last sync: 2024-Sep-19 17:51:32 UTC

Microsoft Managed Control 1021 - Account Management | Restrictions On Use Of Shared / Group Accounts | Regulatory Compliance - Access Control

Azure BuiltIn Policy definition

Source Azure Portal
Display name Microsoft Managed Control 1021 - Account Management | Restrictions On Use Of Shared / Group Accounts
Id 9a3eb0a3-428d-4669-baff-20a14eb4b551
Version 1.0.0
Details on versioning
Versioning Versions supported for Versioning: 0
Built-in Versioning [Preview]
Category Regulatory Compliance
Microsoft Learn
Description Microsoft implements this Access Control control
Additional metadata Name/Id: ACF1021 / Microsoft Managed Control 1021
Category: Access Control
Title: Account Management | Restrictions On Use Of Shared / Group Accounts
Ownership: Customer, Microsoft
Description: The organization only permits the use of shared/group accounts that meet these requirements: established for a clearly-defined administrative purpose that cannot be fulfilled using individual accounts; credentials stored in an approved secret management store.
Requirements: Group or shared accounts are not utilized within Azure unless necessary, such as where the local account or accounts cannot be deleted or disabled, or is necessary for emergency access. For accounts tracked as approved exceptions, the credentials for these accounts are stored in an approved secret management store, which tracks and monitors access to secrets and ensures group or shared account usage is uniquely attributable to the user accessing it by associated the secret store logs with the group or shared account usage. When a user accesses the credentials in the secret management store, that user is identified uniquely, ensuring non-repudiation and attributing user activity to the shared account.
Mode Indexed
Type Static
Preview False
Deprecated False
Effect Fixed
audit
RBAC role(s) none
Rule aliases none
Rule resource types IF (2)
Microsoft.Resources/subscriptions
Microsoft.Resources/subscriptions/resourceGroups
Compliance Not a Compliance control
Initiatives usage none
History none
JSON compare n/a
JSON
api-version=2021-06-01
EPAC