EIDPIM-008: Disabled Accounts in Privileged Roles

Platform
Entra ID / M365
Category
Entra ID Privileged Identity Management
Severity
High
Zero Trust pillar
Identity (weight 3)
Golden fixtures
3
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

Disabled user accounts that retain privileged role assignments create a latent security risk. If the account is re-enabled through administrative action or compromise, it immediately regains full privileged access. Disabled accounts should be promptly removed from all privileged roles as part of the offboarding or account deprovisioning process to eliminate this reactivation risk

Recommended value

No disabled accounts with active or eligible privileged role assignments

Remediation

Enumerate all privileged role members and filter for accounts where accountEnabled is false. Remove all privileged role assignments from disabled accounts immediately. Implement an automated process or access review that detects and removes role assignments when accounts are disabled

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for EIDPIM-008
ScenarioExpected verdict
cleanPASS
known-badFAIL
throttledNot Assessed

Framework mappings

NIST SP 800-53
AC-2(3)
MITRE ATT&CK
T1078.004