Controls / MCSB / PA-2

MCSB PA-2: Privileged Access

10 Senserva Microsoft 365 security checks provide evidence for Microsoft Cloud Security Benchmark control PA-2 (Privileged Access). Each is checked against your tenant, ranked by Severity, with validated remediation.

10 checksPrivileged AccessTop Severity: Critical

What MCSB PA-2 covers

The Microsoft Cloud Security Benchmark is Microsoft's own security baseline for Azure and Microsoft 365, organized into control domains. PA-2 sits in the Privileged Access domain. Senserva evidences it with the 10 checks below, so you can see, per tenant, whether the control is actually met rather than assumed.

Ask your own AI about this control

Copy this prompt into Claude, ChatGPT, or Copilot. The facts are included, sourced from this page.

The 10 checks that evidence MCSB PA-2

Click any row for why it matters and how to fix it, with a link to the full check page.

Senserva checkSeverityWhat it verifies
PIM Policy Expiration RequiredCriticalPIM policy does not require expiration for role assignments. Permanent assignments violate just-in-time access principles
Role Standing High Privilege AssignmentCriticalStanding (permanent, non-PIM) assignment on a high-privilege role
Pa Avoid Standing AccessHighAvoid standing access: privileged roles should use just-in-time activation via PIM
Pa Follow Least Privilege PrincipleHighFollow least privilege principle: users and apps should have minimum permissions needed
PIM Policy Enablement Rule Not SetHighPIM enablement rule is not set for a role. The role lacks activation workflow configuration
PIM Policy Justification RequiredHighPIM policy requires a justification for role activation
PIM Policy Maximum DurationHighPIM policy maximum activation duration for a role
PIM Policy Ticketing RequiredHighPIM policy requires a support ticket number for role activation
PIM Policy PIM Approval RequiredInfoPIM policy requires approval for role activation. Second-person authorization for privileged access
PIM Policy PIM MFA RequiredInfoPIM policy requires MFA for role activation. Confirms step-up auth is enforced

Also evidences

The same checks provide evidence for these frameworks, so one fix counts across your obligations:

Every MCSB control and the checks that evidence it: the control reference. The full benchmark crosswalk: MCSB for Microsoft 365.

Reference: the compliance frameworks crosswalk, the check reference, and the audit guide.
Data notice: control mappings describe which Siemserva checks provide evidence for a control and are informational only, without warranty. They do not constitute compliance advice or certification; confirm requirements with your assessor. All use is subject to the Senserva EULA.