EIDSCA-AP14: EIDSCA AP14: Default Authorization Settings - Default User Role Permissions - Allowed to read other users

Platform
Entra ID / M365
Category
EIDSCA Baseline
Severity
Low
Zero Trust pillar
Identity (weight 1)
Golden fixtures
3
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

Entra ID security-configuration control (EIDSCA AP14): evaluates 'defaultUserRolePermissions.allowedToReadOtherUsers' on the Entra ID authorization policy against the recommended secure value.

Recommended value

eq true

Remediation

Configure the Entra ID authorization policy so 'defaultUserRolePermissions.allowedToReadOtherUsers' is set to true. (Entra ID security-configuration baseline, control EIDSCA AP14.)

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for EIDSCA-AP14
ScenarioExpected verdict
failFAIL
no-dataNot Assessed
passPASS

Framework mappings

EIDSCA
AP14