Microsoft Azure: Identity and Access Management Baseline
Identities are the gateway into your network and services so should have controls in place to secure them. Security controls that should be tightened once privilege is assigned. There should be an automated process around this so that no privilege is missed.
Restrict access to Azure AD administration portal
By default, all accounts will have read only access to Azure AD. It’s important that this is removed. Although no changes can be made with read only access, an attacker could profile your environment and…