MS.AAD.7.6v1 - Activation of the Global Administrator role SHALL require approval.

Information

Requiring approval for a user to activate Global Administrator, which provides unfettered access, makes it more challenging for an attacker to compromise the tenant with stolen credentials and it provides visibility of activities indicating a compromise is taking place.

Solution

1. In Microsoft Entra Privileged Identity Management (PIM), under Manage, select Microsoft Entra roles.

2. Under Manage, select Roles.

1. Select the Global Administrator role in the list.
2. Click Settings.
3. Click Edit.
4. Select the Require approval to activate option.
5. Click Update.

3. Review the list of groups that are actively assigned to the Global Administrator role. If any of the groups are enrolled in PIM for Groups, then also apply the same configurations under step 2 above to each PIM group's Member settings.

See Also

https://github.com/cisagov/ScubaGear/tree/v1.5.0/

Item Details

Category: ACCESS CONTROL, CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|AC-2, 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|AC-20, 800-53|CM-5, 800-53|CM-6, 800-53|IA-2, 800-53|IA-5, 800-53|SI-4, 800-53|SI-7

Plugin: microsoft_azure

Control ID: df3cc9351ec6414a4c2cc40ad86cfc9e9299c85e5dd6c409f6856a61993160ab