STIGQter STIGQter: STIG Summary: Microsoft Entra ID Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 28 Feb 2025:

Microsoft Entra ID must notify system administrators (SAs) and the information system security officer (ISSO) when privileges are being requested.

DISA Rule

SV-270255r1085626_rule

Vulnerability Number

V-270255

Group Title

SRG-APP-000292

Rule Version

ENTR-ID-000835

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure PIM to email notifications to the SA and ISSO when privileges are requested.

1. Sign in to the Microsoft Entra admin center as at least an Authentication Policy Administrator.
2. Search for "Microsoft Entra Privileged Identity Management".
3. Navigate to "Management" and select "Microsoft Entra roles".
4. Expand the "Manage" menu and select roles.
5. For each role that is either active or eligible perform the following:
a. Select the role.
b. Navigate to role settings.
c. Select "Edit".
d. Navigate to the "Notification" tab.
e. Under "Send notifications when eligible members activate this role:" add the SA and ISSO email addresses under "Additional recipients".
f. Select "Update".

Check Contents

Verify PIM is in use with email notifications going to the SA and ISSO when privileges are requested.

1. Sign in to the Microsoft Entra admin center as at least an Authentication Policy Administrator.
2. Search for "Microsoft Entra Privileged Identity Management".
3. Navigate to "Management" and select "Microsoft Entra roles".
4. Expand the "Manage" menu and select roles.
5. For each role that is either active or eligible perform the following:
a. Select the role.
b. Navigate to role settings.
c. Under "Send notifications when eligible members activate this role:" Verify the SA and ISSO email addresses are listed under "Additional recipients" for the type "Role activation alert".

If the SA and ISSO are not set up to receive email notification when privileges are requested through PIM, this is a finding.

Vulnerability Number

V-270255

Documentable

False

Rule Version

ENTR-ID-000835

Severity Override Guidance

Verify PIM is in use with email notifications going to the SA and ISSO when privileges are requested.

1. Sign in to the Microsoft Entra admin center as at least an Authentication Policy Administrator.
2. Search for "Microsoft Entra Privileged Identity Management".
3. Navigate to "Management" and select "Microsoft Entra roles".
4. Expand the "Manage" menu and select roles.
5. For each role that is either active or eligible perform the following:
a. Select the role.
b. Navigate to role settings.
c. Under "Send notifications when eligible members activate this role:" Verify the SA and ISSO email addresses are listed under "Additional recipients" for the type "Role activation alert".

If the SA and ISSO are not set up to receive email notification when privileges are requested through PIM, this is a finding.

Check Content Reference

M

Target Key

5671