Skip to content

Latest commit

 

History

History
22 lines (13 loc) · 736 Bytes

no-custom-owner-roles.md

File metadata and controls

22 lines (13 loc) · 736 Bytes

CloudSploit

AZURE / Active Directory / No Custom Owner Roles

Quick Info

Plugin Title No Custom Owner Roles
Cloud AZURE
Category Active Directory
Description Ensures that no custom owner roles exist.
More Info Subscription owners should not include permissions to create custom owner roles. This follows the principle of least privilege.
AZURE Link https://docs.microsoft.com/en-us/azure/role-based-access-control/custom-roles
Recommended Action Remove roles that allow permissions to create custom owner roles.

Detailed Remediation Steps