ID / outcome
Measurement
Evidence
Acceptance threshold
Purpose
A-01Privileged roles are fully inventoried
Enumerate active and eligible privileged role assignments across the agreed Entra scope.
Timestamped role inventory, principal identifiers and role classification.
100% of in-scope privileged role assignments represented in the evidence package.
Make delivery objectively testable and suitable for assessment, remediation and recurring assurance.
A-02Standing human privilege is classified
Classify every permanent active human privileged assignment as approved, exception-based or requiring remediation.
Standing-role report linked to owner, rationale and exception status.
100% of standing human privileged assignments have a documented disposition.
Make delivery objectively testable and suitable for assessment, remediation and recurring assurance.
A-03PIM / JIT coverage is measured
Compare eligible/JIT-capable role assignments with permanent active assignments for in-scope privileged roles.
PIM eligibility report, activation configuration and coverage metric.
Coverage metric produced for all in-scope privileged roles; target value agreed per policy.
Make delivery objectively testable and suitable for assessment, remediation and recurring assurance.
A-04Emergency access is validated
Verify designated break-glass identities, role state, authentication path, monitoring and latest test status.
Emergency-access register, configuration evidence and validation record.
Every designated emergency account has an owner, documented purpose and current validation record.
Make delivery objectively testable and suitable for assessment, remediation and recurring assurance.
A-05Privileged authentication strength is tested
Evaluate authentication methods and policy coverage for privileged human identities.
Authentication-method inventory, Conditional Access coverage and test results.
100% of in-scope privileged users evaluated against the agreed authentication-strength policy.
Make delivery objectively testable and suitable for assessment, remediation and recurring assurance.
A-06Conditional Access exclusions are governed
Identify privileged identities excluded from relevant Conditional Access controls and validate each exclusion.
Policy map, exclusion list, owner and approved exception reference.
100% of privileged exclusions are either approved and time-bounded or raised for remediation.
Make delivery objectively testable and suitable for assessment, remediation and recurring assurance.
A-07Privileged workload identities are visible
Identify service principals, managed identities or applications with material privileged access in scope.
Workload identity inventory, owners, credentials and permission summary.
100% of identified privileged workload identities have a named owner or are raised as findings.
Make delivery objectively testable and suitable for assessment, remediation and recurring assurance.
A-08Exceptions are controlled
Review security exceptions for owner, rationale, compensating control, approval and expiry.
Exception register and approval trail.
No in-scope exception remains without owner, rationale, approval state and review/expiry date.
Make delivery objectively testable and suitable for assessment, remediation and recurring assurance.
A-09Drift is detected and owned
Repeat agreed control checks and compare current state with the approved baseline.
Drift report, failed checks and assigned remediation backlog.
All detected material drift is assigned a status, owner and next action within the agreed review cycle.
Make delivery objectively testable and suitable for assessment, remediation and recurring assurance.
A-10Evidence is generated and traceable
Generate an evidence bundle linking control result, source data, timestamp and integrity record.
Control-to-evidence matrix, raw exports, summary results and SHA-256 manifest where applicable.
Every reported control result is linked to retrievable evidence and an identifiable collection time.
Make delivery objectively testable and suitable for assessment, remediation and recurring assurance.