last sync: 2025-Apr-29 17:16:02 UTC

Microsoft Managed Control 1057 - Permitted Actions Without Identification Or Authentication | Regulatory Compliance - Access Control

Azure BuiltIn Policy definition

Source Azure Portal
Display name Microsoft Managed Control 1057 - Permitted Actions Without Identification Or Authentication
Id 78255758-6d45-4bf0-a005-7016bc03b13c
Version 1.0.0
Details on versioning
Versioning Versions supported for Versioning: 0
Built-in Versioning [Preview]
Category Regulatory Compliance
Microsoft Learn
Description Microsoft implements this Access Control control
Cloud environments AzureCloud = true
AzureUSGovernment = true
AzureChinaCloud = unknown
Available in AzUSGov The Policy is available in AzureUSGovernment cloud. Version: '1.0.0'
Repository: Azure-Policy 78255758-6d45-4bf0-a005-7016bc03b13c
Additional metadata Name/Id: ACF1057 / Microsoft Managed Control 1057
Category: Access Control
Title: Permitted Actions Without Identification or Authentication - Identification of Actions
Ownership: Customer, Microsoft
Description: The organization: Identifies user actions is not applicable for employees and contractors, only the login page and limited public information is accessible for external users without authentication that can be performed on the information system without identification or authentication consistent with organizational missions/business functions; and
Requirements: The only actions permitted by Azure to be performed without identification and authentication are accessing the public Feature Descriptions, Developer Documents, Legal, Privacy Statement, Help, and Language Preference options on the customer facing welcome page. On the welcome page the user enters his or her email address, at which point Active Directory Federation Services (ADFS) refers the user back to the customer-controlled federated authentication portal. Service teams also make aspects of their services consumable as needed. For instance, Azure Active Directory (AAD) DNS responds to unauthenticated DNS queries by design, as this is required to be compliant with the DNS specification and to ensure customers can successfully resolve AAD URLs.
Mode Indexed
Type Static
Preview False
Deprecated False
Effect Fixed
audit
RBAC role(s) none
Rule aliases none
Rule resource types IF (2)
Compliance
The following 1 compliance controls are associated with this Policy definition 'Microsoft Managed Control 1057 - Permitted Actions Without Identification Or Authentication' (78255758-6d45-4bf0-a005-7016bc03b13c)
Control Domain Control Name MetadataId Category Title Owner Requirements Description Info Policy#
NIS2 IM._Identity_Management_10 NIS2_IM._Identity_Management_10 NIS2_IM._Identity_Management_10 IM. Identity Management The use of multi-factor authentication Customer, Microsoft Cryptographic Module Authentication The use of multi-factor authentication or continuous authentication solutions, secured voice, video and text communications and secured emergency communication systems within the entity, where appropriate. 29
Initiatives usage
Initiative DisplayName Initiative Id Initiative Category State Type polSet in AzUSGov
[Preview]: NIS2 32ff9e30-4725-4ca7-ba3a-904a7721ee87 Regulatory Compliance Preview BuiltIn unknown
History none
JSON compare n/a
JSON
api-version=2021-06-01
EPAC