<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Administrative access to Azure Cloud Infrastructure - how to prove in Cloud Security</title>
    <link>https://community.isc2.org/t5/Cloud-Security/Administrative-access-to-Azure-Cloud-Infrastructure-how-to-prove/m-p/64998#M368</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Our auditors are asking IT to show who has access to Azure Infrastructure. IT says that's a very broad ask. What they need to see is: everyone who has the ability administer IT logical access related items on&amp;nbsp; Azure Cloud Infrastructure. What specific screens, settings should we be specifically asking for to review this kind of ability?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 29 Nov 2023 17:18:21 GMT</pubDate>
    <dc:creator>Midude2000</dc:creator>
    <dc:date>2023-11-29T17:18:21Z</dc:date>
    <item>
      <title>Administrative access to Azure Cloud Infrastructure - how to prove</title>
      <link>https://community.isc2.org/t5/Cloud-Security/Administrative-access-to-Azure-Cloud-Infrastructure-how-to-prove/m-p/64998#M368</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Our auditors are asking IT to show who has access to Azure Infrastructure. IT says that's a very broad ask. What they need to see is: everyone who has the ability administer IT logical access related items on&amp;nbsp; Azure Cloud Infrastructure. What specific screens, settings should we be specifically asking for to review this kind of ability?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Nov 2023 17:18:21 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Cloud-Security/Administrative-access-to-Azure-Cloud-Infrastructure-how-to-prove/m-p/64998#M368</guid>
      <dc:creator>Midude2000</dc:creator>
      <dc:date>2023-11-29T17:18:21Z</dc:date>
    </item>
    <item>
      <title>Re: Administrative access to Azure Cloud Infrastructure - how to prove</title>
      <link>https://community.isc2.org/t5/Cloud-Security/Administrative-access-to-Azure-Cloud-Infrastructure-how-to-prove/m-p/64999#M369</link>
      <description>&lt;P&gt;So that is a very broad ask.&amp;nbsp; I believe they are working from an audit "cheat" sheet on audits.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I personally would push back a little and ask them to clarify their ask.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If we look at some of the roles in Azure:&amp;nbsp; say&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Contributor........the user is allowed to&amp;nbsp;&lt;SPAN&gt;manage all resources, but does not allow you to assign roles&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;User access administrator ....&lt;SPAN&gt;allows one to manage user access to Azure resources.&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Disk backup reader ....permission to backup&lt;/P&gt;&lt;P&gt;etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think I would go back and ask the following questions?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1.&amp;nbsp; Do you want to know who can create accounts. etc?&lt;/P&gt;&lt;P&gt;2. Do you want to see that users only have access to the resource that are essential to them (think RBAC here)&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. Are you looking to see how inbound and outbound traffic is controlled?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;MHOO&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;d&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Nov 2023 17:40:07 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Cloud-Security/Administrative-access-to-Azure-Cloud-Infrastructure-how-to-prove/m-p/64999#M369</guid>
      <dc:creator>dcontesti</dc:creator>
      <dc:date>2023-11-29T17:40:07Z</dc:date>
    </item>
    <item>
      <title>Re: Administrative access to Azure Cloud Infrastructure - how to prove</title>
      <link>https://community.isc2.org/t5/Cloud-Security/Administrative-access-to-Azure-Cloud-Infrastructure-how-to-prove/m-p/65003#M370</link>
      <description>&lt;P&gt;To Diana-Lynn's point, the auditors need to be clear in their ask, lest they find the answer overwhelming with irrelevant detail.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would supply them the list of &lt;A href="https://learn.microsoft.com/en-us/azure/role-based-access-control/built-in-roles" target="_blank"&gt;azure built-in roles&lt;/A&gt; and ask them to identify those which they would like you to retrieve membership.&amp;nbsp; Or, perhaps, they could provide a powershell script that extracts the data they desire.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You might also take a look at Azure PIM.&amp;nbsp; It has &lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/azure-pim-resource-rbac" target="_blank"&gt;reporting&lt;/A&gt; they may find useful, but do be aware that it is pricy ($6+ per M365 user per month).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And if you want to mess with the auditors (fun, but risky), feel free to point out that I have "Azure Cloud Infrastructure" access and if they want it, they can to.&amp;nbsp; All one needs to do is &lt;A href="https://azure.microsoft.com/en-us/free/#all-free-services" target="_blank"&gt;sign-up&lt;/A&gt;&amp;nbsp;and give them a credit card number.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Nov 2023 18:10:16 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Cloud-Security/Administrative-access-to-Azure-Cloud-Infrastructure-how-to-prove/m-p/65003#M370</guid>
      <dc:creator>denbesten</dc:creator>
      <dc:date>2023-11-29T18:10:16Z</dc:date>
    </item>
    <item>
      <title>Re: Administrative access to Azure Cloud Infrastructure - how to prove</title>
      <link>https://community.isc2.org/t5/Cloud-Security/Administrative-access-to-Azure-Cloud-Infrastructure-how-to-prove/m-p/65019#M371</link>
      <description>Internal audit or external audit..? Same questions but the stakes are different.&lt;BR /&gt;&lt;BR /&gt;I guess as well as seeing what you have actually set it’s good to be ready to show them your access management process for requests and approvals and how that is governed.</description>
      <pubDate>Thu, 30 Nov 2023 13:54:28 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Cloud-Security/Administrative-access-to-Azure-Cloud-Infrastructure-how-to-prove/m-p/65019#M371</guid>
      <dc:creator>Early_Adopter</dc:creator>
      <dc:date>2023-11-30T13:54:28Z</dc:date>
    </item>
    <item>
      <title>Re: Administrative access to Azure Cloud Infrastructure - how to prove</title>
      <link>https://community.isc2.org/t5/Cloud-Security/Administrative-access-to-Azure-Cloud-Infrastructure-how-to-prove/m-p/65061#M372</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/985787817"&gt;@Midude2000&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;&lt;SPAN&gt;What they need to see is: everyone who has the ability administer IT logical access related items on&amp;nbsp; Azure Cloud Infrastructure. What specific screens, settings should we be specifically asking for to review this kind of ability?&lt;/SPAN&gt;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;First, ask for clarification but I interpret this as requesting a comprehensive inventory of all individuals/entities with privileged access to Azure (Entra) resources. This includes users, groups, and systems with the ability to manage identities, access permissions, and privileged accounts. The reasoning is to see if anyone/system has unauthorized access to environment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Microsoft Entra --&amp;gt; Identity --&amp;gt; Roles &amp;amp; Admins --&amp;gt; All Roles. You can download all administrative roles into a .CSV file for viewing.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Dec 2023 15:03:53 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Cloud-Security/Administrative-access-to-Azure-Cloud-Infrastructure-how-to-prove/m-p/65061#M372</guid>
      <dc:creator>tmekelburg1</dc:creator>
      <dc:date>2023-12-01T15:03:53Z</dc:date>
    </item>
    <item>
      <title>Re: Administrative access to Azure Cloud Infrastructure - how to prove</title>
      <link>https://community.isc2.org/t5/Cloud-Security/Administrative-access-to-Azure-Cloud-Infrastructure-how-to-prove/m-p/65132#M373</link>
      <description>&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 00:31:35 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Cloud-Security/Administrative-access-to-Azure-Cloud-Infrastructure-how-to-prove/m-p/65132#M373</guid>
      <dc:creator>Midude2000</dc:creator>
      <dc:date>2023-12-05T00:31:35Z</dc:date>
    </item>
    <item>
      <title>Re: Administrative access to Azure Cloud Infrastructure - how to prove</title>
      <link>https://community.isc2.org/t5/Cloud-Security/Administrative-access-to-Azure-Cloud-Infrastructure-how-to-prove/m-p/65133#M374</link>
      <description>haha! points well taken! especially the last piece of advice. Mess with them just a little bit..</description>
      <pubDate>Tue, 05 Dec 2023 00:33:10 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Cloud-Security/Administrative-access-to-Azure-Cloud-Infrastructure-how-to-prove/m-p/65133#M374</guid>
      <dc:creator>Midude2000</dc:creator>
      <dc:date>2023-12-05T00:33:10Z</dc:date>
    </item>
    <item>
      <title>Re: Administrative access to Azure Cloud Infrastructure - how to prove</title>
      <link>https://community.isc2.org/t5/Cloud-Security/Administrative-access-to-Azure-Cloud-Infrastructure-how-to-prove/m-p/65134#M375</link>
      <description>external audit - SOX auditors</description>
      <pubDate>Tue, 05 Dec 2023 00:33:36 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Cloud-Security/Administrative-access-to-Azure-Cloud-Infrastructure-how-to-prove/m-p/65134#M375</guid>
      <dc:creator>Midude2000</dc:creator>
      <dc:date>2023-12-05T00:33:36Z</dc:date>
    </item>
    <item>
      <title>Re: Administrative access to Azure Cloud Infrastructure - how to prove</title>
      <link>https://community.isc2.org/t5/Cloud-Security/Administrative-access-to-Azure-Cloud-Infrastructure-how-to-prove/m-p/65135#M376</link>
      <description>&lt;P&gt;very helpful thank you!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 00:35:26 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Cloud-Security/Administrative-access-to-Azure-Cloud-Infrastructure-how-to-prove/m-p/65135#M376</guid>
      <dc:creator>Midude2000</dc:creator>
      <dc:date>2023-12-05T00:35:26Z</dc:date>
    </item>
    <item>
      <title>Re: Administrative access to Azure Cloud Infrastructure - how to prove</title>
      <link>https://community.isc2.org/t5/Cloud-Security/Administrative-access-to-Azure-Cloud-Infrastructure-how-to-prove/m-p/65162#M377</link>
      <description>&lt;P&gt;It's a very broad ask. If someone is familiar with azure and knows what to ask, they should ask for list of specific roles, such as Global Administrator, User Administrator....etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Like the Microsoft article suggested, there are many built-in roles. Some are related to Microsoft Entra, some are related to Azure&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can access the default Azure roles from Subscription&amp;gt;Access Control(IAM) to see the list of roles and assignment&lt;/P&gt;&lt;P&gt;You can access the default Microsoft Entra roles on the Roles and administrators page and export the list.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/role-based-access-control/rbac-and-directory-admin-roles" target="_blank"&gt;https://learn.microsoft.com/en-us/azure/role-based-access-control/rbac-and-directory-admin-roles&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 21:22:40 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Cloud-Security/Administrative-access-to-Azure-Cloud-Infrastructure-how-to-prove/m-p/65162#M377</guid>
      <dc:creator>sergeling</dc:creator>
      <dc:date>2023-12-05T21:22:40Z</dc:date>
    </item>
  </channel>
</rss>

