MS.AAD.7.7v1 - Eligible and Active highly privileged role assignments SHALL trigger an alert.

Information

Closely monitor assignment of the highest privileged roles for signs of compromise. Send assignment alerts to enable the security monitoring team to detect compromise attempts.

Solution

1. In Microsoft Entra Privileged Identity Management (PIM), under Manage, select Microsoft Entra roles.

2. Under Manage, select Roles. Perform the steps below for each highly privileged role. We reference the Global Administrator role as an example.

3. Click the Global Administrator role.

4. Click Settings and then click Edit.

5. Click the Notification tab.

6. Under Send notifications when members are assigned as eligible to this role, in the Role assignment alert > Additional recipients textbox, enter the email address of the security monitoring mailbox configured to receive privileged role assignment alerts.

7. Under Send notifications when members are assigned as active to this role, in the Role assignment alert > Additional recipients textbox, enter the email address of the security monitoring mailbox configured to receive privileged role assignment alerts.

8. Click Update.

9. For each of the highly privileged roles, if they have any PIM groups actively assigned to them, then also apply the same configurations per the steps above to each PIM group's Member settings.

See Also

https://github.com/cisagov/ScubaGear/tree/v1.5.0/

Item Details

Category: ACCESS CONTROL, CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|AC-2, 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|AC-20, 800-53|CM-5, 800-53|CM-6, 800-53|IA-2, 800-53|IA-5, 800-53|SI-4, 800-53|SI-7

Plugin: microsoft_azure

Control ID: 38d07bcba697da3906e3800516ac7ef26eae28eef9d6a893668b919aae61ec45