Information
Perform a periodic review of the Tenant Creator role assignment to ensure that the assignments are accurate and appropriate.
This recommendation should be applied alongside the recommendation "Ensure that 'Restrict non-admin users from creating tenants' is set to 'Yes'".
Unnecessary assignments increase the risk of privilege escalation and unauthorized access.
NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.
Solution
Remediate from Azure Portal
- Go to Microsoft Entra ID.
- Under Manage, click Roles and administrators.
- In the search bar, type Tenant Creator.
- Click the role.
- Click the name of an assignment.
- Check the box next to the Tenant Creator role.
- Click X Remove assignments.
- Click Yes.
- Repeat steps 1-8 for each assignment requiring remediation.
Impact:
Verify that the Tenant Creator role is no longer required by any assignments before removal to avoid disruption of critical functions.