Forum Discussion

WHendrickson's avatar
WHendrickson
Copper Contributor
Apr 06, 2021

Azure CIS policies with ADDS Joined VMs

I'm having problems with 2 specific CIS policies that I can't seems to remediate.

 

The 2 policies are as follows;

1. CCE-37167-4 -- Ensure 'Maximum password age' is set to '70 or fewer days, but not 0'

2. CCE-36534-6 -- Ensure 'Minimum password length' is set to '14 or more character(s)'

 

As my VMs are domain joined to an ADDS managed domain these two (2) settings are inherited from them and are not changeable from what I've read. I have also tried to influence these values from O365 admin portal with no resolve.

 

My question is how do I remediate these or remove them from the recommendations if I don't have control over there values? Dismissing them does not remove them from the recommendations unfortunately.

Resources