EIDGOV-004: External access-package eligibility is controlled
- Platform
- Entra ID / M365
- Category
- Entitlement Management
- Severity
- High
- Zero Trust pillar
- Identity (weight 3)
- Golden fixtures
- 4
- Branch coverage
- Observed: fixtures prove the verdicts they exercise
- Provenance
- baseline
What it checks
Entitlement management can extend access packages to users outside the tenant (guests and users from connected organizations). A policy that both allows external targets and does not require approval lets outside users self-provision internal access — a direct external-exposure path. This check FAILs when a policy allows external eligibility without approval, WARNs when external eligibility is approval-gated, and passes when policies are internally scoped.
Recommended value
No assignment policy allows external or all-users eligibility without approval; external eligibility is scoped to specific connected organizations and approval-gated
Remediation
For policies whose allowed-target scope includes external or all users, either narrow the scope to specific connected organizations, or require approval (and preferably access reviews) on the policy. Never leave a broadly-scoped external eligibility policy auto-approved.
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| external-approved | WARN |
| external-open | FAIL |
| internal | PASS |
| not-assessed | Not Assessed |
Framework mappings
- NIST SP 800-53
- AC-2, AC-3, AC-6, SA-9
- CIS M365 Benchmark
- 1.1.1