SV-272886r1119409_rule
V-272886
SRG-APP-000211
MSDE-00-000300
CAT II
10
Access the Azure Entra ID portal as a Global Admin or other role with the ability to create/assign roles and users/groups.
1. Select Manage >> Roles and administrators.
2. Click on the "Security Administrator" role ,then click "+Add assignments".
3. Under "Select Member(s)" add AO-approved users for this role. This role is a top-level administrator within MDE.
Note: A custom defined, AO-approved role may be created and used in lieu of the built-in "MDE Administrator" role.
4. Return to the Entra ID portal home and select Manage >> Groups. Click "New group".
5. Define at least one sub-level group for MDE administration as defined by the AO and assign users(s) to these groups.
Access the Azure Entra ID portal as a Global Admin or other role with the ability to create/assign roles.
1. Select Manage >> Roles and administrators. Click on the "MDE Administrator" role.
2. Under "Active assignments" ensure one or more authorizing official (AO)-approved users are assigned to this role. This role is a top-level administrator within MDE.
Note: A custom defined, AO-approved role may be created and used in lieu of the built-in MDE Administrator role.
If one or more AO-approved users have not been assigned to the security administrator (or equivalent AO-approved) role, this is a finding.
1. Return to the Entra ID portal home and select Manage >> Groups. Click the number next to "Total Groups".
2. Ensure one or more custom roles have been defined as subordinate roles for MDE administration. The structure of various subordinate groups is to be defined by the AO.
3. Click on each of these groups and ensure one or more users have been assigned.
If one or more subordinate groups do not exist, this is a finding.
If one or more users do not exist in these subordinate groups, this is a finding.
V-272886
False
MSDE-00-000300
Access the Azure Entra ID portal as a Global Admin or other role with the ability to create/assign roles.
1. Select Manage >> Roles and administrators. Click on the "MDE Administrator" role.
2. Under "Active assignments" ensure one or more authorizing official (AO)-approved users are assigned to this role. This role is a top-level administrator within MDE.
Note: A custom defined, AO-approved role may be created and used in lieu of the built-in MDE Administrator role.
If one or more AO-approved users have not been assigned to the security administrator (or equivalent AO-approved) role, this is a finding.
1. Return to the Entra ID portal home and select Manage >> Groups. Click the number next to "Total Groups".
2. Ensure one or more custom roles have been defined as subordinate roles for MDE administration. The structure of various subordinate groups is to be defined by the AO.
3. Click on each of these groups and ensure one or more users have been assigned.
If one or more subordinate groups do not exist, this is a finding.
If one or more users do not exist in these subordinate groups, this is a finding.
M
5693