EIDGOV-005: Access-package catalog external visibility reviewed
- Platform
- Entra ID / M365
- Category
- Entitlement Management
- Severity
- Low
- Zero Trust pillar
- Governance (weight 1)
- Golden fixtures
- 4
- Branch coverage
- Observed: fixtures prove the verdicts they exercise
- Provenance
- baseline
What it checks
An entitlement-management catalog marked externally visible can surface its access packages to users outside the tenant in the My Access portal. Externally-visible catalogs are appropriate for deliberate B2B collaboration but are worth confirming, since they widen who can discover and request access. This check flags externally-visible catalogs for review.
Recommended value
Externally-visible catalogs are intentional and limited to those needed for B2B collaboration
Remediation
In Identity Governance > Entitlement management > Catalogs, review each catalog with external visibility enabled. Disable external visibility on catalogs that only serve internal access packages, keeping external discoverability limited to catalogs deliberately built for partner or guest collaboration.
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| clean | PASS |
| not-assessed | Not Assessed |
| not-in-use | PASS |
| warn | WARN |
Framework mappings
- NIST SP 800-53
- AC-3, AC-22, SA-9
- CIS M365 Benchmark
- 1.1.1