5.3.6 Ensure 'Tenant Creator' role assignments are periodically reviewed

Information

Perform a periodic review of the Tenant Creator role assignment to ensure that the assignments are accurate and appropriate.

This recommendation should be applied alongside the recommendation "Ensure that 'Restrict non-admin users from creating tenants' is set to 'Yes'".

Unnecessary assignments increase the risk of privilege escalation and unauthorized access.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Remediate from Azure Portal

- Go to Microsoft Entra ID.
- Under Manage, click Roles and administrators.
- In the search bar, type Tenant Creator.
- Click the role.
- Click the name of an assignment.
- Check the box next to the Tenant Creator role.
- Click X Remove assignments.
- Click Yes.
- Repeat steps 1-8 for each assignment requiring remediation.

Impact:

Verify that the Tenant Creator role is no longer required by any assignments before removal to avoid disruption of critical functions.

See Also

https://workbench.cisecurity.org/benchmarks/21611

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6(2), 800-53|AC-6(5), CSCv7|4.3

Plugin: microsoft_azure

Control ID: eb824d8b6804a97baf28bacb0cb685b71c30dde35727fe327f92bd78082f6bd4