EIDFED-006: Azure AD Connect Sync Scope Audit

Plataforma
Entra ID / M365
Categoría
Entra ID Federation & Hybrid Identity
Severidad
Medium
Pilar de Zero Trust
Identity (peso 3)
Fixtures de referencia
1
Cobertura de ramas
Observada: los fixtures prueban los veredictos que ejercitan
Procedencia
baseline

Qué comprueba

The synchronization scope in Azure AD Connect determines which on-premises organizational units, groups, and attributes are replicated to Entra ID. An overly broad sync scope may replicate sensitive service accounts, administrative accounts, or security groups that should remain exclusively on-premises. Conversely, an improperly restricted scope may fail to sync accounts that require cloud access, causing authentication failures.

Valor recomendado

Synchronization scope restricted to required organizational units and objects only, with sensitive service accounts and administrative objects excluded

Remediación

Review the Azure AD Connect synchronization scope including OU filtering, group-based filtering, and attribute-level filtering rules. Verify that only OUs containing user accounts that require cloud access are included in the sync scope. Exclude sensitive on-premises service accounts, administrative accounts, and security groups that do not need cloud representation, and document the rationale for each included OU.

Veredictos probados con fixtures

Cada veredicto de esta tabla está probado por un fixture de referencia en la suite de pruebas que valida el módulo. La tabla se deriva de la última ejecución en verde; no puede editarse a mano.

Escenarios de veredicto de EIDFED-006
EscenarioVeredicto esperado
not-implementedNot Assessed

Mapeos a marcos de referencia

NIST SP 800-53
AC-2