EIDPIM-014: Privileged Role Assignment Notification Settings

Platform
Entra ID / M365
Category
Entra ID Privileged Identity Management
Severity
Medium
Zero Trust pillar
Identity (weight 3)
Golden fixtures
1
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

Notifications should be configured to alert security personnel when privileged roles are activated or permanently assigned. Without proper notification settings, unauthorized privilege escalation or role activation can go undetected, allowing attackers or malicious insiders to operate with elevated permissions without triggering any alerts. Notification settings are a critical detective control that complements preventive PIM configurations

Recommended value

Notifications enabled for all privileged role activations and new permanent assignments, sent to designated security operations contacts

Remediation

Navigate to Entra ID > Roles and administrators > Settings for each privileged role. Under the Notification tab, ensure notifications are enabled for role activation, permanent assignment, and eligible assignment events. Configure notification recipients to include the security operations team distribution list. Verify notifications are being received by performing a test activation

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for EIDPIM-014
ScenarioExpected verdict
not-implementedNot Assessed

Framework mappings

CISA SCuBA
MS.AAD.7.7v1, MS.AAD.7.8v1, MS.AAD.7.9v1
NIST SP 800-53
AU-5, SI-4
MITRE ATT&CK
T1078.004