Control: 5.25 Ensure that 'Subscription leaving Microsoft Entra tenant' and 'Subscription entering Microsoft Entra tenant' is set to 'Permit no one'
Description
Users who are set as subscription owners are able to make administrative changes to the subscriptions and move them into and out of Microsoft Entra ID.
Remediation
Remediate from Azure Portal
- From the Azure Portal Home select the portal menu.
- Select
Subscriptions. - In the
Advanced optionsdrop-down menu, selectManage Policies. - Set
Subscription leaving Microsoft Entra tenantandSubscription. entering Microsoft Entra tenanttoPermit no one. - Click
Save changes.
Default Value
By default Subscription leaving Microsoft Entra tenant and Subscription entering Microsoft Entra tenant are set to Allow everyone (default).
Usage
Run the control in your terminal:
powerpipe control run azure_compliance.control.cis_v500_5_25Snapshot and share results via Turbot Pipes:
powerpipe loginpowerpipe control run azure_compliance.control.cis_v500_5_25 --shareSQL
This control uses a named query:
select id as resource, 'info' as status, 'Manual verification required.' as reason, display_name as subscriptionfrom azure_subscription;