EIDTNT-015: Privileged Partner Delegated Admin Access (GDAP)

Plataforma
Entra ID / M365
Categoría
Entra ID Tenant Configuration
Severidad
High
Pilar de Zero Trust
Identity (peso 3)
Fixtures de referencia
5
Cobertura de ramas
Observada: los fixtures prueban los veredictos que ejercitan
Procedencia
original

Qué comprueba

Granular Delegated Admin Privileges (GDAP) let a CSP or managed-services partner hold standing administrative roles in your tenant. This relationship is invisible in most day-to-day admin views, is rarely reviewed, and is a Kaseya-class propagation path: an attacker who compromises one partner inherits delegated administration in every downstream customer tenant at once. A partner relationship that carries a Tier-0 / high-impact directory role (Global Administrator, Privileged Role Administrator, Privileged/Authentication Administrator, Security Administrator, User/Password/Application/Cloud Application Administrator) is effectively an external set of keys to the kingdom. This check inventories active delegatedAdminRelationships and FAILS when any active relationship grants one of those privileged roles; it warns when non-privileged partner access exists so it can be confirmed and scoped, and passes only when there is no active partner delegated administration. Empty results are treated as 'no relationships' only when the collection succeeded — a failed call surfaces as Not Assessed, never as a clean pass.

Valor recomendado

No active GDAP relationship grants a privileged directory role; partner access is least-privilege, time-bound, and reviewed

Remediación

Review every active partner delegated admin (GDAP) relationship in Microsoft Entra admin center > Identity > External Identities > Cross-tenant access (Partner-led) and in the Microsoft 365 admin center > Settings > Partner relationships. For each relationship, remove Tier-0 / high-impact roles (Global Administrator, Privileged Role Administrator, Privileged Authentication Administrator, Security Administrator, User/Password/Application/Cloud Application Administrator) unless there is a documented, time-bound need. Replace standing privileged delegation with least-privilege roles, request just-in-time elevation through the partner's own PIM where possible, and terminate any relationship that is no longer required. Confirm the partner's own tenant enforces phishing-resistant MFA for the admins who exercise this access.

Veredictos probados con fixtures

Cada veredicto de esta tabla está probado por un fixture de referencia en la suite de pruebas que valida el módulo. La tabla se deriva de la última ejecución en verde; no puede editarse a mano.

Escenarios de veredicto de EIDTNT-015
EscenarioVeredicto esperado
no-partnersPASS
not-assessedNot Assessed
privilegedFAIL
scopedWARN
terminated-onlyPASS

Mapeos a marcos de referencia

NIST SP 800-53
AC-2, AC-3, AC-6, PS-7, SA-9
CIS M365 Benchmark
1.1.3