EIDPIM-014: Privileged Role Assignment Notification Settings
- Plataforma
- Entra ID / M365
- Categoría
- Entra ID Privileged Identity Management
- Severidad
- Medium
- Pilar de Zero Trust
- Identity (peso 3)
- Fixtures de referencia
- 1
- Cobertura de ramas
- Observada: los fixtures prueban los veredictos que ejercitan
- Procedencia
- baseline
Qué comprueba
Notifications should be configured to alert security personnel when privileged roles are activated or permanently assigned. Without proper notification settings, unauthorized privilege escalation or role activation can go undetected, allowing attackers or malicious insiders to operate with elevated permissions without triggering any alerts. Notification settings are a critical detective control that complements preventive PIM configurations
Valor recomendado
Notifications enabled for all privileged role activations and new permanent assignments, sent to designated security operations contacts
Remediación
Navigate to Entra ID > Roles and administrators > Settings for each privileged role. Under the Notification tab, ensure notifications are enabled for role activation, permanent assignment, and eligible assignment events. Configure notification recipients to include the security operations team distribution list. Verify notifications are being received by performing a test activation
Veredictos probados con fixtures
Cada veredicto de esta tabla está probado por un fixture de referencia en la suite de pruebas que valida el módulo. La tabla se deriva de la última ejecución en verde; no puede editarse a mano.
| Escenario | Veredicto esperado |
|---|---|
| not-implemented | Not Assessed |
Mapeos a marcos de referencia
- CISA SCuBA
- MS.AAD.7.7v1, MS.AAD.7.8v1, MS.AAD.7.9v1
- NIST SP 800-53
- AU-5, SI-4
- MITRE ATT&CK
- T1078.004