Forum Discussion
WHendrickson
Apr 06, 2021Copper Contributor
Azure CIS policies with ADDS Joined VMs
I'm having problems with 2 specific CIS policies that I can't seems to remediate.
The 2 policies are as follows;
1. CCE-37167-4 -- Ensure 'Maximum password age' is set to '70 or fewer days, but not 0'
2. CCE-36534-6 -- Ensure 'Minimum password length' is set to '14 or more character(s)'
As my VMs are domain joined to an ADDS managed domain these two (2) settings are inherited from them and are not changeable from what I've read. I have also tried to influence these values from O365 admin portal with no resolve.
My question is how do I remediate these or remove them from the recommendations if I don't have control over there values? Dismissing them does not remove them from the recommendations unfortunately.
- StanislavBelov
Microsoft
Hi WHendrickson
Dismissing a CCEID changes the status of an item to "dismissed" and hides it from the dashboard.
If you still see it, please make sure your filter set to not display dismissed items:
- WHendricksonCopper Contributor
You are correct that they are hidden if dismissed however they are not removed from your secure score and regulatory compliance scores.
I'm looking at how to be exempt from these policies if I can't control them so they don't reflect negatively against our scores.
Thanks,
- StanislavBelov
Microsoft
In this case you can either disable certain rules (disabled findings won't be counted towards your secure score) or exempt the whole recommendation (not recommended):
https://docs.microsoft.com/en-us/azure/security-center/remediate-vulnerability-findings-vm?WT.mc_id=Portal-Microsoft_Azure_Security#disable-specific-findings-preview