Highly privileged accounts shall be cloud-only

Description

Assign users that need to perform highly privileged tasks to cloud-only Azure AD accounts to minimize the collateral damage of an on-premises identity compromise.

Policy

  • Users that need to be assigned to highly privileged Azure AD roles SHALL be provisioned cloud-only accounts that are separate from the on-premises directory or other federated identity providers.

Licensing Considerations

• All Microsoft Licensing Models support this configuration.

Set Up Instructions

  1. Follow these stepsarrow-up-right to review the administrative roles like Global Administrator

  2. Ensure that these accounts are cloud only

End-User Impact

circle-info

Level: None

There is no real end user impact here as you are establishing cloud only administrative accounts.

circle-info

Tips

Periodically review the privileged roles within the organization to ensure compliance with this policy.

PowerShell Scripts

Getting Sync Status: Listing Azure AD/Office 365 User Accounts with Directory Sync Status (practical365.com)arrow-up-right

View Microsoft 365 user accounts with PowerShell - Microsoft 365 Enterprise | Microsoft Learnarrow-up-right

Videos

• None Currently

Last updated