MS.AAD.7.8v1 - User activation of the Global Administrator role SHALL trigger an alert.

Information

Closely monitor activation of the Global Administrator role for signs of compromise. Send activation alerts to enable the security monitoring team to detect compromise attempts.

Solution

1. In Microsoft Entra Privileged Identity Management (PIM), under Manage, select Microsoft Entra roles.

2. Under Manage, select Roles.

3. Click the Global Administrator role.

4. Click Settings and then click Edit.

5. Click the Notification tab.

6. Under Send notifications when eligible members activate this role, in the Role activation alert > Additional recipients textbox, enter the email address of the security monitoring mailbox configured to receive Global Administrator activation alerts.

7. Click Update.

8. If the Global Administrator role has any PIM groups actively assigned to it, then also apply the same configurations per the steps above to each PIM group's Member settings.

See Also

https://github.com/cisagov/ScubaGear/tree/v1.5.0/

Item Details

Category: ACCESS CONTROL, CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|AC-2, 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|AC-20, 800-53|CM-5, 800-53|CM-6, 800-53|IA-2, 800-53|IA-5, 800-53|SI-4, 800-53|SI-7

Plugin: microsoft_azure

Control ID: 4953d652a773e1bbad6346ce6084b58395d96e3a85ca12208f37daf80d811dfb