EIDGOV-001: Access-package assignment policies require approval
- Plataforma
- Entra ID / M365
- Categoría
- Entitlement Management
- Severidad
- Medium
- Pilar de Zero Trust
- Governance (peso 2)
- Fixtures de referencia
- 4
- Cobertura de ramas
- Observada: los fixtures prueban los veredictos que ejercitan
- Procedencia
- baseline
Qué comprueba
Entra ID Governance entitlement-management assignment policies control how users obtain access packages (bundles of group, application, and SharePoint access). A policy whose request-approval setting is disabled grants the bundled access with no human in the loop, turning an access package into self-service standing access. This check inspects every assignment policy and flags those that do not require approval so they can be reviewed. Empty results are treated as 'no entitlement management in use' (nothing to govern) only when collection succeeded; a failed collection is Not Assessed.
Valor recomendado
Every access-package assignment policy requires approval, or the auto-approved packages grant only low-risk, internally-scoped access that has been deliberately reviewed
Remediación
In Microsoft Entra admin center > Identity Governance > Entitlement management > Access packages, open each package's policies and enable 'Require approval' for policies that grant sensitive or externally-scoped access. Reserve auto-approval for low-risk, internally-scoped self-service packages, and document that decision. Pair approval with access reviews so standing grants are re-justified.
Veredictos probados con fixtures
Cada veredicto de esta tabla está probado por un fixture de referencia en la suite de pruebas que valida el módulo. La tabla se deriva de la última ejecución en verde; no puede editarse a mano.
| Escenario | Veredicto esperado |
|---|---|
| clean | PASS |
| not-assessed | Not Assessed |
| not-in-use | PASS |
| warn | WARN |
Mapeos a marcos de referencia
- NIST SP 800-53
- AC-2, AC-2(1), AC-6, PM-10
- CIS M365 Benchmark
- 1.1.1