More Info:

Minimize or restrict principals which can modify infrastructure.

Risk Level

High

Address

Security

Compliance Standards

CBP

Triage and Remediation

Remediation

To remediate the misconfiguration of “Principals with Infrastructure modification capabilities” in Azure using the Azure console, follow these step-by-step instructions:

  1. Sign in to the Azure portal (https://portal.azure.com) using your Azure account credentials.

  2. Navigate to the Azure Active Directory (AAD) service by clicking on the “Azure Active Directory” option in the left-hand menu.

  3. In the Azure Active Directory overview page, click on the “Security” tab in the left-hand menu.

  4. Under the “Security” tab, click on the “Azure AD Identity Governance” option.

  5. In the Azure AD Identity Governance page, click on the “Privileged Identity Management” option.

  6. In the Privileged Identity Management page, click on the “Azure resources” tab.

  7. You will see a list of Azure resources with their respective owners and roles. Identify the principals (users or groups) that have “Infrastructure modification capabilities” assigned to them.

  8. To remediate the misconfiguration, you have two options:

    a. Remove the “Infrastructure modification capabilities” assignment:

    • Click on the principal’s name or email address.
    • In the principal’s details page, click on the “Remove Assignment” button next to the “Infrastructure modification capabilities” role.
    • Confirm the removal when prompted.

    b. Review and modify the “Infrastructure modification capabilities” assignment:

    • Click on the principal’s name or email address.
    • In the principal’s details page, review the “Infrastructure modification capabilities” role assignment.
    • Modify the assignment as per your organization’s security policies and requirements.
    • Click on the “Save” button to apply the changes.
  9. Repeat steps 7 and 8 for all principals that have the “Infrastructure modification capabilities” assigned.

By following these steps, you will be able to remediate the misconfiguration of “Principals with Infrastructure modification capabilities” in Azure using the Azure console.