

#### How is the required permission in Microsoft configured?

This permission is granted as part of the automated consent process that is done by a global administrator.

#### Does the consent app link ever change?

No, once created, the consent app link remains the same and will not expire.

#### Can I setup Entra ID Account Lockdown for more than one tenant?

No, at this time, Entra ID (AAD) Account Lockdown supports a single Microsoft tenant. If the consent link is executed against a 2nd tenant, AAD Account Lockdown will stop working for accounts that exist in the original tenant where the consent flow was executed and start working in the 2nd tenant.

## Usage FAQs

#### What enforcement options does Entra ID (AAD) Account Lockdown provide?

Entra ID (AAD)/M365 accounts can be locked manually through the Respond UX with two options for enforcement actions:

1. Revoke active sessions
   * The account’s active session(s) are interrupted and the user is signed out.
2. Disable account and revoke active sessions
   * The account is disabled in Entra ID and the account's active session(s) and interrupted.
3. Reset account password and revoke active sessions
   * The user will be prompted to provide a new password on the next login and the account's active session(s) are interrupted.

Please note that all accounts that have been disabled will require manual re-enablement.

* This can be done through the Vectra UI (preferred) or outside of the Vectra UI in AAD.

#### How do I manually lock down an account?

All Entra ID (AAD)/M365 accounts will have a new Account Lockdown widget in the sidebar of individual account entity pages. From here you can enable or disable Lockdown. To lock down an account, simply click the **Disable Account** button and then select the desired enforcement action.

Please note that enabling or disabling manual lockdown on an account will require the Respond UX user to have the **Edit** for **Azure AD Lockdown** permission enabled in their assigned Vectra role.

<img src="/files/HiS7E03lIpRhX96rEpvV" alt="" width="245">

#### How can I utilize Automatic Entra ID (AAD) Account Lockdown?

After enabling Entra ID (AAD) Account Lockdown, you can also choose to enable Automatic Account Lockdown by clicking the slider next to the feature to **On**.

You can also pick the threshold for Automatic Lockdown by moving the slider to the desired Urgency score that must be met before Lockdown will happen.

#### Where can I check the Lockdown status of an account?

All Entra ID (AAD)/M365 accounts will have a new Account Lockdown widget in the sidebar of individual account pages. From here you can see the account's current Lockdown status. If an account is locked down, the status will show the username of the Respond UX user that enabled lockdown for that account and the time it was invoked.

<img src="/files/k5kHeqIRoFIeyd0PnNok" alt="" width="332">

In the case of an account having only their sessions revoked, the Lockdown event will be logged, but it will not be visible on the account page.

#### Once an AAD/M365 account has been disabled, how can it be re-enabled?

Entra ID (AAD)/M365 accounts can only be re-enabled via the following methods:

* A user with correct permissions manually re-enables account via the Respond UX (strongly recommended).
* Account is re-enabled outside of Respond UX (via Entra ID) (**NOT recommended**).
  * This is **NOT** recommended because Entra ID Account Lockdown does not know the enablement state of the account in the Microsoft tenant.

To re-enable an account through the Respond UX, simply click the **Re-enable Account** button as seen in the screenshot above.

#### Why is it preferred to re-enable an account through the Vectra UI?

Entra ID Account Lockdown does not know the enablement state of the account in the Microsoft tenant.

If an account is re-enabled in Entra ID and not through the Vectra UI, your Vectra UI will still show the account as **Disabled**. You can simply use the **Re-enable Account** option in your Vectra UI if you know the account has been enabled outside of the Respond UX.

#### Are there any account types that cannot be disabled?

Yes, Admin Azure AD account cannot be disabled and can only have active sessions revoked.

Revoke sessions, however, works for all accounts.

#### Is there API support for AAD Account Lockdown?

Not at this time.

## Notification

#### Will the end user be notified when an account is locked down?

No, the end user is not notified from Vectra whenever their account is in lockdown.

#### How can administrators know if an account has been locked down through Vectra?

The status of **Disabled until re-enabled** will be shown in the Account Lockdown widget on the account entity page.

Administrators will be notified via email.

#### Are logs available of Lockdown related actions?

* Yes, the audit log is available via API calls to the `/api/v3.3/events/audits endpoint`.
  * Any RUX API higher than v3.3 will work using the same endpoint.
* In the below example using Postman, here you can see a successful pull of `azure_ad_lockdown` related event objects:

![](/files/QlTQUrOSigicsdRxvzgK)

* For additional information on using the Respond UX API, please see the following KB articles:
  * [API Guide v3.3](/configuration/access/api-rux/v33-api-guide-rux.md)
  * [Quickstart Guide for using the API](/configuration/access/api-rux/rux-api-postman-quick-start-guide.md)
  * [Vectra public Postman collection for the API](https://www.postman.com/planetary-trinity-669963/workspace/vectra-ai/collection/1058623-cc38478b-7261-4e59-8768-1cf61a68ec5d)

## Disabling

#### If I no longer wish to use Entra ID (AAD) Account Lockdown, what are the steps to turn it off?

A Vectra user with the proper permissions to edit AAD Account Lockdown settings can simply navigate to *Configuration → RESPONSE → Lockdown → Azure AD Lockdown*, click **Edit** and then toggle the feature to **Off** and **Save** the setting.

* This will disable Entra ID Account Lockdown for any Vectra user until it is re-enabled.

#### How do I remove consent for the App if I wish to completely remove the integration?

Microsoft does not allow 3rd parties to revoke consent on behalf of a customer so an administrator can simply delete the **Vectra AI - Azure AD Lockdown** enterprise application.

The consent process can be followed again if you wish to re-enable consent in the future.

#### Technical Note

Most customers synchronize on premises Active Directory with Entra ID. AD remains the authoritative source for account attributes. Disabling an account only in the cloud layer can be overwritten by AD Connect on the next sync which makes that action less dependable. Disabling via Active Directory should be preferred.

Password resets behave differently. The reset is written back to AD then synced to Entra ID, for most deployment, so it persists across both systems. When paired with session revocation, all access and refresh tokens are invalidated. Since token theft attacks do not require the user’s password, forcing reauthentication cuts off the attacker immediately, giving your team a reliable containment action across cloud and hybrid identities.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.vectra.ai/configuration/response/lockdown/entra-id-azure-ad-account-lockdown-rux.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
