MS.AAD.7.5v1 - Provisioning users to highly privileged roles SHALL NOT occur outside of a PAM system.

Information

Provisioning users to privileged roles within a PAM system enables enforcement of numerous privileged access policies and monitoring. If privileged users are assigned directly to roles in the M365 admin center or via PowerShell outside of the context of a PAM system, a significant set of critical security capabilities are bypassed.

Solution

1. Perform the steps below for each highly privileged role. We reference the Global Administrator role as an example.

2. In Microsoft Entra admin center select Roles and administrators.

3. Select the Global administrator role.

4. Under Manage, select Assignments and click the Active assignments tab.

5. For each user or group listed, examine the value in the Start time column. If it contains a value of -, this indicates the respective user/group was assigned to that role outside of Microsoft Entra ID PIM. If the role was assigned outside of Microsoft Entra ID PIM, delete the assignment and recreate it using Microsoft Entra ID PIM.

See Also

https://github.com/cisagov/ScubaGear/tree/v1.5.0/

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: microsoft_azure

Control ID: a0cfd2dff9bcec59caa478e6240dae3f9a5a1432bbc23568a384686d7baf5f72