Policy: Azure > CIS v5.0 > 3 - Compute Services > 3.01 - Virtual Machines > 3.01.01 - Ensure only MFA enabled identities can access privileged Virtual Machine
Configures auditing against a CIS Benchmark item.
Level: 1
Organizational policy should require that Multi-Factor Authentication (MFA) is enabled for all users who have privileged access to Azure Virtual Machines.
This includes users with: - VM Contributor role - Custom roles with VM management permissions - Direct RDP/SSH access to production VMs - Just-in-time VM access
This is a manual control requiring attestation as the specific definition of "privileged access" varies by organization.
Targets
This policy targets the following resource types:
Primary Policy
This policy is used with the following primary policy:
Related Policies
Controls
Setting this policy configures this control:
Policy Specification
Schema Type | |
|---|---|
Default | |
Valid Values [YAML] |
|
Category
In Your Workspace
Developers
- tmod:@turbot/cis#/control/categories/v070405
- tmod:@turbot/azure-cisv5-0#/policy/types/r030101
- turbot graphql policy-type --id "tmod:@turbot/azure-cisv5-0#/policy/types/r030101"
- turbot graphql policy-settings --filter "policyTypeId:tmod:@turbot/azure-cisv5-0#/policy/types/r030101"
Get Policy TypeGet Policy Settings
Category URI
Policy Type URI
GraphQL
CLI