IAM-02.1: Access to the CSP's console/portal is done through consolidated single sign-on. This can be via an external SSO provider or one built into the cloud platform.
  • Control automation: Automated
  • AWS control specification: At least one identity provider (IdP) is enabled in all accounts
  • Azure control specification: This is the default for Azure, which requires the use of Entra ID (formerly Azure AD)
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none

Description

  • Control automation: Automated
  • AWS control specification: At least one identity provider (IdP) is enabled in all accounts
  • Azure control specification: This is the default for Azure, which requires the use of Entra ID (formerly Azure AD)
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none