rules/findings/entra/pim/eid-approval-not-required-for-role-activation.json
|
{
"provider": "EntraID", "serviceType": "Privileged Identity Management", "serviceName": "Microsoft Entra ID", "displayName": "Ensure approval is required for _ARG_0_ role activation", "description": "_ARG_1_", "rationale": "_ARG_2_", "impact": "_ARG_3_", "remediation": { "text": " ###### To remediate using the UI: 1. Navigate to Microsoft Entra admin center https://entra.microsoft.com/. 2. Click to expand Identity Governance select Privileged Identity Management. 3. Under Manage select Microsoft Entra Roles. 4. Under Manage select Roles. 5. Select _ARG_0_ in the list. 6. Select Role settings and click Edit. 7. Check the Require approval to activate box. 8. Add at least two approvers. 9. Click Update. ", "code": { "powerShell": null, "iac": null, "terraform": null, "other": null } }, "recommendation": null, "references": [ "https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-configure", "https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/groups-role-settings#require-approval-to-activate" ], "compliance": [ { "name": "Monkey365 Entra", "version": "0.0.1", "reference": "5.3.1", "profile": [ ] } ], "level": "medium", "tags": [ ], "rule": { "path": "aad_pim_roleAssignment", "subPath": null, "selectCondition": { }, "data": { "properties": { "policy.settings.@odata.type": "@odata.type", "policy.settings.id": "policyId", "policy.settings.setting": "policySetting", "roleName": "displayName", "description": "description", "templateId": "templateId" }, "expandObject": "policy.settings" }, "query": [ { "filter": [ { "conditions": [ [ "templateId", "eq", "_ARG_4_" ], [ "@odata.type", "like", "*unifiedRoleManagementPolicyApprovalRule*" ] ], "operator":"and" } ] }, { "connectOperator": "and", "filter": [ { "conditions": [ [ "isApprovalRequired", "eq", "False" ], [ "approvalStages.primaryApproversCount", "lt", "2" ] ], "operator":"or", "whereObject":"policySetting" } ] } ], "shouldExist": null, "returnObject": null, "removeIfNotExists": null }, "output": { "html": { "data": { "properties": { "templateId": "templateId", "displayName": "displayName", "description": "description", "policySetting.isApprovalRequired": "Approval Required", "policySetting.approvalStages.primaryApproversCount": "Primary Approvers Count" } }, "table": "default", "decorate": [ ], "emphasis": [ ], "actions": { "objectData": { "properties": [ "*" ], "expandObject": null, "limit": null }, "showGoToButton": false, "showModalButton": false, "directLink": null } }, "text": { "data": { "properties": { "templateId": "templateId", "displayName": "displayName", "description": "description", "policySetting.isApprovalRequired": "Approval Required", "policySetting.approvalStages.primaryApproversCount": "Primary Approvers Count" } }, "status": { "keyName": "", "message": "Ensure approval is required for _ARG_0_ role activation", "defaultMessage": "Ensure approval is required for _ARG_0_ role activation" }, "properties": { "resourceName": "displayName", "resourceId": "templateId", "resourceType": "PIMUnifiedRoleManagementPolicyApprovalRule" }, "onlyStatus": false } }, "idSuffix": "eid_approval_for__ARG_0__not_enabled", "notes": [ ], "categories": [ ], "immutable_properties": [ "templateId", "displayName" ], "id": "monkey_entra__ARG_5_" } |