
Summary
The rule 'Stale Accounts In A Privileged Role' is designed to detect accounts with privileged roles that have not been signed into for a specified period. The absence of sign-ins signals potential orphaned accounts which can pose risks if left unattended, as they might be targets for misuse. By identifying such stale accounts, organizations can take appropriate actions to review, disable, or remove them, thus reducing the attack surface associated with privileged role accounts. This detection leverages Azure's Privileged Identity Management (PIM) capabilities and triggers when an event of the type 'staleSignInAlertIncident' is detected. The intent is to maintain a healthier and more secure privilege management by ensuring that only actively used accounts remain in privileged roles, minimizing the potential for privilege escalation or account misuse due to stale accounts.
Categories
- Cloud
- Azure
- Identity Management
Data Sources
- User Account
- Cloud Service
Created: 2023-09-14