Description:
Verifies that admins are actively using assigned privileged role assignments.
Why:
Users that have been assigned privileged roles they don't need increases the chance of an attack. It's also easier for attackers to remain unnoticed in accounts that aren't actively being used.
Note: The check attempts to exclude emergency (Break Glass) accounts.
Configured: Admins are actively using assigned privileged role assignments.
Not Configured: Some admins have privileged role assignments which are not in use.
Scoring: Contributes up to 1 point to the Posture Recommendations score.
Category: Identity
Microsoft Licensing: Requires Premium (P2) licensing
Secure Score Impact: Not verified. No Microsoft Secure Score control could be confirmed for this setting from published sources. See the note in README.md before publishing this field.
Remediation in Augmentt: No in-product remediation — remediate in the Microsoft admin portals.
Compliance Frameworks:
Essential Eight (Maturity Level 2) — 1648
Essential Eight (Maturity Level 3) — 1648
Microsoft documentation:
_KB status: new — this check is not yet documented in the knowledge base._
_Source: Sourced from the open-source Maester project and extended by Augmentt with multi-tenant support, compliance mapping and in-product remediation. Check ID MT.1030 (module 1002)._
Sourced for this page:
Category — Maester test catalog (maester.dev/docs/tests) — test is graded against the "Privileged" tier, so it evaluates a Microsoft Entra ID setting
Secure Score — No Microsoft Secure Score control name is published for this setting and Augmentt does not read one.
Draft metadata — apply these as Stonly tags in the console, then delete this block. The Stonly API cannot set tags, so they are recorded here instead.
Tags: posture-check · compliance-audit · Microsoft Entra ID · Entra ID P2 · Essential Eight ML2 · Essential Eight ML3
