EIDGOV-002: Access-package assignment policies enforce access reviews
- Platform
- Entra ID / M365
- Category
- Entitlement Management
- Severity
- Medium
- Zero Trust pillar
- Governance (weight 2)
- Golden fixtures
- 3
- Branch coverage
- Observed: fixtures prove the verdicts they exercise
- Provenance
- baseline
What it checks
An access-package assignment policy without access reviews grants access that is never periodically re-justified, accumulating standing privilege over time. Entra ID Governance can attach recurring access reviews to each policy so assignees (or their managers) must reconfirm need. This check flags assignment policies whose access-review setting is not enabled.
Recommended value
Every access-package assignment policy has recurring access reviews enabled
Remediation
For each access-package assignment policy, enable access reviews under the policy's lifecycle settings: choose a recurrence (for example quarterly), reviewers (self, manager, or a named reviewer), and an auto-remove action for denied or unreviewed assignments so unused access is revoked automatically.
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| clean | PASS |
| not-assessed | Not Assessed |
| warn | WARN |
Framework mappings
- NIST SP 800-53
- AC-2(3), AC-6(7), PM-10
- CIS M365 Benchmark
- 1.1.1