AC.L2-3.1.7Privileged Functions
Prevent non-privileged users from executing privileged functions and capture the execution of such functions in audit logs.
[a]
privileged functions are defined;[b]
non-privileged users are defined;[c]
non-privileged users are prevented from executing privileged functions; and[d]
the execution of privileged functions is captured in audit logs.
Block privileged functions for standard users; log every elevation
Implementation
AO coverage. Addresses all Privileged Functions objectives (prevent + capture).
Prevent. Standard users cannot activate Global Admin, User Admin, or enclave storage admin roles. Those roles are PIM-eligible. Endpoint local admin is denied by policy; UAC alone is not the control.
Capture. PIM activations (who, why/ticket, MFA method, duration) stream to the SIEM. Falcon records process creations under elevated tokens on PAWs. Alerts fire on elevation outside change windows.
Maintenance. Weekly review of PIM activations without ticket IDs. Quarterly tabletop of a suspected privilege abuse using SIEM queries.
Accepted gap. One vendor appliance has a shared root equivalent with no federation. Console access is PAW-only; commands are session-recorded; password dual-custody.
What the evidence looks like
- PIM role settings showing eligible-not-active for privileged roles
- SIEM query results for a sample week of activations
- Falcon / endpoint policy denying local admin to standard users
- Appliance session-recording sample
Environment
Tools
Was this example useful?
Quick reaction — no account needed. For reasoning that moves the community meter, cast a full verdict below.
Discussion(0)
No discussion on this example yet
Verdicts capture a conclusion. Use a thread when the interesting part is the argument.
Sign in to start a thread.