Description:
Verifies that tenant has no unmanaged active role assignments.
Why:
Provisioning users to privileged roles within a PAM system enables enforcement of numerous privileged access policies and monitoring. If privileged users are assigned directly to roles in the M365 admin center or via PowerShell outside of the context of a PAM system, a significant set of critical security capabilities are bypassed.
Configured: Tenant has no unmanaged active role assignments.
Not Configured: Tenant has unmanaged active role assignments.
Scoring: Contributes up to 1 point to the Posture Recommendations score.
Category: Identity
Microsoft Licensing: Requires Premium (P2) licensing
Secure Score Impact: Not verified. No Microsoft Secure Score control could be confirmed for this setting from published sources. See the note in README.md before publishing this field.
Remediation in Augmentt: No in-product remediation — remediate in the Microsoft admin portals.
Compliance Frameworks:
CISA SCuBA — MS.AAD.7.5
CIS Microsoft 365 Benchmark v6 (Level 2) — 5.3.1
CIS Microsoft 365 Benchmark v7 (Level 2) — 5.3.1
CMMC Level 2 — AC.L2-3.1.5, AC.L2-3.1.2
Microsoft documentation:
_KB status: new — this check is not yet documented in the knowledge base._
_Source: Sourced from the open-source Maester project and extended by Augmentt with multi-tenant support, compliance mapping and in-product remediation. Check ID CISA.MS.AAD.7.5 (module 1067)._
Sourced for this page:
Category — Maester test catalog (maester.dev/docs/tests) — test is graded against the "Entra ID P2" tier, so it evaluates a Microsoft Entra ID setting
Secure Score — No Microsoft Secure Score control name is published for this setting and Augmentt does not read one.
Draft metadata — apply these as Stonly tags in the console, then delete this block. The Stonly API cannot set tags, so they are recorded here instead.
Tags: posture-check · compliance-audit · Microsoft Entra ID · Entra ID P2 · CISA SCuBA · CIS M365 v6 L2 · CIS M365 v7 L2 · CMMC Level 2
