Azure CIS policies with ADDS Joined VMs

Copper Contributor

I'm having problems with 2 specific CIS policies that I can't seems to remediate.

 

The 2 policies are as follows;

1. CCE-37167-4 -- Ensure 'Maximum password age' is set to '70 or fewer days, but not 0'

2. CCE-36534-6 -- Ensure 'Minimum password length' is set to '14 or more character(s)'

 

As my VMs are domain joined to an ADDS managed domain these two (2) settings are inherited from them and are not changeable from what I've read. I have also tried to influence these values from O365 admin portal with no resolve.

 

My question is how do I remediate these or remove them from the recommendations if I don't have control over there values? Dismissing them does not remove them from the recommendations unfortunately.

4 Replies

Hi @WHendrickson 

 

Dismissing a CCEID changes the status of an item to "dismissed" and hides it from the dashboard.

If you still see it, please make sure your filter set to not display dismissed items:

 

2021-04-08_14-27-05.jpg

@Stanislav Belov 

 

You are correct that they are hidden if dismissed however they are not removed from your secure score and regulatory compliance scores.

 

I'm looking at how to be exempt from these policies if I can't control them so they don't reflect negatively against our scores.

 

Thanks,

@WHendrickson 

 

In this case you can either disable certain rules (disabled findings won't be counted towards your secure score) or exempt the whole recommendation (not recommended):
https://docs.microsoft.com/en-us/azure/security-center/remediate-vulnerability-findings-vm?WT.mc_id=... 

@Stanislav Belov 

These 2 CIS policies cannot be disabled like findings from a vulnerability assessment. Only way to remediate them is to disable the entire policy in Azure which is not the desired outcome. Microsoft either has to exclude them from ADDS joined VMs or allow users to set the restrictions from within Azure to satisfy them I believe.