Policy: Azure > CIS v5.0 > 5 - Identity Services > 5.03 - Periodic Identity Reviews > 5.03.03 - Ensure that use of the 'User Access Administrator' role is restricted
Configures auditing against a CIS Benchmark item.
Level: 1
The User Access Administrator role allows users to manage user access to Azure resources. This role should be restricted to only those users who require it, as it grants significant permissions including the ability to assign roles to users, groups, and service principals.
Targets
This policy targets the following resource types:
Primary Policy
This policy is used with the following primary policy:
Controls
Setting this policy configures this control:
Policy Specification
Schema Type | |
|---|---|
Default | |
Valid Values [YAML] |
|
Category
In Your Workspace
Developers
- tmod:@turbot/cis#/control/categories/cis
- tmod:@turbot/azure-cisv5-0#/policy/types/r050303
- turbot graphql policy-type --id "tmod:@turbot/azure-cisv5-0#/policy/types/r050303"
- turbot graphql policy-settings --filter "policyTypeId:tmod:@turbot/azure-cisv5-0#/policy/types/r050303"
Get Policy TypeGet Policy Settings
Category URI
Policy Type URI
GraphQL
CLI