organisational Preventive Protect

A.5.18 Access Rights

M365 Admin Path: Microsoft Entra admin centre > Identity Governance > Entitlement management

Evidence Source: Microsoft Entra ID

What is this control?

ISO 27001 control A.5.18 Access Rights ensures that access to information and organisational assets is defined, provisioned, reviewed, and revoked according to business requirements using the principle of least privilege. The control implements a formal, auditable lifecycle for all access rights including provisioning, review, modification, and revocation using Microsoft Entra ID Access Packages, PIM, and Access Reviews.

How to implement in Microsoft 365

Implement A.5.18 with baseline access where users are automatically provisioned to security groups matching their job role during onboarding via the Joiner workflow using RBAC. For additional access, submit requests via Microsoft Entra Access Packages requiring business owner approval. Configure Microsoft Entra PIM to make users eligible rather than actively provisioned for privileged roles with JIT activation and approval workflows.

Configure Access Reviews quarterly for privileged roles, quarterly for contractor groups, and bi-annually for standard groups using Microsoft Entra Identity Governance. Implement Mover workflow to review all group memberships on role change.

What an auditor looks for

Auditors will verify Access Packages are configured with approval policies routing requests to business owners. They will check that Microsoft Entra Access Reviews are configured and executed with documented approval or denial decisions. Auditors will review documented Power Automate JML workflows for Joiner, Mover, and Leaver processes with approval steps and audit trails.

They will verify PIM configuration showing eligible rather than active privileged access model. Auditors will examine access review results demonstrating periodic re-certification of access rights.

M365 capabilities that implement this control

Entra ID CIS Hardening (Identity) Foundation

CIS M365 v6.0.1 Entra ID hardening: guest access, consent, group creation, app registration, PIM approval, device join

Privileged Identity Management Endpoint

Entra ID PIM for just-in-time privileged access, cloud-only accounts, access reviews

Access Reviews - Basic Info Gov

Quarterly access reviews for privileged roles and groups

Access Reviews - Full Info Gov

Comprehensive access reviews including application access