STIGQter STIGQter: STIG Summary: Microsoft Entra ID Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 28 Feb 2025:

Microsoft Entra ID must use Privileged Identity Management (PIM).

DISA Rule

SV-270335r1085641_rule

Vulnerability Number

V-270335

Group Title

SRG-APP-000234

Rule Version

ENTR-ID-001900

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure PIM to just-in-time (JIT) access and employ the principle of least privilege access.

When assigning privileged roles to accounts, select the assignment type of "Eligible".

Check Contents

Verify PIM is in use with just-in-time (JIT) access and employing the principle of least privilege access.

1. Sign in to the Microsoft Entra admin center as at least an Authentication Policy Administrator.
2. Search for "Microsoft Entra Privileged Identity Management".
3. Navigate to "Management" and select "Microsoft Entra roles".
4. Expand the "Manage" menu and select "Assignments".
5. Select the "Active assignments" tab and for each privileged role, verify there are no roles with an end time of "Permanent".

If any privileged roles are present with an end time of "Permanent", this is a finding.

Vulnerability Number

V-270335

Documentable

False

Rule Version

ENTR-ID-001900

Severity Override Guidance

Verify PIM is in use with just-in-time (JIT) access and employing the principle of least privilege access.

1. Sign in to the Microsoft Entra admin center as at least an Authentication Policy Administrator.
2. Search for "Microsoft Entra Privileged Identity Management".
3. Navigate to "Management" and select "Microsoft Entra roles".
4. Expand the "Manage" menu and select "Assignments".
5. Select the "Active assignments" tab and for each privileged role, verify there are no roles with an end time of "Permanent".

If any privileged roles are present with an end time of "Permanent", this is a finding.

Check Content Reference

M

Target Key

5671