EIDCA-004: CA Exclusion Group Analysis

Platform
Entra ID / M365
Category
Entra ID Conditional Access
Severity
High
Zero Trust pillar
Identity (weight 3)
Golden fixtures
3
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

Users and groups excluded from Conditional Access policies bypass critical security controls. Exclusions should be minimized, documented with business justification, and regularly reviewed to prevent privilege creep and unauthorized access.

Recommended value

All exclusions documented with business justification and reviewed quarterly

Remediation

Audit all Conditional Access policies to identify excluded users and groups. Document the business justification for each exclusion and establish an owner responsible for periodic review. Remove any exclusions that no longer have a valid business need and implement compensating controls where exclusions are required.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for EIDCA-004
ScenarioExpected verdict
cleanPASS
known-badFAIL
throttledNot Assessed

Framework mappings

NIST SP 800-53
AC-6(1)
MITRE ATT&CK
T1078.004