Is service provider access to network/data restricted on least-privilege basis, reviewed periodically?
Vendor access is granted during a project and reviewed approximately never. It is one of the most measurable exposures in any tenant.
What the carrier is actually asking
The carrier is asking whether third parties have only the access they need, and whether that access is reviewed periodically rather than granted permanently. It covers guest accounts, federated access, support accounts, and application permissions.
Why it is underwritten
Standing vendor access is a persistent path into your environment that you do not monitor and cannot patch. Attackers who compromise a service provider use exactly this access, and it is usually broader and older than anyone realises.
Where the answer lives in Microsoft 365, Entra ID, and Azure
This is one of the more directly measurable third-party questions, because external access in Entra ID is enumerable.
| Platform | Where the setting lives | What has to be true |
|---|---|---|
| Entra ID | Guest accounts, their sponsors, and last sign-in | Guests tied to current engagements, with dormant ones removed rather than accumulating |
| Entra ID | Access reviews configured for guest access | Recurring reviews that complete, so removal happens without anyone remembering to ask |
| Entra ID | External collaboration settings and invitation restrictions | Who can invite guests, and to which domains, since unrestricted invitation is how vendor access proliferates |
| Entra ID | Enterprise applications with delegated or application permissions | Third-party applications and the scope of what they can read, reviewed and reduced |
| Entra ID | Delegated administrative relationships from partners | Partner access to your tenant, time-bound and granular rather than standing and full |
A vendor engagement ends, the guest accounts are removed, and the enterprise application they registered keeps its consented permissions indefinitely. Application permissions do not expire and are not tied to any user, which makes them the most persistent form of vendor access in a tenant.
What a defensible yes requires
- Vendor access is scoped to what the engagement requires and expires with it.
- Guest access is subject to recurring review or automatic expiry.
- Invitation rights are restricted rather than available to every user.
- Application permissions are inventoried, reviewed, and revoked when engagements end.
- Delegated administrative relationships are granular and time-bound.
How this answer goes wrong
Guest accounts from a project that finished three years ago still hold access to the sites they were invited to, and nobody owns the removal. The organisation answers yes because access was scoped correctly at the time it was granted. The question asks about the current state.
Frequently asked
How often should vendor access be reviewed?
Quarterly for anything privileged, annually as a floor. Automated access reviews make the cadence sustainable, which is why they beat a calendar reminder.
Should vendors have accounts in our directory?
Guest accounts with scoped access are usually better than shared credentials, because activity is attributable and removal is one action.
What about vendor support accounts?
Disable them between support cases where the vendor allows it. Standing support access is access whether or not anyone is using it today.
Is this verifiable?
Yes, more than most third-party questions. Guest inventory, sign-in activity, and application permissions are all enumerable, which makes this answer evidence-backed rather than asserted.
Related questions
Stop answering this from memory
Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.
Assess your posture