Description:
Verifies that admins are actively using assigned privileged role assignments.
Why:
Users that have been assigned privileged roles they don't need increases the chance of an attack. It's also easier for attackers to remain unnoticed in accounts that aren't actively being used.
Note: The check attempts to exclude emergency (Break Glass) accounts.
Configured: Admins are actively using assigned privileged role assignments.
Not Configured: Some admins have privileged role assignments which are not in use.
Scoring: Contributes up to 1 point to the Posture Recommendations score.
Category: Identity
Microsoft Licensing: Requires Premium (P2) licensing
Remediation in Augmentt: No in-product remediation — remediate in the Microsoft admin portals.
Compliance Frameworks:
Essential Eight (Maturity Level 2) — 1648
Essential Eight (Maturity Level 3) — 1648
Microsoft documentation:
