EIDPIM-009: Accounts Never Signed In with Active Privileged Role
- Plataforma
- Entra ID / M365
- Categoría
- Entra ID Privileged Identity Management
- Severidad
- Medium
- Pilar de Zero Trust
- Identity (peso 1)
- Fixtures de referencia
- 3
- Cobertura de ramas
- Observada: los fixtures prueban los veredictos que ejercitan
- Procedencia
- baseline
Qué comprueba
Accounts that hold privileged role assignments but have never signed in may represent provisioned-but-unclaimed accounts, test accounts, or migration artifacts. These dormant privileged accounts are high-risk targets because they may have default or weak credentials and are unlikely to be monitored by their intended owners. An attacker who discovers and authenticates as one of these accounts gains immediate privileged access
Valor recomendado
No privileged role assignments on accounts that have never signed in
Remediación
Review all privileged role members and identify accounts with a null or empty lastSignInDateTime. Investigate each account to determine if it is still needed. Remove privileged role assignments from dormant accounts and disable any accounts that have no valid business purpose
Veredictos probados con fixtures
Cada veredicto de esta tabla está probado por un fixture de referencia en la suite de pruebas que valida el módulo. La tabla se deriva de la última ejecución en verde; no puede editarse a mano.
| Escenario | Veredicto esperado |
|---|---|
| clean | PASS |
| known-bad | FAIL |
| throttled | Not Assessed |
Mapeos a marcos de referencia
- NIST SP 800-53
- AC-2(3)
- MITRE ATT&CK
- T1078.004