Description:

Verifies that users have least privilege access.

Why:

Many privileged administrative users do not need unfettered access to the tenant to perform their duties. By assigning them to roles based on least privilege, the risks associated with having their accounts compromised are reduced.

Configured: Users have least privilege access.

Not Configured: User with Global Admin privilege does not adhere to least privilege.

Scoring: Contributes up to 1 point to the Posture Recommendations score.

Category: Identity

Microsoft Licensing: Works with Basic licensing

Secure Score Impact: Not verified. No Microsoft Secure Score control could be confirmed for this setting from published sources. See the note in README.md before publishing this field.

Remediation in Augmentt: No in-product remediation — remediate in the Microsoft admin portals.

Compliance Frameworks:

  • CISA SCuBA — MS.AAD.7.2

  • CMMC Level 2 — AC.L2-3.1.5, AC.L2-3.1.7

Microsoft documentation:


_KB status: new — this check is not yet documented in the knowledge base._

_Source: Sourced from the open-source Maester project and extended by Augmentt with multi-tenant support, compliance mapping and in-product remediation. Check ID CISA.MS.AAD.7.2 (module 1073)._

Sourced for this page:

  • Category — Maester test catalog (maester.dev/docs/tests) — test is graded against the "Entra ID Free" tier, so it evaluates a Microsoft Entra ID setting

  • Secure Score — No Microsoft Secure Score control name is published for this setting and Augmentt does not read one.


Draft metadata — apply these as Stonly tags in the console, then delete this block. The Stonly API cannot set tags, so they are recorded here instead.
Tags: posture-check · compliance-audit · Microsoft Entra ID · M365 Basic · CISA SCuBA · CMMC Level 2