To create employee security terms in entra id for ISO 27001 control 6.2, upload an approved information-security employment terms document as a Microsoft Entra Terms of Use policy and require acceptance through Conditional Access before employees access organizational resources. This provides a controlled acknowledgement record, but the underlying employment contract or HR policy must still contain the organization’s and personnel’s information-security responsibilities.
What does ISO 27001 control 6.2 require, and can Entra ID satisfy it?
ISO/IEC 27001:2022 Annex A control 6.2, Terms and conditions of employment, requires employment contractual agreements to state both the personnel’s information-security responsibilities and the organization’s responsibilities for information security. For an audit, you need to show that these terms exist, are approved, are issued to the relevant workforce population, and can be demonstrated as accepted or otherwise acknowledged.
Microsoft Entra ID can support this requirement by presenting a PDF document to users at sign-in, recording their acceptance, and preventing access to selected cloud resources until they accept. This is particularly useful for employees, contractors, and temporary workers who access Microsoft 365, Azure, or other enterprise applications through Entra ID.
For audit purposes, use a document that has been approved by HR, Legal, and Information Security. The document should identify its owner, version, effective date, review date, and the population to which it applies. Do not upload an informal security-awareness handout and treat it as contractual terms; the document must align with your organization’s actual employment agreements and HR process.
How do you create employee security terms in entra id with the exact menu path?
Before configuring Entra, prepare a PDF named something similar to Employee_Information_Security_Terms_v3.0.pdf. Include clauses covering acceptable use, protection of organizational information, credential protection, reporting suspected incidents, asset return, confidentiality, monitoring where legally appropriate, disciplinary consequences, and the organization’s commitments to provide security policies, training, and appropriate safeguards.
- Sign in with the correct role. Open the Microsoft Entra admin center at
https://entra.microsoft.com. Use an account assigned the Conditional Access Administrator, Security Administrator, or Global Administrator role. Your tenant also needs Microsoft Entra ID P1 or P2 licensing for Conditional Access. - Open the Terms of Use area. In the left navigation, select
Protection, then selectConditional Access, then selectTerms of use. - Create the terms record. Select
New terms. In the creation pane, enter a descriptive administrative name inName, such asEmployee Information Security Terms - Version 3.0. This name is visible to Entra administrators and should make the document version clear during an audit. - Set the employee-facing title. In
Display name, enter the title users will see, such asEmployee Information Security Responsibilities. Avoid generic titles such as “Terms” or “Policy,” because acceptance reports are more useful when the accepted item is clearly identifiable. - Upload the approved PDF. Under
Terms of use document, select the language, such asEnglish, and upload the approved PDF. If your workforce requires multiple languages, selectAdd languageand upload the formally approved translated version for each language. Ensure every translated document carries the same version and effective date or is traceably mapped to the approved master version. - Configure acceptance controls. Under
Require users to expand the terms of use, selectOn. This requires users to open the document before accepting it. UnderRequire users to consent on every device, normally selectOfffor employment terms; this is a personnel acknowledgement, not a device-specific consent. UnderExpire consents, selectOnand set an appropriate recurrence, such as365 days, if your policy requires annual reacceptance. - Set a reacceptance date for a revised document. Under
Require users to reaccept after, set the date on which the current terms should no longer be valid. For example, if version 3.0 is effective on 1 January 2026 and reviewed annually, set a reacceptance date of31 December 2026. When a material revision is issued, create a new Terms of Use record and use Conditional Access to require acceptance of the new version. - Create the terms. Review the configuration and select
Create. Wait for the new item to appear in theTerms of uselist with its document name, language, and expiration settings. - Create the Conditional Access policy that enforces acceptance. Navigate to
Protection>Conditional Access>Policies, then selectNew policy. - Name and scope the policy. In
Name, enterCA - Require Employee Information Security Terms. UnderAssignments>Users or workload identities>Users, selectIncludeand choose a controlled group such asSG-Employees-All. UnderExclude, exclude emergency access accounts and document the exclusion in your access-control register. - Select the protected resources. Under
Target resources, selectAll resourcesif the terms must be accepted before access to any Entra-integrated application. If that scope is too broad for initial deployment, selectSelect resourcesand chooseOffice 365and the specific enterprise applications used by employees. A broad scope is generally easier to defend for ISO 27001 employment security terms, provided it is tested first. - Require the Terms of Use grant control. Open
Access controls>Grant. SelectGrant access, checkTerms of use, and selectEmployee Information Security Terms - Version 3.0. SelectSelect, then selectCreate. - Deploy safely. Set
Enable policytoReport-onlyfirst, review the results, then change it toOnafter testing with a pilot employee account. Do not leave an ISO control-dependent policy permanently in report-only mode.
Which Entra settings should an auditor expect to see?
| Configuration item | Recommended audit-ready value | Why it matters |
|---|---|---|
| Terms of Use name | Employee Information Security Terms - Version 3.0 | Connects Entra acceptance evidence to an approved document version. |
| Require users to expand | On | Shows users had to open the document before accepting. |
| Expire consents | On; 365 days | Supports periodic acknowledgement where required by policy. |
| Conditional Access users | Include: SG-Employees-All | Demonstrates defined personnel scope rather than ad hoc assignment. |
| Conditional Access grant | Grant access; Terms of use selected | Enforces acceptance before access is granted. |
| Policy state | On | Shows the control is operating, not merely configured for testing. |
How do you verify that the terms requirement took effect?
First, test with a non-administrative pilot account that is a member of SG-Employees-All. Open an in-scope application such as Microsoft 365, sign in as the pilot user, and confirm that Entra displays the Employee Information Security Responsibilities document before granting access. Confirm that the user must expand the PDF, select the acceptance option, and continue before reaching the application.
Next, return to Protection > Conditional Access > Terms of use, select the relevant terms record, and review the acceptance information available for that document. Also review Protection > Conditional Access > Monitoring > Sign-in logs. Open the pilot user’s sign-in event and confirm that the Conditional Access policy appears in the policy evaluation details and that the grant requirement was satisfied.
Perform one negative test as well: use a second pilot account that has not accepted the terms and attempt to access an in-scope application. The sign-in should be interrupted for acceptance rather than silently granting access. Record the date, tester, account used, application tested, and result in your control test record.
What evidence should you capture for an ISO 27001 assessor?
- A PDF copy of the approved employment information-security terms, including version number, effective date, document owner, and approval evidence from HR, Legal, and Information Security.
- A screenshot of
Protection>Conditional Access>Terms of useshowing the terms name, uploaded document, language, consent expiration, and reacceptance configuration. - A screenshot of the Conditional Access policy showing the included employee group, excluded emergency accounts, target resources, selected
Terms of usegrant control, and policy state ofOn. - An export or retained screenshot of the employee group membership from
Identity>Groups>All groups>SG-Employees-All, demonstrating that the intended workforce population is in scope. - A dated test record with screenshots of the acceptance prompt and the Conditional Access sign-in log result for a pilot user.
- An acceptance report or retained acceptance records showing user identity, document name or version, acceptance status, and acceptance date. Retain this according to your HR and audit evidence retention schedule.
- A documented exception register for users who cannot authenticate through Entra, such as certain frontline workers, and the alternative signed acknowledgement process used for them.
Where does Entra ID fall short of ISO 27001 employment terms?
Entra Terms of Use records a digital acknowledgement and can block cloud access pending acceptance, but it does not create, negotiate, or legally validate an employment contract. It also does not prove that a worker received role-specific confidentiality clauses, completed onboarding paperwork, understood the terms, or remained bound by obligations after termination. Whether a click-through acceptance is legally sufficient depends on jurisdiction, employment law, collective agreements, and your organization’s Legal counsel.
Fill these gaps with an HR-controlled employment agreement or addendum, a documented onboarding workflow, legal review, signed-record retention in the HR system, and a process for non-Entra users. Your information-security management system should also define who reviews the terms, how often they are updated, what triggers a revision, and how revised terms are reissued. Entra is strong evidence of technical presentation and acknowledgement; HR and Legal evidence establish the contractual basis required by ISO 27001 control 6.2.
Next step: upload your approved current terms, deploy the Conditional Access policy to a pilot employee group, and add the resulting screenshots and acceptance records to your ISO 27001 control 6.2 evidence pack.