More Info:

Ensure that the external accounts with write permissions are monitored using Azure Security Center.

Risk Level

Medium

Address

Security, Operational Maturity

Compliance Standards

CBP

Triage and Remediation

Remediation

The misconfiguration “Monitor External Accounts with Write Permissions” in Azure means that external accounts have write permissions to your Azure resources, which can potentially lead to unauthorized access or data breaches. To remediate this, follow the steps below:

  1. Open the Azure portal and sign in with your credentials.
  2. Navigate to the “Azure Active Directory” service.
  3. Click on “External Identities” in the left-hand menu.
  4. Click on “Azure AD Domain Services” in the External Identities menu.
  5. Click on the “Properties” tab.
  6. Under “Write Access,” select “Disabled.”
  7. Click “Save” to apply the changes.

By disabling write access for external accounts, you are limiting their ability to modify your Azure resources. This helps prevent unauthorized access or data breaches.