Third parties and vendors

Is service provider access to network/data restricted on least-privilege basis, reviewed periodically?

Vendor access is granted during a project and reviewed approximately never. It is one of the most measurable exposures in any tenant.

Verifiable from your tenant

What the carrier is actually asking

The carrier is asking whether third parties have only the access they need, and whether that access is reviewed periodically rather than granted permanently. It covers guest accounts, federated access, support accounts, and application permissions.

Why it is underwritten

Standing vendor access is a persistent path into your environment that you do not monitor and cannot patch. Attackers who compromise a service provider use exactly this access, and it is usually broader and older than anyone realises.

Where the answer lives in Microsoft 365, Entra ID, and Azure

This is one of the more directly measurable third-party questions, because external access in Entra ID is enumerable.

PlatformWhere the setting livesWhat has to be true
Entra IDGuest accounts, their sponsors, and last sign-inGuests tied to current engagements, with dormant ones removed rather than accumulating
Entra IDAccess reviews configured for guest accessRecurring reviews that complete, so removal happens without anyone remembering to ask
Entra IDExternal collaboration settings and invitation restrictionsWho can invite guests, and to which domains, since unrestricted invitation is how vendor access proliferates
Entra IDEnterprise applications with delegated or application permissionsThird-party applications and the scope of what they can read, reviewed and reduced
Entra IDDelegated administrative relationships from partnersPartner access to your tenant, time-bound and granular rather than standing and full
Application permissions outlive the vendor

A vendor engagement ends, the guest accounts are removed, and the enterprise application they registered keeps its consented permissions indefinitely. Application permissions do not expire and are not tied to any user, which makes them the most persistent form of vendor access in a tenant.

What a defensible yes requires

  • Vendor access is scoped to what the engagement requires and expires with it.
  • Guest access is subject to recurring review or automatic expiry.
  • Invitation rights are restricted rather than available to every user.
  • Application permissions are inventoried, reviewed, and revoked when engagements end.
  • Delegated administrative relationships are granular and time-bound.

How this answer goes wrong

Guest accounts from a project that finished three years ago still hold access to the sites they were invited to, and nobody owns the removal. The organisation answers yes because access was scoped correctly at the time it was granted. The question asks about the current state.

Frequently asked

How often should vendor access be reviewed?

Quarterly for anything privileged, annually as a floor. Automated access reviews make the cadence sustainable, which is why they beat a calendar reminder.

Should vendors have accounts in our directory?

Guest accounts with scoped access are usually better than shared credentials, because activity is attributable and removal is one action.

What about vendor support accounts?

Disable them between support cases where the vendor allows it. Standing support access is access whether or not anyone is using it today.

Is this verifiable?

Yes, more than most third-party questions. Guest inventory, sign-in activity, and application permissions are all enumerable, which makes this answer evidence-backed rather than asserted.

Related questions

Stop answering this from memory

Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.

Assess your posture