More Info:

Administrator access also brings risk with them. Try to have minimum admins in your account.

Risk Level

High

Address

Security

Compliance Standards

CISGCP,HIPAA,SCO2,NISTCSF,NIST,AWSWAF,ISO27001,HITRUST

Triage and Remediation

Remediation

To remediate the misconfiguration of having users with Administrator Access in Azure, follow these step-by-step instructions using the Azure console:

  1. Sign in to the Azure portal (portal.azure.com) using your Azure account credentials.

  2. In the Azure portal, navigate to the Azure Active Directory (AAD) service by clicking on “Azure Active Directory” in the left-hand navigation menu.

  3. In the AAD overview page, click on “Users” under the “Manage” section in the left-hand menu.

  4. Review the list of users and identify the user accounts that have Administrator Access. These accounts will typically have the “Global administrator” or “User administrator” roles assigned.

  5. Select the user account(s) that have Administrator Access by clicking on the checkbox next to their names.

  6. Once the desired user account(s) are selected, click on the “Remove” button at the top of the user list.

  7. In the confirmation dialog box, review the list of selected user accounts and click on “Yes” to confirm the removal of their Administrator Access.

  8. After removing the Administrator Access, it is recommended to assign appropriate roles and permissions to these user accounts based on their responsibilities and requirements. To do this, click on the “Add assignments” button at the top of the user list.

  9. In the “Add assignments” dialog box, select the desired role(s) from the list based on the user’s responsibilities. Commonly used roles include “Owner,” “Contributor,” or more specific roles like “Virtual Machine Contributor” or “Storage Account Contributor.”

  10. After selecting the role(s), search and select the user account(s) that need to be assigned the role(s). You can search by name or email address.

  11. Once the user account(s) are selected, click on the “Add” button to assign the selected role(s).

  12. Repeat steps 9-11 for each user account that needs to be assigned appropriate roles.

  13. After assigning the roles, review the list of users to ensure that there are no remaining user accounts with Administrator Access.

By following these steps, you will remediate the misconfiguration of having users with Administrator Access in Azure. It is crucial to regularly review and manage user access to maintain a secure and well-controlled environment.