Source | Azure Portal | ||||||
Display name | Microsoft Managed Control 1306 - User Identification And Authentication | Network Access To Privileged Accounts - Replay... | ||||||
Id | cafc6c3c-5fc5-4c5e-a99b-a0ccb1d34eff | ||||||
Version | 1.0.1 Details on versioning |
||||||
Versioning |
Versions supported for Versioning: 0 Built-in Versioning [Preview] |
||||||
Category | Regulatory Compliance Microsoft Learn |
||||||
Description | Microsoft implements this Identification and Authentication control | ||||||
Additional metadata |
Name/Id: ACF1306 / Microsoft Managed Control 1306 Category: Identification and Authentication Title: User Identification And Authentication | Network Access To Privileged Accounts - Replay Resistant Ownership: Customer, Microsoft Description: The information system implements replay-resistant authentication mechanisms for network access to privileged accounts. Requirements: Azure implements multifactor authentication for network access by Azure personnel with eAuth Level 4 and FIPS 140-2 compliant Thales smart cards. All Microsoft users connect to Azure assets via Jumpboxes, Debug servers, and Network Hop Boxes. This requires the user to present a certificate bound to the card along with a PIN. Access to the Azure production environment using the smart card solution is protected from replay attacks by the built-in Kerberos v5 functionality of Active Directory (AD). In Kerberos authentication, the authenticator sent by the client contains additional data, such as an encrypted IP list, the client's timestamp, and the ticket lifetime. If a packet is replayed, the timestamp is checked. If the timestamp is earlier than or the same as a previous authenticator, the packet is rejected because it is a replay. For more information on Active Directory and Kerberos, see TechNet article 742516: |
||||||
Mode | Indexed | ||||||
Type | Static | ||||||
Preview | False | ||||||
Deprecated | False | ||||||
Effect | Fixed audit |
||||||
RBAC role(s) | none | ||||||
Rule aliases | none | ||||||
Rule resource types | IF (2) Microsoft.Resources/subscriptions Microsoft.Resources/subscriptions/resourceGroups |
||||||
Compliance | Not a Compliance control | ||||||
Initiatives usage | none | ||||||
History |
|
||||||
JSON compare |
compare mode:
version left:
version right:
|
||||||
JSON |
|