Feature Request - AzOps IAM security guidance for least privilege access
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 5/5
- Tiempo estimado
- Más de una semana
- Aptitud para principiantes
- 20/100
- Tipo de issue
- Documentación
- Claridad
- Necesita aclaración
- Estado de actividad
- Estancado
- Stack tecnológico
- azure, powershell
- Área
- cloud, documentation, security
Línea de trabajo
Start by reading the AzOps operating guidance and the linked Microsoft privileged-access and Enterprise-Scale references. Establish what security and least-privilege guidance is missing for AzOps and how it relates to the Enterprise Access Model. Done means a reviewed documentation update that answers the requested best-practice questions and clearly identifies any remaining limitations.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
The security concept around AzOps is questionable. It basically breaks with all of Microsoft's recommendations around least privileges. You have a single pipeline with permissions to manage more or less everything. This includes granting permissions on MG level, e.g. on Platform Identity -> bye bye Domain Controller(s).
Where access to DC was highly restricted on-prem and also should be it according to your ALZ architecture if moved to the cloud, the AzOps completely circumvents this unless the approver is from the same DC admin team and can read code to understand the request to approve. The same for other resources and services.
It seems like AzOps only serves an operational purpose without security being thought through. The suspicion is only strengthened by AzOps never mentioning security as a factor.
What is best practice and Microsoft recommendations around AzOps and security?
How can we ensure that Enterprise Access Model is still valid?
Source:
- https://github.com/Azure/Enterprise-Scale/wiki/Deploying-ALZ-Platform-DevOps#operating-the-azure-platform-using-azops-infrastructure-as-code-with-github-actions
- https://learn.microsoft.com/en-us/security/compass/privileged-access-access-model
- https://learn.microsoft.com/en-us/security/compass/privileged-access-strategy
- https://github.com/azure/azops
- Lenguaje dominante
- PowerShell
- Estrellas
- 420
- Forks
- 174
- Merge medio
- 16 d 18 h
- PR fusionados (30 d)
- 1
Guía de contribución
No hay ninguna guía de contribución indexada para este repositorio
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de Azure/AzOps
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 90/100
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 74/100
-
Dificultad 3/5 1-2 días Aptitud para principiantes 78/100
-
Dificultad 4/5 3-5 días Aptitud para principiantes 42/100
-
Failed to export child resources Abierto
Dificultad 4/5 3-5 días Aptitud para principiantes 28/100
Todos los issues de Azure/AzOps
Issues similares
-
Language: Terraform :globe_with_meridians: Needs: Triage :mag: Type: Bug :bug:
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
Azure/terraform-azurerm-avm-res-containerregistry-registry#230 · 1 comentario ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
-
bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
-
level/task module/gcp type/bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 85/100