Vendor services misconfigurations

AKS cluster is not using Azure Active Directory authorization

Risk Level

Informational (4)

Platform(s)
Compliance Frameworks

Description

The ability to manage RBAC (Role-Based Access Control) for Kubernetes resources from Azure gives you the choice to manage RBAC for the cluster resources either using Azure or native Kubernetes mechanisms. When enabled, Azure AD (Active Directory) principals will be validated exclusively by Azure RBAC while regular Kubernetes users and service accounts are exclusively validated by Kubernetes RBAC. It was detected that {AzureAksCluster} cluster does not have Azure AD authorization enabled.