🛡️ Azure Tenant Creator Role Assignments are not periodically reviewed🟢⚪
- Contextual name: 🛡️ Tenant Creator Role Assignments are not periodically reviewed🟢⚪
- ID:
/ce/ca/azure/subscription/tenant-creator-role-assignments - Tags:
- Policy Type:
COMPLIANCE_POLICY - Policy Categories:
SECURITY
Description
Description
Perform a periodic review of the Tenant Creator role assignment to ensure that the assignments are accurate and appropriate.
Rationale
Unnecessary assignments increase the risk of privilege escalation and unauthorized access.
Impact
Verify that the Tenant Creator role is no longer required by any assignments before removal to avoid disruption of critical functions.
Audit
From Azure Portal
- Go to
Microsoft Entra ID.- Under
Manage, clickRoles and administrators.- In the search bar, type
Tenant Creator.- Click the role.
- Review the assignments and ensure that they are appropriate.
Default Value
The Tenant Creator role is not assigned by default.
References
Remediation
Remediation
From Azure Portal
- Go to
Microsoft Entra ID.- Under
Manage, clickRoles and administrators.- In the search bar, type
Tenant Creator.- Click the role.
- Click the name of an assignment.
- Check the box next to the
Tenant Creatorrole.- Click
X Remove assignments.- Click
Yes.- Repeat steps 1-8 for each assignment requiring remediation.
policy.yaml
Linked Framework Sections
| Section | Sub Sections | Internal Rules | Policies | Flags | Compliance |
|---|---|---|---|---|---|
| 💼 CIS Azure v5.0.0 → 💼 5.3.6 Ensure 'Tenant Creator' role assignments are periodically reviewed (Manual) | 1 | no data | |||
| 💼 Cloudaware Framework → 💼 Role-Based Access Control (RBAC) Management | 18 | no data |