EIDGOV-001: Access-package assignment policies require approval
- Platform
- Entra ID / M365
- Category
- Entitlement Management
- Severity
- Medium
- Zero Trust pillar
- Governance (weight 2)
- Golden fixtures
- 4
- Branch coverage
- Observed: fixtures prove the verdicts they exercise
- Provenance
- baseline
What it checks
Entra ID Governance entitlement-management assignment policies control how users obtain access packages (bundles of group, application, and SharePoint access). A policy whose request-approval setting is disabled grants the bundled access with no human in the loop, turning an access package into self-service standing access. This check inspects every assignment policy and flags those that do not require approval so they can be reviewed. Empty results are treated as 'no entitlement management in use' (nothing to govern) only when collection succeeded; a failed collection is Not Assessed.
Recommended value
Every access-package assignment policy requires approval, or the auto-approved packages grant only low-risk, internally-scoped access that has been deliberately reviewed
Remediation
In Microsoft Entra admin center > Identity Governance > Entitlement management > Access packages, open each package's policies and enable 'Require approval' for policies that grant sensitive or externally-scoped access. Reserve auto-approval for low-risk, internally-scoped self-service packages, and document that decision. Pair approval with access reviews so standing grants are re-justified.
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| clean | PASS |
| not-assessed | Not Assessed |
| not-in-use | PASS |
| warn | WARN |
Framework mappings
- NIST SP 800-53
- AC-2, AC-2(1), AC-6, PM-10
- CIS M365 Benchmark
- 1.1.1