First published on CloudBlogs on Jul, 29 2015
Howdy folks, More cool news to share. We've just turned on the preview of our new Security Reviews in Azure AD Premium! Many large organizations are required to do security reviews (what we identity geeks commonly call "attestation campaigns") to prove that only the correct employees have access to specific important resources in order to meet government and industry compliance requirements. We've received a LOT of requests from customers to add support for this kind of campaign for the privileged roles in Azure AD, Intune and Office 365. Mark Wahl, who many of you probably already know due to his deep identity expertise and industry experience is the Principal Program Manager in our team responsible for this new set of features. He's done a great blog post below walking you through how it all works. This is our first foray into Cloud Based Enterprise Role Management and we'd love to receive any feedback or suggestions you have! Best regards, Alex Simons (Twitter: @Alex_A_Simons ) Director of Program Management Microsoft Identity and Security Services Division --------------------------------------------------- Hi everyone, It's me, Mark! We've recently enhanced our Azure Active Directory Privileged Identity Management preview by adding a new feature: Security Reviews. Security Reviews make it easier for you to determine whether your administrators still need to be in a privileged role for managing Azure AD/Office365/Intune, by asking them to confirm they still need that role. We've heard from many of our enterprise customers that as their use of cloud services increases, often they find they're adding more and more users to highly privileged roles in Microsoft Online Services, such as the Global Administrator role. Over time, users may still be in that role even though those privileges are no longer necessary for their current job. This poses security concerns and makes their accounts high-value targets for attacks. Security reviews help the organization stay protected, by ensuring that users periodically confirm they still need to be in those roles. Subsequent updates to Azure Active Directory will expand the scope of security reviews to other features, such as group memberships. Security reviews have 3 steps:
Howdy folks, More cool news to share. We've just turned on the preview of our new Security Reviews in Azure AD Premium! Many large organizations are required to do security reviews (what we identity geeks commonly call "attestation campaigns") to prove that only the correct employees have access to specific important resources in order to meet government and industry compliance requirements. We've received a LOT of requests from customers to add support for this kind of campaign for the privileged roles in Azure AD, Intune and Office 365. Mark Wahl, who many of you probably already know due to his deep identity expertise and industry experience is the Principal Program Manager in our team responsible for this new set of features. He's done a great blog post below walking you through how it all works. This is our first foray into Cloud Based Enterprise Role Management and we'd love to receive any feedback or suggestions you have! Best regards, Alex Simons (Twitter: @Alex_A_Simons ) Director of Program Management Microsoft Identity and Security Services Division --------------------------------------------------- Hi everyone, It's me, Mark! We've recently enhanced our Azure Active Directory Privileged Identity Management preview by adding a new feature: Security Reviews. Security Reviews make it easier for you to determine whether your administrators still need to be in a privileged role for managing Azure AD/Office365/Intune, by asking them to confirm they still need that role. We've heard from many of our enterprise customers that as their use of cloud services increases, often they find they're adding more and more users to highly privileged roles in Microsoft Online Services, such as the Global Administrator role. Over time, users may still be in that role even though those privileges are no longer necessary for their current job. This poses security concerns and makes their accounts high-value targets for attacks. Security reviews help the organization stay protected, by ensuring that users periodically confirm they still need to be in those roles. Subsequent updates to Azure Active Directory will expand the scope of security reviews to other features, such as group memberships. Security reviews have 3 steps:
- Select the resource and access rights to review: the security administrator picks a privileged role, such as Global Administrator, where they believe administrators might still be holding that role who no longer need it.
- Review of the access rights: Azure AD sends each user in that role a notification, and they respond in the Azure portal whether or not they need still need that role.
- Complete the review: the security administrator reviews the results to decide who to remove from the role.
-
Click the Marketplace tile on your Startboard
-
Click Security and Identity
-
Click the 'Azure AD Privileged Identity Management' item
-
Complete the wizard
-
Pin the resulting service instance to your Startboard
-
Click on the tile to get started with Azure AD Privileged Identity Management
Published Sep 07, 2018
Version 1.0Alex Simons (AZURE)
Microsoft
Joined May 01, 2017
Microsoft Entra Blog
Stay informed on how to secure access for workforce, customer, and workload identities, from anywhere, to multicloud and on-premises resources, with comprehensive identity and network access solutions.