Appearance
Least Privilege Baseline — Cirius Group
Established: April 15, 2026 Scope: All service identities across Azure (PROD, DDE), AWS, and ops-automation Purpose: Expected state for quarterly LPRIV audits. Deviations trigger investigation.
How to Use This Baseline
- Run the LPRIV checks in
pim-audit.yml— the automated check compares live assignments against expected counts in this document - For each identity, verify live permissions match the expected list
- Any permission NOT in this baseline is a finding that must be justified or removed
- Any permission IN this baseline that is absent is also a finding (check for removal or breakage)
- Update this document after any intentional permission change with date and reason
SecOps Platform
id-secops-prod (Managed Identity)
Resource: id-secops-prod in rg-logging-logsExpected role count: 2
| Role | Scope | Last Verified |
|---|---|---|
AcrPull | ciriusagentsprod (resource) | 2026-04-15 |
Key Vault Secrets User | cirius-openai-kv-prod (resource) | 2026-04-15 |
id-agents-prod (Managed Identity)
Resource: id-agents-prod in rg-logging-logsExpected role count: 8
| Role | Scope | Last Verified |
|---|---|---|
Key Vault Secrets User | cirius-openai-kv-prod (resource) | 2026-04-15 |
Log Analytics Reader | cirius-logging-law-central (resource) | 2026-04-15 |
AcrPull | ciriusagentsprod (resource) | 2026-04-15 |
Storage Table Data Contributor | ciriussecuritymemprod (storage account) | 2026-04-15 |
Storage Blob Data Contributor | ciriusarchiveprod (storage account) | 2026-04-15 |
Cognitive Services OpenAI User | cirius-openai-prod (resource) | 2026-04-15 |
Reader | Logging subscription (3946532a) | 2026-04-15 |
Security Reader | Logging subscription (3946532a) | 2026-04-15 |
Note: Reader and Security Reader at subscription scope are broader than ideal but required for Defender for Cloud and resource discovery. Tracked for potential narrowing to resource group scope (LPRIV-007).
cirius-findings-tracker (App Registration)
App ID: cc42af53-8eef-4705-a1d6-227c3313175dExpected Graph permission count: 3
| Permission | Type | Last Verified |
|---|---|---|
User.Read | Delegated | 2026-04-15 |
GroupMember.Read.All | Application | 2026-04-15 |
User.Read.All | Application | 2026-04-15 |
Cirius SecOps Bot (App Registration)
App ID: 7a3ea16d-a903-4252-9203-1159136a7eacExpected Graph permission count: 1
| Permission | Type | Last Verified |
|---|---|---|
User.Read.All | Application | 2026-04-15 |
PostgreSQL — secops_app Role
Database: psql-secops-prod.postgres.database.azure.com, database secopsExpected grants:
| Privilege | Object | Last Verified |
|---|---|---|
CONNECT | Database secops | 2026-04-15 |
USAGE, CREATE | Schema public | 2026-04-15 |
SELECT, INSERT, UPDATE, DELETE | All tables in public | 2026-04-15 |
USAGE, SELECT | All sequences in public | 2026-04-15 |
No DROP, TRUNCATE, REFERENCES, or superuser privileges.
CI/CD Identities
github-deploy-app (Azure RBAC)
App ID: 8e01e97f-090c-45b1-9659-a99ded5d217cSP ID: 484de69a-ed8a-4202-b0b9-2616b91e1a67
Expected post-LPRIV-007 state (after PR #649 merge and manual cleanup):
| Role | Scope | Notes |
|---|---|---|
Contributor | Logging subscription | Terraform all logging resources |
Resource Policy Contributor | Logging subscription | Azure Policy in logging sub |
User Access Administrator | Logging subscription | RBAC assignments via Terraform |
Key Vault Secrets User | cirius-openai-kv-prod (resource) | Secret reads during plan/apply |
Key Vault Secrets Officer | cirius-openai-kv-prod (resource) | Secret rotation via Terraform |
Contributor | Prod subscription (db824d94) | Terraform all prod resources |
Key Vault Crypto Officer | prod-dde-key-vault (resource) | CMK key lifecycle — LPRIV-007 |
Key Vault Secrets Officer | prod-dde-key-vault (resource) | Secret management — LPRIV-007 |
User Access Administrator | Prod subscription | RBAC assignments |
Contributor | Firewall subscription (0412f98f) | Terraform all firewall resources |
Key Vault Crypto Officer | cirius-fw-keyvault (resource) | CMK key lifecycle — LPRIV-007 |
Key Vault Secrets Officer | cirius-fw-keyvault (resource) | Secret management — LPRIV-007 |
Key Vault Secrets Officer | palo-alto-backup-kv (resource) | PA backup secrets — LPRIV-007 |
User Access Administrator | Firewall subscription | RBAC assignments |
Contributor | Identity subscription (ac212528) | Terraform all identity resources |
Key Vault Crypto Officer | cirius-id-key-vault (resource) | CMK key lifecycle — LPRIV-007 |
Key Vault Secrets Officer | cirius-id-key-vault (resource) | Secret management — LPRIV-007 |
User Access Administrator | Identity subscription | RBAC assignments |
Resource Policy Contributor | Tenant management group (d477c9f8) | HIPAA/HITRUST policy at MG scope |
Resource Policy Contributor | Identity subscription | Azure Policy in identity sub |
Note: Contributor + User Access Administrator = functional Owner in each sub. This is a known tradeoff for Terraform CI/CD. Documented in LPRIV-008.
Pre-LPRIV-007: Key Vault Administrator at subscription scope (not per-KV). Post-PR #649 merge + manual cleanup, this will be replaced by per-KV Officer roles.
github-deploy-* (AWS IAM)
| Role | Account | Policy | Notes |
|---|---|---|---|
github-deploy-main | Management (206820231356) | AdministratorAccess | LPRIV-009 flagged |
github-deploy-prod | Prod (807267566999) | AdministratorAccess | LPRIV-009 flagged |
github-deploy-logging | Logging (038901680748) | Scoped custom policies | ✅ Target pattern |
github-deploy-firewall | Networking (238342914131) | (verify) | |
github-deploy-identity | Identity (414134953818) | (verify) | |
github-deploy-backup | Backup (863609217450) | (verify) | |
github-deploy-dev | Dev (040067931468) | (verify) |
Ops-Automation Identities
kobe-security-audit (App Registration)
App ID: 8f9a3c24-8d9b-40b9-99e0-34a8c76759f6SP ID: a373da7a-cb84-4520-b9a1-3040be9a1db6Expected permission count: 25 (post-LPRIV-018: 27 − Mail.ReadWrite − Mail.Send)
Microsoft Graph (Application): 22 permissions
Policy.Read.ConditionalAccess,RoleEligibilitySchedule.Read.Directory,DeviceManagementManagedDevices.Read.All,BitlockerKey.ReadBasic.All,UserAuthenticationMethod.Read.All,OnPremDirectorySynchronization.Read.All,SharePointTenantSettings.Read.All,PrivilegedAccess.Read.AzureAD,SecurityIdentitiesHealth.Read.All,DirectoryRecommendations.Read.All,Directory.Read.All,ReportSettings.Read.All,RoleManagement.Read.All,User.Read.All,DeviceManagementRBAC.Read.All,SecurityIdentitiesSensors.Read.All,DeviceManagementConfiguration.Read.All,IdentityRiskEvent.Read.All,AuditLog.Read.All,Policy.Read.All,Reports.Read.All,ThreatHunting.Read.All
Exchange Online (Application): 1 permission
Exchange.ManageAsApp
Windows Defender ATP (Application): 2 permissions
Machine.Read.All,Vulnerability.Read.All
Removed permissions (do not re-add without justification):
Mail.ReadWrite— removed 2026-04-15; unused, email delivery uses SESMail.Send— removed 2026-04-15; unused, no Graph mail call in any workflow
cirius-kobe-bot (GitHub)
Org role: member (not owner) Expected repository permissions: pull, push, triage on all infra repos Must NOT have: admin, maintain, owner
Telegram Bot Token
No Telegram API scope isolation available. Architectural controls:
- Bot may only call:
sendMessage,editMessageText,sendReaction - Bot MUST NOT call: admin methods,
deleteMessage, bulk operations
Quarterly Review Checklist
Each quarter, verify:
- [ ] All identities match expected permission counts above
- [ ] No new identities added to Key Vault or GitHub without story tracking
- [ ]
secops_appPostgreSQL grants unchanged (\du secops_appand\dpin psql) - [ ] kobe-security-audit Graph permissions count = 25 (or document changes)
- [ ] Cortex XDR API key role = Viewer (verify in console)
- [ ] New GitHub Actions workflows: verify they use OIDC, not stored secrets
- [ ] Check for any permissions added outside LPRIV story tracking (alert if found)
Document History
| Date | Change | Author |
|---|---|---|
| April 2026 | Initial baseline — all LPRIV-001 through LPRIV-018 findings incorporated | Kobe |