people Preventive Protect

A.6.5 Responsibilities After Termination or Change of Employment

M365 Admin Path: Microsoft Entra admin center > Identity governance > Lifecycle Workflows; Access reviews; Intune admin center > Devices

Evidence Source: Microsoft Graph (Identity Lifecycle Workflows, Access Reviews, Intune)

What is this control?

ISO 27001 control A.6.5 Responsibilities After Termination or Change of Employment ensures that information security responsibilities and duties are properly enforced when personnel leave or change employment. The organisation implements a formal Joiners, Movers, and Leavers process using Microsoft Entra Identity Lifecycle Workflows to automatically revoke access, update role-based group membership to prevent access creep, and wipe remote devices upon termination.

How to implement in Microsoft 365

Implement A.6.5 by configuring Microsoft Entra Identity Lifecycle Workflows with an active Leaver workflow that automatically retires or wipes all Intune-enrolled devices, removes all PIM role eligibilities, revokes all active sign-in sessions, and disables the user’s Entra account. Implement dynamic groups based on departmental and role attributes to automatically update group membership when HR updates user attributes during role changes. Configure automatic access review triggers when a user’s department or job title changes requiring the new manager to attest pre-existing access permissions.

Set up recurring Microsoft Entra Access Review policies for B2B and guest accounts with 90-day review cycles.

What an auditor looks for

Auditors will verify an active Leaver workflow in Identity Lifecycle Workflows with recent execution history. They will check recently disabled user accounts showing automated enforcement via audit logs. Auditors will review dynamic group configurations based on job attributes with automatic membership updates.

They will verify access review definitions targeting role changes with manager attestation evidence. Auditors will check recurring access review policies for guest and B2B accounts with attestation history. They will review Intune device management showing retire and wipe capability with recent actions.

M365 capabilities that implement this control

Leaver Entitlement Packages Info Gov

Identity Governance lifecycle workflows for leavers

Lifecycle Workflows Info Gov

Entra ID Governance lifecycle workflows for pre-hire, joiner, mover, and leaver identity lifecycle automation