Information
Non-global administrator role group assignments should be reviewed at least every week.
Rationale:
While these roles are less powerful than a global admin, they do grant special privileges that can be used illicitly. If unusual activity is detected, contact the user to confirm it is a legitimate need.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.
Solution
To review non-global administrator role group assignments:
Navigate to Microsoft 365 Defender https://security.microsoft.com.
Click on Audit.
Set Added member to Role and Removed a user from a directory role for Activities.
Set Start Date and End Date.
Click Search.
Review.