Skip to content

Least Privilege Baseline — Cirius Group

Established: April 15, 2026 Scope: All service identities across Azure (PROD, DDE), AWS, and ops-automation Purpose: Expected state for quarterly LPRIV audits. Deviations trigger investigation.


How to Use This Baseline

  1. Run the LPRIV checks in pim-audit.yml — the automated check compares live assignments against expected counts in this document
  2. For each identity, verify live permissions match the expected list
  3. Any permission NOT in this baseline is a finding that must be justified or removed
  4. Any permission IN this baseline that is absent is also a finding (check for removal or breakage)
  5. Update this document after any intentional permission change with date and reason

SecOps Platform

id-secops-prod (Managed Identity)

Resource: id-secops-prod in rg-logging-logsExpected role count: 2

RoleScopeLast Verified
AcrPullciriusagentsprod (resource)2026-04-15
Key Vault Secrets Usercirius-openai-kv-prod (resource)2026-04-15

id-agents-prod (Managed Identity)

Resource: id-agents-prod in rg-logging-logsExpected role count: 8

RoleScopeLast Verified
Key Vault Secrets Usercirius-openai-kv-prod (resource)2026-04-15
Log Analytics Readercirius-logging-law-central (resource)2026-04-15
AcrPullciriusagentsprod (resource)2026-04-15
Storage Table Data Contributorciriussecuritymemprod (storage account)2026-04-15
Storage Blob Data Contributorciriusarchiveprod (storage account)2026-04-15
Cognitive Services OpenAI Usercirius-openai-prod (resource)2026-04-15
ReaderLogging subscription (3946532a)2026-04-15
Security ReaderLogging subscription (3946532a)2026-04-15

Note: Reader and Security Reader at subscription scope are broader than ideal but required for Defender for Cloud and resource discovery. Tracked for potential narrowing to resource group scope (LPRIV-007).

cirius-findings-tracker (App Registration)

App ID: cc42af53-8eef-4705-a1d6-227c3313175dExpected Graph permission count: 3

PermissionTypeLast Verified
User.ReadDelegated2026-04-15
GroupMember.Read.AllApplication2026-04-15
User.Read.AllApplication2026-04-15

Cirius SecOps Bot (App Registration)

App ID: 7a3ea16d-a903-4252-9203-1159136a7eacExpected Graph permission count: 1

PermissionTypeLast Verified
User.Read.AllApplication2026-04-15

PostgreSQL — secops_app Role

Database: psql-secops-prod.postgres.database.azure.com, database secopsExpected grants:

PrivilegeObjectLast Verified
CONNECTDatabase secops2026-04-15
USAGE, CREATESchema public2026-04-15
SELECT, INSERT, UPDATE, DELETEAll tables in public2026-04-15
USAGE, SELECTAll sequences in public2026-04-15

No DROP, TRUNCATE, REFERENCES, or superuser privileges.


CI/CD Identities

github-deploy-app (Azure RBAC)

App ID: 8e01e97f-090c-45b1-9659-a99ded5d217cSP ID: 484de69a-ed8a-4202-b0b9-2616b91e1a67

Expected post-LPRIV-007 state (after PR #649 merge and manual cleanup):

RoleScopeNotes
ContributorLogging subscriptionTerraform all logging resources
Resource Policy ContributorLogging subscriptionAzure Policy in logging sub
User Access AdministratorLogging subscriptionRBAC assignments via Terraform
Key Vault Secrets Usercirius-openai-kv-prod (resource)Secret reads during plan/apply
Key Vault Secrets Officercirius-openai-kv-prod (resource)Secret rotation via Terraform
ContributorProd subscription (db824d94)Terraform all prod resources
Key Vault Crypto Officerprod-dde-key-vault (resource)CMK key lifecycle — LPRIV-007
Key Vault Secrets Officerprod-dde-key-vault (resource)Secret management — LPRIV-007
User Access AdministratorProd subscriptionRBAC assignments
ContributorFirewall subscription (0412f98f)Terraform all firewall resources
Key Vault Crypto Officercirius-fw-keyvault (resource)CMK key lifecycle — LPRIV-007
Key Vault Secrets Officercirius-fw-keyvault (resource)Secret management — LPRIV-007
Key Vault Secrets Officerpalo-alto-backup-kv (resource)PA backup secrets — LPRIV-007
User Access AdministratorFirewall subscriptionRBAC assignments
ContributorIdentity subscription (ac212528)Terraform all identity resources
Key Vault Crypto Officercirius-id-key-vault (resource)CMK key lifecycle — LPRIV-007
Key Vault Secrets Officercirius-id-key-vault (resource)Secret management — LPRIV-007
User Access AdministratorIdentity subscriptionRBAC assignments
Resource Policy ContributorTenant management group (d477c9f8)HIPAA/HITRUST policy at MG scope
Resource Policy ContributorIdentity subscriptionAzure Policy in identity sub

Note: Contributor + User Access Administrator = functional Owner in each sub. This is a known tradeoff for Terraform CI/CD. Documented in LPRIV-008.

Pre-LPRIV-007: Key Vault Administrator at subscription scope (not per-KV). Post-PR #649 merge + manual cleanup, this will be replaced by per-KV Officer roles.

github-deploy-* (AWS IAM)

RoleAccountPolicyNotes
github-deploy-mainManagement (206820231356)AdministratorAccessLPRIV-009 flagged
github-deploy-prodProd (807267566999)AdministratorAccessLPRIV-009 flagged
github-deploy-loggingLogging (038901680748)Scoped custom policies✅ Target pattern
github-deploy-firewallNetworking (238342914131)(verify)
github-deploy-identityIdentity (414134953818)(verify)
github-deploy-backupBackup (863609217450)(verify)
github-deploy-devDev (040067931468)(verify)

Ops-Automation Identities

kobe-security-audit (App Registration)

App ID: 8f9a3c24-8d9b-40b9-99e0-34a8c76759f6SP ID: a373da7a-cb84-4520-b9a1-3040be9a1db6Expected permission count: 25 (post-LPRIV-018: 27 − Mail.ReadWriteMail.Send)

Microsoft Graph (Application): 22 permissions

  • Policy.Read.ConditionalAccess, RoleEligibilitySchedule.Read.Directory, DeviceManagementManagedDevices.Read.All, BitlockerKey.ReadBasic.All, UserAuthenticationMethod.Read.All, OnPremDirectorySynchronization.Read.All, SharePointTenantSettings.Read.All, PrivilegedAccess.Read.AzureAD, SecurityIdentitiesHealth.Read.All, DirectoryRecommendations.Read.All, Directory.Read.All, ReportSettings.Read.All, RoleManagement.Read.All, User.Read.All, DeviceManagementRBAC.Read.All, SecurityIdentitiesSensors.Read.All, DeviceManagementConfiguration.Read.All, IdentityRiskEvent.Read.All, AuditLog.Read.All, Policy.Read.All, Reports.Read.All, ThreatHunting.Read.All

Exchange Online (Application): 1 permission

  • Exchange.ManageAsApp

Windows Defender ATP (Application): 2 permissions

  • Machine.Read.All, Vulnerability.Read.All

Removed permissions (do not re-add without justification):

  • Mail.ReadWrite — removed 2026-04-15; unused, email delivery uses SES
  • Mail.Send — removed 2026-04-15; unused, no Graph mail call in any workflow

cirius-kobe-bot (GitHub)

Org role: member (not owner) Expected repository permissions: pull, push, triage on all infra repos Must NOT have: admin, maintain, owner

Telegram Bot Token

No Telegram API scope isolation available. Architectural controls:

  • Bot may only call: sendMessage, editMessageText, sendReaction
  • Bot MUST NOT call: admin methods, deleteMessage, bulk operations

Quarterly Review Checklist

Each quarter, verify:

  • [ ] All identities match expected permission counts above
  • [ ] No new identities added to Key Vault or GitHub without story tracking
  • [ ] secops_app PostgreSQL grants unchanged (\du secops_app and \dp in psql)
  • [ ] kobe-security-audit Graph permissions count = 25 (or document changes)
  • [ ] Cortex XDR API key role = Viewer (verify in console)
  • [ ] New GitHub Actions workflows: verify they use OIDC, not stored secrets
  • [ ] Check for any permissions added outside LPRIV story tracking (alert if found)

Document History

DateChangeAuthor
April 2026Initial baseline — all LPRIV-001 through LPRIV-018 findings incorporatedKobe

Internal use only — Cirius Group