EIDPIM-014: Privileged Role Assignment Notification Settings
- Platform
- Entra ID / M365
- Category
- Entra ID Privileged Identity Management
- Severity
- Medium
- Zero Trust pillar
- Identity (weight 3)
- Golden fixtures
- 1
- Branch coverage
- Observed: fixtures prove the verdicts they exercise
- Provenance
- baseline
What it checks
Notifications should be configured to alert security personnel when privileged roles are activated or permanently assigned. Without proper notification settings, unauthorized privilege escalation or role activation can go undetected, allowing attackers or malicious insiders to operate with elevated permissions without triggering any alerts. Notification settings are a critical detective control that complements preventive PIM configurations
Recommended value
Notifications enabled for all privileged role activations and new permanent assignments, sent to designated security operations contacts
Remediation
Navigate to Entra ID > Roles and administrators > Settings for each privileged role. Under the Notification tab, ensure notifications are enabled for role activation, permanent assignment, and eligible assignment events. Configure notification recipients to include the security operations team distribution list. Verify notifications are being received by performing a test activation
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| not-implemented | Not Assessed |
Framework mappings
- CISA SCuBA
- MS.AAD.7.7v1, MS.AAD.7.8v1, MS.AAD.7.9v1
- NIST SP 800-53
- AU-5, SI-4
- MITRE ATT&CK
- T1078.004