Skip to content

Commit 688468b

Browse files
Merge pull request #267561 from AlizaBernstein/WI-215990-release-deprecate-two-recom-over-provisioned-identities
WI-215990-release-deprecate-two-recom-over-provisioned-identities
2 parents bc34d16 + b416a5e commit 688468b

File tree

3 files changed

+27
-8
lines changed

3 files changed

+27
-8
lines changed

articles/defender-for-cloud/enable-permissions-management.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -132,7 +132,7 @@ The integration feature comes as part of Defender CSPM plan and doesn't require
132132
| Category | Capabilities | Defender for Cloud | Permissions Management |
133133
| --------- | ------------------------------------------------------------ | ------------------ | ---------------------- |
134134
| Discover | Permissions discovery for risky identities (including unused identities, overprovisioned active identities, super identities) in Azure, AWS, GCP |||
135-
| Discover | Permissions Creep Index (PCI) for multicloud environments (Azure, AWS, GCP) and all identities | ||
135+
| Discover | Permissions Creep Index (PCI) for multicloud environments (Azure, AWS, GCP) and all identities | ||
136136
| Discover | Permissions discovery for all identities, groups in Azure, AWS, GCP |||
137137
| Discover | Permissions usage analytics, role / policy assignments in Azure, AWS, GCP |||
138138
| Discover | Support for Identity Providers (including AWS IAM Identity Center, Okta, GSuite) |||

articles/defender-for-cloud/recommendations-reference.md

Lines changed: 13 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -1441,13 +1441,6 @@ Learn more in [Introduction to Microsoft Defender for Storage](/azure/defender-f
14411441

14421442
**Severity**: Low
14431443

1444-
### [Over-provisioned identities in subscriptions should be investigated to reduce the Permission Creep Index (PCI)](https://portal.azure.com/#blade/Microsoft_Azure_Security/RecommendationsBlade/assessmentKey/d103537b-9f3d-4658-a568-31dd66eb05cb)
1445-
1446-
**Description**: Over-provisioned identities in subscription should be investigated to reduce the Permission Creep Index (PCI) and to safeguard your infrastructure. Reduce the PCI by removing the unused high risk permission assignments. High PCI reflects risk associated with the identities with permissions that exceed their normal or required usage
1447-
(No related policy).
1448-
1449-
**Severity**: Medium
1450-
14511444
### [Private endpoint connections on Azure SQL Database should be enabled](https://portal.azure.com/#blade/Microsoft_Azure_Security/RecommendationsBlade/assessmentKey/75396512-3323-9be4-059d-32ecb113c3de)
14521445

14531446
**Description**: Private endpoint connections enforce secure communication by enabling private connectivity to Azure SQL Database.
@@ -2153,6 +2146,19 @@ Note that the following subnet types will be listed as not applicable: GatewaySu
21532146

21542147
## Deprecated recommendations
21552148

2149+
### Over-provisioned identities in subscriptions should be investigated to reduce the Permission Creep Index (PCI)
2150+
2151+
**Description**: Over-provisioned identities in subscription should be investigated to reduce the Permission Creep Index (PCI) and to safeguard your infrastructure. Reduce the PCI by removing the unused high risk permission assignments. High PCI reflects risk associated with the identities with permissions that exceed their normal or required usage
2152+
(No related policy).
2153+
2154+
**Severity**: Medium
2155+
2156+
### Over-provisioned identities in accounts should be investigated to reduce the Permission Creep Index (PCI)
2157+
2158+
**Description**: Over-provisioned identities in accounts should be investigated to reduce the Permission Creep Index (PCI) and to safeguard your infrastructure. Reduce the PCI by removing the unused high risk permission assignments. High PCI reflects risk associated with the identities with permissions that exceed their normal or required usage.
2159+
2160+
**Severity**: Medium
2161+
21562162
### Access to App Services should be restricted
21572163

21582164
**Description & related policy**: Restrict access to your App Services by changing the networking configuration, to deny inbound traffic from ranges that are too broad.

articles/defender-for-cloud/release-notes.md

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -24,8 +24,21 @@ If you're looking for items older than six months, you can find them in the [Arc
2424

2525
|Date | Update |
2626
|----------|----------|
27+
| March 5 | [Deprecation of two recommendations related to PCI](#deprecation-of-two-recommendations-related-to-pci) |
2728
| March 3 | [Defender for Cloud Containers Vulnerability Assessment powered by Qualys retirement](#defender-for-cloud-containers-vulnerability-assessment-powered-by-qualys-retirement) |
2829

30+
### Deprecation of two recommendations related to PCI
31+
32+
March 5, 2024
33+
34+
The following two recommendations related to Permission Creep Index (PCI) are being deprecated:
35+
36+
- Over-provisioned identities in accounts should be investigated to reduce the Permission Creep Index (PCI)
37+
- Over-provisioned identities in subscriptions should be investigated to reduce the Permission Creep Index (PCI)
38+
39+
See the [list of deprecated security recommendations](recommendations-reference.md#deprecated-recommendations).
40+
41+
2942
### Defender for Cloud Containers Vulnerability Assessment powered by Qualys retirement
3043

3144
March 3, 2024

0 commit comments

Comments
 (0)