turbot/azure_insights

Query: activedirectory_deprecated_user_with_owner_role_count

Usage

powerpipe query azure_insights.query.activedirectory_deprecated_user_with_owner_role_count

SQL

select
count(distinct
u.display_name) as value,
'Deprecated Users With Owner Role' as label,
case when count(*) = 0 then 'ok' else 'alert' end as type
from
azuread_user as u
left join azure_role_assignment as a on a.principal_id = u.id
left join azure_role_definition as d on d.id = a.role_definition_id
where d.role_name = 'Owner' and not u.account_enabled;

Dashboards

The query is used in the dashboards: