Description:
Verifies that tenant has no active privilege role assignments without expiration.
Why:
Instead of giving users permanent assignments to privileged roles, provisioning access just in time lessens exposure if those accounts become compromised. In Azure AD PIM or an alternative PAM system, just in time access can be provisioned by assigning users to roles as eligible instead of perpetually active.
Configured: Tenant has no active privilege role assignments without expiration.
Not Configured: Your tenant has active privileged role assignments without expiration.
Scoring: Contributes up to 1 point to the Posture Recommendations score.
Category: Identity
Microsoft Licensing: Requires Premium (P2) licensing
Remediation in Augmentt: No in-product remediation — remediate in the Microsoft admin portals.
Compliance Frameworks:
CISA SCuBA — MS.AAD.7.4
CIS Microsoft 365 Benchmark v6 (Level 2) — 5.3.1
CIS Microsoft 365 Benchmark v7 (Level 2) — 5.3.1
CMMC Level 2 — AC.L2-3.1.5
Microsoft documentation:
