Description:

Verifies that users have least privilege access.

Why:

Many privileged administrative users do not need unfettered access to the tenant to perform their duties. By assigning them to roles based on least privilege, the risks associated with having their accounts compromised are reduced.

Configured: Users have least privilege access.

Not Configured: User with Global Admin privilege does not adhere to least privilege.

Scoring: Contributes up to 1 point to the Posture Recommendations score.

Category: Identity

Microsoft Licensing: Works with Basic licensing

Remediation in Augmentt: No in-product remediation — remediate in the Microsoft admin portals.

Compliance Frameworks:

  • CISA SCuBA — MS.AAD.7.2

  • CMMC Level 2 — AC.L2-3.1.5, AC.L2-3.1.7

Microsoft documentation: