Description:

Verifies that tenant has no unmanaged active role assignments.

Why:

Provisioning users to privileged roles within a PAM system enables enforcement of numerous privileged access policies and monitoring. If privileged users are assigned directly to roles in the M365 admin center or via PowerShell outside of the context of a PAM system, a significant set of critical security capabilities are bypassed.

Configured: Tenant has no unmanaged active role assignments.

Not Configured: Tenant has unmanaged active role assignments.

Scoring: Contributes up to 1 point to the Posture Recommendations score.

Category: Identity

Microsoft Licensing: Requires Premium (P2) licensing

Remediation in Augmentt: No in-product remediation — remediate in the Microsoft admin portals.

Compliance Frameworks:

  • CISA SCuBA — MS.AAD.7.5

  • CIS Microsoft 365 Benchmark v6 (Level 2) — 5.3.1

  • CIS Microsoft 365 Benchmark v7 (Level 2) — 5.3.1

  • CMMC Level 2 — AC.L2-3.1.5, AC.L2-3.1.2

Microsoft documentation: