Microsoft PKI Services: Trusted Role Control Failure
Microsoft PKI Services disclosed a process failure involving Trusted Role access controls. The issue was identified by an internal self-audit, which found that a user account had been provisioned for an employee who was not assigned to a Trusted Role but was granted access to a Secure Zone/High Security Zone. The failure did not meet section 2.c. of the Network Security Requirements requiring that only personnel assigned to Trusted Roles have access to Secure Zones and High Security Zones. Microsoft stated that certificates were not impacted by this process failure and that it identified a single problem user account that was deleted quickly after being discovered. Microsoft reported that it updated its manual provisioning process to include an independent check for Trusted Role group membership, and later centralized management of the Trusted Role group list to enable automation. Microsoft requested closure after completing the centralized management work and automation to verify Secure Zone access users against the Trusted Role list. The bug was marked RESOLVED with resolution FIXED.
- A non-Trusted Role user requested and had an account approved for access to a Secure Zone/High Security Zone outside the normal process.
- The user account was created for the non-Trusted Role user outside of process for the Secure Zone/High Security Zone.
- A Trusted Role Engineer’s random audit discovered the non-Trusted Role user account in the Secure Zone/High Security Zone and Microsoft opened an internal incident and deleted the account.
- Microsoft updated the manual provisioning process to add an independent check for Trusted Role group membership.
- Microsoft planned to implement centralized management and improved visibility/automation for the Trusted Role group list.
- Microsoft completed centralized management of the Trusted Role group list and added automation to verify Secure Zone users are in an appropriate Trusted Role.
- Disabled representative — Submitted a preliminary report describing the Trusted Role control failure, stating it was discovered via internal self-audit and that the non-Trusted Role user account was deleted after discovery.
- Microsoft Corporation — Posted an incident report with the same Trusted Role access-control failure details and referenced a separate bug for a related 3-month access review issue (1848280).
- Disabled representative — Provided an update that Trusted Role list management/process improvements were progressing but commitment dates needed adjustment due to staffing.
- Disabled representative — Reported finalized commitment dates and described planned centralization and automation for Trusted Role group list verification.
- Disabled representative — Stated that centralized management of the Trusted Role group list was completed and automation was added to verify Secure Zone users against the Trusted Role list, requesting closure.
- Mozilla representative — Indicated intent to close the bug on 11-Oct-2023.