EIDGOV-001: Access-package assignment policies require approval

Platform
Entra ID / M365
Category
Entitlement Management
Severity
Medium
Zero Trust pillar
Governance (weight 2)
Golden fixtures
4
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

Entra ID Governance entitlement-management assignment policies control how users obtain access packages (bundles of group, application, and SharePoint access). A policy whose request-approval setting is disabled grants the bundled access with no human in the loop, turning an access package into self-service standing access. This check inspects every assignment policy and flags those that do not require approval so they can be reviewed. Empty results are treated as 'no entitlement management in use' (nothing to govern) only when collection succeeded; a failed collection is Not Assessed.

Recommended value

Every access-package assignment policy requires approval, or the auto-approved packages grant only low-risk, internally-scoped access that has been deliberately reviewed

Remediation

In Microsoft Entra admin center > Identity Governance > Entitlement management > Access packages, open each package's policies and enable 'Require approval' for policies that grant sensitive or externally-scoped access. Reserve auto-approval for low-risk, internally-scoped self-service packages, and document that decision. Pair approval with access reviews so standing grants are re-justified.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for EIDGOV-001
ScenarioExpected verdict
cleanPASS
not-assessedNot Assessed
not-in-usePASS
warnWARN

Framework mappings

NIST SP 800-53
AC-2, AC-2(1), AC-6, PM-10
CIS M365 Benchmark
1.1.1