用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill cis-azure-foundations-2-1-4命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
macOS post-exploitation for credential harvesting, DTrace monitoring, TCC bypass, and stealth operations via native tools
Windows userland post-exploitation for credential harvesting, monitoring, AMSI/ETW bypass, and stealth operations
Kubernetes post-exploitation for container escape, secret extraction, RBAC abuse, and cluster persistence
基于 SOC 职业分类
正在显示 SKILL.md
| name | cis-azure-foundations-2.1.4 |
| description | Ensure users and groups are synced from Microsoft Entra ID to Azure Databricks |
| category | cis-azure-foundations |
| version | 5.0.0 |
| author | cyberstrike-official |
| tags | ["cis","azure","databricks","analytics"] |
| cis_id | 2.1.4 |
| cis_benchmark | CIS Microsoft Azure Foundations Benchmark v5.0.0 |
| tech_stack | ["azure"] |
| cwe_ids | [] |
| chains_with | ["cis-azure-foundations-2.1.5","cis-azure-foundations-2.1.6"] |
| prerequisites | [] |
| severity_boost | {} |
To ensure centralized identity and access management, users and groups from Microsoft Entra ID should be synchronized with Azure Databricks. This is achieved through SCIM provisioning, which automates the creation, update, and deactivation of users and groups in Databricks based on Entra ID assignments. Enabling this integration ensures that access controls in Databricks remain consistent with corporate identity governance policies, reducing the risk of orphaned accounts, stale permissions, and unauthorized access.
Syncing users and groups from Microsoft Entra ID centralizes access control, enforces the least privilege principle by automatically revoking unnecessary access, reduces administrative overhead by eliminating manual user management, and ensures auditability and compliance with industry regulations.
SCIM provisioning requires role mapping to avoid misconfigured user privileges.
Verify SCIM provisioning is enabled:
Microsoft Entra ID.Manage, click Enterprise applications.Provisioning, confirm that SCIM provisioning is enabled and running.Check user sync status in Azure Portal:
Provisioning Logs, verify the last successful sync and any failed entries.Check user sync status in Databricks:
Admin Console > Identity and Access Management.Ensure role-based access control (RBAC) mapping is correct:
SCIM provisioning should be enabled and running. Users and groups in Azure Databricks should match those in Microsoft Entra ID. All role assignments should follow the least privilege principle.
Enable provisioning in Azure Portal:
Microsoft Entra ID.Manage, click Enterprise applications.Provisioning, select Automatic and enter the SCIM endpoint and API token from Databricks.Enable provisioning in Databricks:
Admin Console > Identity and Access Management.Configure role assignments:
Regularly monitor sync logs:
Disable manual user creation in Databricks:
Enable SCIM User and Group Provisioning in Azure Databricks:
az ad app update --id <databricks-app-id> --set provisioning.provisioningMode=Automatic
By default, Azure Databricks does not sync users and groups from Microsoft Entra ID.
| Controls Version | Control | IG 1 | IG 2 | IG 3 |
|---|---|---|---|---|
| v8 | 5.6 Centralize Account Management | x | x | |
| v7 | 16.2 Configure Centralized Point of Authentication | x | x |
Level 1 | Manual