EIDGOV-004: External access-package eligibility is controlled

Platform
Entra ID / M365
Category
Entitlement Management
Severity
High
Zero Trust pillar
Identity (weight 3)
Golden fixtures
4
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

Entitlement management can extend access packages to users outside the tenant (guests and users from connected organizations). A policy that both allows external targets and does not require approval lets outside users self-provision internal access — a direct external-exposure path. This check FAILs when a policy allows external eligibility without approval, WARNs when external eligibility is approval-gated, and passes when policies are internally scoped.

Recommended value

No assignment policy allows external or all-users eligibility without approval; external eligibility is scoped to specific connected organizations and approval-gated

Remediation

For policies whose allowed-target scope includes external or all users, either narrow the scope to specific connected organizations, or require approval (and preferably access reviews) on the policy. Never leave a broadly-scoped external eligibility policy auto-approved.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for EIDGOV-004
ScenarioExpected verdict
external-approvedWARN
external-openFAIL
internalPASS
not-assessedNot Assessed

Framework mappings

NIST SP 800-53
AC-2, AC-3, AC-6, SA-9
CIS M365 Benchmark
1.1.1