GOV-07: Audit Privileged Role Assignments
Frequently asked questions about implementing and managing the GOV-07 security control in Microsoft 365 and Entra ID.
QWhat is GOV-07 (Audit Privileged Role Assignments)?▼
GOV-07 is a security control that privilege creep happens gradually. without a baseline of who should have admin rights, you cannot detect unauthorized role assignments. regular auditing ensures only authorized users retain privileged access. It requires that all privileged role assignments are documented and a baseline of expected role holders exists, changes from baseline are detected and reviewed.
QWhy is Audit Privileged Role Assignments important for Microsoft 365 security?▼
Privilege creep happens gradually. Without a baseline of who should have admin rights, you cannot detect unauthorized role assignments. Regular auditing ensures only authorized users retain privileged access.
QHow do I implement GOV-07 in my tenant?▼
GOV-07 requires manual implementation. Creates baseline snapshot of privileged role assignments for drift detection
QWhat license do I need for GOV-07?▼
This control can be implemented with any Microsoft 365 subscription, including free Azure AD.
QWhich security baseline includes GOV-07?▼
GOV-07 is included in the TrueConfig Recommended Secure baseline (Level 1). This is the foundation level suitable for most organizations.
5
Questions
1
Related Controls
—
Categorized
Related Resources
Still have questions?
Our security experts are here to help. Start a free trial and get personalized guidance for your Microsoft 365 environment.
Start Free Trial