SV-253535r1051115_rule
V-253535
SRG-APP-000148-CTR-000335
CNTR-PC-000510
CAT II
10
Navigate to Prisma Cloud Compute Console's >> Manage >> Authentication >> Users tab.
Ensure only the break glass administrator account is a "local" account.
Delete all other local accounts and use the SAML identity provider for all authentication and authorization to the Prisma Cloud Compute Console.
Confirm there is only one "break glass" local administrative account.
Navigate to Prisma Cloud Compute Console's Manage >> Authentication >> Users tab.
Only the administrative break glass account is allowed to have Authentication Method = Local.
For all other accounts, Authentication Method = SAML.
If any local account, except the administrative break glass account, has Authentication Method set to other than "SAML", this is a finding.
V-253535
False
CNTR-PC-000510
Confirm there is only one "break glass" local administrative account.
Navigate to Prisma Cloud Compute Console's Manage >> Authentication >> Users tab.
Only the administrative break glass account is allowed to have Authentication Method = Local.
For all other accounts, Authentication Method = SAML.
If any local account, except the administrative break glass account, has Authentication Method set to other than "SAML", this is a finding.
M
5473