
Multi-Factor Authentication (MFA) should be enabled for all subscription accounts with write privileges to prevent a breach of accounts or resources.Įnsure that multi-factor authentication is enabled for all non-privileged users Multi-Factor Authentication (MFA) should be enabled for all subscription accounts with owner permissions to prevent a breach of accounts or resources.Īccounts with write permissions on Azure resources should be MFA enabled ID: CIS Microsoft Azure Foundations Benchmark recommendation 1.1Īccounts with owner permissions on Azure resources should be MFA enabled 1 Identity and Access Management Ensure that multi-factor authentication is enabled for all privileged users The associations between compliance domains, controls, and Azure Policyĭefinitions for this compliance standard may change over time. Therefore, compliance in Azure Policy is only a partial view of your


InĪddition, the compliance standard includes controls that aren't addressed by any Azure Policyĭefinitions at this time. Themselves this doesn't ensure you're fully compliant with all requirements of a control. As such, Compliant in Azure Policy refers only to the policy definitions These policies may help you assess compliance with theĬontrol however, there often is not a one-to-one or complete match between a control and one or

Each control below is associated with one or more Azure Policy definitions.
