Create Employee Security Terms in Entra ID: Exact Menu Path

Create Employee Security Terms in Entra ID: Exact Menu Path

Learn how to create employee security terms in entra id, require acceptance with Conditional Access, and collect ISO 27001 audit evidence.

LakeRidge Team
July 17, 2026
8 min read

Share:

Schedule Your Free Compliance Consultation

Feeling overwhelmed by compliance requirements? Not sure where to start? Get expert guidance tailored to your specific needs in just 15 minutes.

Personalized Compliance Roadmap
Expert Answers to Your Questions
No Obligation, 100% Free

CMMC Phase 2 begins November 10, 2026.

To create employee security terms in entra id for ISO 27001 control 6.2, upload an approved information-security employment terms document as a Microsoft Entra Terms of Use policy and require acceptance through Conditional Access before employees access organizational resources. This provides a controlled acknowledgement record, but the underlying employment contract or HR policy must still contain the organization’s and personnel’s information-security responsibilities.

What does ISO 27001 control 6.2 require, and can Entra ID satisfy it?

ISO/IEC 27001:2022 Annex A control 6.2, Terms and conditions of employment, requires employment contractual agreements to state both the personnel’s information-security responsibilities and the organization’s responsibilities for information security. For an audit, you need to show that these terms exist, are approved, are issued to the relevant workforce population, and can be demonstrated as accepted or otherwise acknowledged.

Microsoft Entra ID can support this requirement by presenting a PDF document to users at sign-in, recording their acceptance, and preventing access to selected cloud resources until they accept. This is particularly useful for employees, contractors, and temporary workers who access Microsoft 365, Azure, or other enterprise applications through Entra ID.

For audit purposes, use a document that has been approved by HR, Legal, and Information Security. The document should identify its owner, version, effective date, review date, and the population to which it applies. Do not upload an informal security-awareness handout and treat it as contractual terms; the document must align with your organization’s actual employment agreements and HR process.

How do you create employee security terms in entra id with the exact menu path?

Before configuring Entra, prepare a PDF named something similar to Employee_Information_Security_Terms_v3.0.pdf. Include clauses covering acceptable use, protection of organizational information, credential protection, reporting suspected incidents, asset return, confidentiality, monitoring where legally appropriate, disciplinary consequences, and the organization’s commitments to provide security policies, training, and appropriate safeguards.

  1. Sign in with the correct role. Open the Microsoft Entra admin center at https://entra.microsoft.com. Use an account assigned the Conditional Access Administrator, Security Administrator, or Global Administrator role. Your tenant also needs Microsoft Entra ID P1 or P2 licensing for Conditional Access.
  2. Open the Terms of Use area. In the left navigation, select Protection, then select Conditional Access, then select Terms of use.
  3. Create the terms record. Select New terms. In the creation pane, enter a descriptive administrative name in Name, such as Employee Information Security Terms - Version 3.0. This name is visible to Entra administrators and should make the document version clear during an audit.
  4. Set the employee-facing title. In Display name, enter the title users will see, such as Employee Information Security Responsibilities. Avoid generic titles such as “Terms” or “Policy,” because acceptance reports are more useful when the accepted item is clearly identifiable.
  5. Upload the approved PDF. Under Terms of use document, select the language, such as English, and upload the approved PDF. If your workforce requires multiple languages, select Add language and upload the formally approved translated version for each language. Ensure every translated document carries the same version and effective date or is traceably mapped to the approved master version.
  6. Configure acceptance controls. Under Require users to expand the terms of use, select On. This requires users to open the document before accepting it. Under Require users to consent on every device, normally select Off for employment terms; this is a personnel acknowledgement, not a device-specific consent. Under Expire consents, select On and set an appropriate recurrence, such as 365 days, if your policy requires annual reacceptance.
  7. Set a reacceptance date for a revised document. Under Require users to reaccept after, set the date on which the current terms should no longer be valid. For example, if version 3.0 is effective on 1 January 2026 and reviewed annually, set a reacceptance date of 31 December 2026. When a material revision is issued, create a new Terms of Use record and use Conditional Access to require acceptance of the new version.
  8. Create the terms. Review the configuration and select Create. Wait for the new item to appear in the Terms of use list with its document name, language, and expiration settings.
  9. Create the Conditional Access policy that enforces acceptance. Navigate to Protection > Conditional Access > Policies, then select New policy.
  10. Name and scope the policy. In Name, enter CA - Require Employee Information Security Terms. Under Assignments > Users or workload identities > Users, select Include and choose a controlled group such as SG-Employees-All. Under Exclude, exclude emergency access accounts and document the exclusion in your access-control register.
  11. Select the protected resources. Under Target resources, select All resources if the terms must be accepted before access to any Entra-integrated application. If that scope is too broad for initial deployment, select Select resources and choose Office 365 and the specific enterprise applications used by employees. A broad scope is generally easier to defend for ISO 27001 employment security terms, provided it is tested first.
  12. Require the Terms of Use grant control. Open Access controls > Grant. Select Grant access, check Terms of use, and select Employee Information Security Terms - Version 3.0. Select Select, then select Create.
  13. Deploy safely. Set Enable policy to Report-only first, review the results, then change it to On after testing with a pilot employee account. Do not leave an ISO control-dependent policy permanently in report-only mode.

Which Entra settings should an auditor expect to see?

Configuration item Recommended audit-ready value Why it matters
Terms of Use name Employee Information Security Terms - Version 3.0 Connects Entra acceptance evidence to an approved document version.
Require users to expand On Shows users had to open the document before accepting.
Expire consents On; 365 days Supports periodic acknowledgement where required by policy.
Conditional Access users Include: SG-Employees-All Demonstrates defined personnel scope rather than ad hoc assignment.
Conditional Access grant Grant access; Terms of use selected Enforces acceptance before access is granted.
Policy state On Shows the control is operating, not merely configured for testing.

How do you verify that the terms requirement took effect?

First, test with a non-administrative pilot account that is a member of SG-Employees-All. Open an in-scope application such as Microsoft 365, sign in as the pilot user, and confirm that Entra displays the Employee Information Security Responsibilities document before granting access. Confirm that the user must expand the PDF, select the acceptance option, and continue before reaching the application.

Next, return to Protection > Conditional Access > Terms of use, select the relevant terms record, and review the acceptance information available for that document. Also review Protection > Conditional Access > Monitoring > Sign-in logs. Open the pilot user’s sign-in event and confirm that the Conditional Access policy appears in the policy evaluation details and that the grant requirement was satisfied.

Perform one negative test as well: use a second pilot account that has not accepted the terms and attempt to access an in-scope application. The sign-in should be interrupted for acceptance rather than silently granting access. Record the date, tester, account used, application tested, and result in your control test record.

What evidence should you capture for an ISO 27001 assessor?

  • A PDF copy of the approved employment information-security terms, including version number, effective date, document owner, and approval evidence from HR, Legal, and Information Security.
  • A screenshot of Protection > Conditional Access > Terms of use showing the terms name, uploaded document, language, consent expiration, and reacceptance configuration.
  • A screenshot of the Conditional Access policy showing the included employee group, excluded emergency accounts, target resources, selected Terms of use grant control, and policy state of On.
  • An export or retained screenshot of the employee group membership from Identity > Groups > All groups > SG-Employees-All, demonstrating that the intended workforce population is in scope.
  • A dated test record with screenshots of the acceptance prompt and the Conditional Access sign-in log result for a pilot user.
  • An acceptance report or retained acceptance records showing user identity, document name or version, acceptance status, and acceptance date. Retain this according to your HR and audit evidence retention schedule.
  • A documented exception register for users who cannot authenticate through Entra, such as certain frontline workers, and the alternative signed acknowledgement process used for them.

Where does Entra ID fall short of ISO 27001 employment terms?

Entra Terms of Use records a digital acknowledgement and can block cloud access pending acceptance, but it does not create, negotiate, or legally validate an employment contract. It also does not prove that a worker received role-specific confidentiality clauses, completed onboarding paperwork, understood the terms, or remained bound by obligations after termination. Whether a click-through acceptance is legally sufficient depends on jurisdiction, employment law, collective agreements, and your organization’s Legal counsel.

Fill these gaps with an HR-controlled employment agreement or addendum, a documented onboarding workflow, legal review, signed-record retention in the HR system, and a process for non-Entra users. Your information-security management system should also define who reviews the terms, how often they are updated, what triggers a revision, and how revised terms are reissued. Entra is strong evidence of technical presentation and acknowledgement; HR and Legal evidence establish the contractual basis required by ISO 27001 control 6.2.

Next step: upload your approved current terms, deploy the Conditional Access policy to a pilot employee group, and add the resulting screenshots and acceptance records to your ISO 27001 control 6.2 evidence pack.

 

Quick & Simple

Discover Our Cybersecurity Compliance Solutions:

Whether you need to meet and maintain your compliance requirements, help your clients meet them, or verify supplier compliance we have the expertise and solution for you

 CMMC Level 1 Compliance App

CMMC Level 1 Compliance

Become compliant, provide compliance services, or verify partner compliance with CMMC Level 1 Basic Safeguarding of Covered Contractor Information Systems requirements.
 NIST SP 800-171 & CMMC Level 2 Compliance App

NIST SP 800-171 & CMMC Level 2 Compliance

Become compliant, provide compliance services, or verify partner compliance with NIST SP 800-171 and CMMC Level 2 requirements.
 HIPAA Compliance App

HIPAA Compliance

Become compliant, provide compliance services, or verify partner compliance with HIPAA security rule requirements.
 ISO 27001 Compliance App

ISO 27001 Compliance

Become compliant, provide compliance services, or verify partner compliance with ISO 27001 requirements.
 FAR 52.204-21 Compliance App

FAR 52.204-21 Compliance

Become compliant, provide compliance services, or verify partner compliance with FAR 52.204-21 Basic Safeguarding of Covered Contractor Information Systems requirements.
 ECC Compliance App

ECC Compliance

Become compliant, provide compliance services, or verify partner compliance with Essential Cybersecurity Controls (ECC – 2 : 2024) requirements.