Microsoft 365 CUI Access Policy Template: Screening Gates (PS.L2-3.9.1)

Microsoft 365 CUI Access Policy Template: Screening Gates (PS.L2-3.9.1)

Use this Microsoft 365 CUI access policy template to document screening gates before authorizing access to CUI systems under PS.L2-3.9.1.

LakeRidge Team
July 19, 2026
9 min read

Share:

Schedule Your Free Compliance Consultation

Feeling overwhelmed by compliance requirements? Not sure where to start? Get expert guidance tailored to your specific needs in just 15 minutes.

Personalized Compliance Roadmap
Expert Answers to Your Questions
No Obligation, 100% Free

CMMC Phase 2 begins November 10, 2026.

A Microsoft 365 CUI access policy template should require documented, role-appropriate personnel screening before an individual receives an account, group membership, license, or administrative privilege that permits access to Controlled Unclassified Information (CUI). For NIST SP 800-171 Rev. 2 and CMMC 2.0 Level 2 practice PS.L2-3.9.1, the policy must establish who is screened, what evidence is required, who approves exceptions, and how the organization proves screening occurred before access authorization.

Why must policy come before Microsoft 365 tooling?

Microsoft 365 can enforce many access decisions through Microsoft Entra ID, Privileged Identity Management, Conditional Access, sensitivity labels, and SharePoint permissions. It cannot independently determine whether a new employee, temporary worker, subcontractor, or administrator has completed the organization-defined screening required for the position. That determination is a personnel-security decision, not an identity-platform setting.

For an internal auditor responding to a new DFARS 252.204-7012 flow-down, the policy is the evidence bridge between Human Resources, contracting, security, and Microsoft 365 administration. An assessor should be able to trace a sampled user from a CUI-enabled Microsoft 365 group back to a screening record dated before the user’s access was authorized. Authentication controls under IA.L2-3.5.2 confirm that a person can log in; PS.L2-3.9.1 establishes that the person was eligible to receive CUI access in the first place.

The template below intentionally separates screening approval from technical provisioning. This prevents a manager’s email request, an Entra ID account creation date, or a completed security-awareness course from being treated as a substitute for documented screening.

What should a Microsoft 365 CUI access policy template say?

Customize the following policy body with your organization’s names, retention periods, contract-specific requirements, and screening criteria. Bracketed text identifies information that must be defined locally. Do not remove the requirement that screening be completed before authorization; an assessor will typically test that sequence using dated records.

POLICY TITLE: Personnel Screening for Microsoft 365 CUI Access
POLICY OWNER: [Director of Information Security / Facility Security Officer]
APPROVING AUTHORITY: [Executive Title]
EFFECTIVE DATE: [Month Day, Year]
VERSION: [Version Number]

1. PURPOSE
[Organization Name] screens individuals before authorizing access to
organizational systems containing Controlled Unclassified Information (CUI).
This policy supports NIST SP 800-171 Rev. 2 requirement 3.9.1 and CMMC 2.0
Level 2 practice PS.L2-3.9.1.

2. SCOPE
This policy applies to employees, temporary employees, contractors,
subcontractors, consultants, interns, managed service provider personnel,
and other non-employees who require access to CUI in Microsoft 365,
including Microsoft Teams, SharePoint Online, OneDrive for Business,
Exchange Online, Microsoft Purview, Microsoft Defender, and Microsoft
Entra ID administrative functions.

3. POLICY REQUIREMENT
No individual shall be granted access to a CUI-designated Microsoft 365
resource until [Human Resources / Security / Contract Administration] has
documented completion of screening appropriate to the individual’s role,
position sensitivity, contractual obligations, and level of access.

4. SCREENING CRITERIA
At a minimum, screening for CUI access shall include:
a. Verification of identity and employment or contractual relationship;
b. Confirmation that the individual has a legitimate business need for CUI;
c. Review of role-based screening requirements established by
   [Human Resources / Facility Security / Legal];
d. Confirmation of required nondisclosure, acceptable-use, and CUI handling
   acknowledgments; and
e. Verification of any contract-required eligibility, citizenship,
   export-control, background investigation, or customer-specific condition.

Additional screening is required for privileged Microsoft 365 roles,
including Global Administrator, Privileged Role Administrator, Exchange
Administrator, SharePoint Administrator, Security Administrator, Compliance
Administrator, and personnel able to modify CUI access controls.

5. SCREENING APPROVAL AND ACCESS AUTHORIZATION
[Human Resources / Security Office] shall issue a dated screening approval
record after required screening is complete. The approval record shall
identify the individual, role, screening level, reviewer, approval date,
and any access limitations.

The Microsoft 365 Access Administrator may provision CUI access only after
receiving an approved access request that includes the screening approval
record or a verified reference to the record in [ticketing system name].
Managers may request access but may not override screening requirements.

6. TECHNICAL PROVISIONING REQUIREMENTS
CUI access shall be assigned through approved Microsoft Entra ID security
groups or Microsoft 365 groups designated in the CUI Access Register.
Direct user permissions to CUI SharePoint sites, Teams, and OneDrive
locations are prohibited unless approved as a documented exception.

Privileged access shall use separate administrative accounts, multifactor
authentication, and Microsoft Entra Privileged Identity Management where
available. Privileged role eligibility shall not be activated until required
enhanced screening is documented.

7. SCREENING FAILURES, PENDING STATUS, AND EXCEPTIONS
Individuals with incomplete, expired, unsuccessful, or unverifiable
screening shall not receive CUI access. Their accounts may be provisioned
for non-CUI business services only when technically segregated from CUI.

Exceptions require written approval from [CISO], [Human Resources Lead],
and [Contract Administrator], must state the business justification,
compensating safeguards, expiration date, and affected resources, and may
not conflict with contract, law, or customer requirements. No exception
may authorize access where screening is expressly required by law, contract,
or customer direction.

8. RE-SCREENING AND ACCESS REVIEW
Screening status shall be revalidated upon role change, transfer to a
CUI-related program, conversion from employee to contractor or vice versa,
material change in contractual requirements, or every [12/24] months,
whichever occurs first. CUI access owners shall review membership in
CUI-designated Microsoft 365 groups at least every [90] days.

9. TERMINATION AND REMOVAL
Upon termination, contract completion, role change, failed re-screening,
or loss of business need, [Human Resources / Contract Administration] shall
notify the Access Administrator through [ticketing system] within [one
business day]. CUI access shall be removed within [four hours / one
business day] according to the severity and circumstance of the event.

10. RECORDS AND RETENTION
[Organization Name] shall retain screening approvals, access requests,
approval workflows, group membership evidence, review records, exceptions,
and revocation records for [three years after contract completion / period
required by contract or records schedule]. Records shall be protected from
unauthorized modification and made available for assessment or audit.

11. ENFORCEMENT
Violations of this policy may result in removal of access, disciplinary
action, contract remedies, and other actions permitted by applicable law,
contract, and organizational policy.

Which attachments and exhibits should support the policy?

A policy alone rarely satisfies an external assessor. The following attachments provide the operational evidence that the policy is implemented consistently rather than existing only as approved language.

Attachment or exhibit Required contents Primary evidence owner
CUI Access Request Form User name, manager, contract or program, requested Microsoft 365 resource, business need, screening approval reference, and approver signatures. Access Administration
Screening Determination Record Identity verification, screening type, completion date, reviewer, role sensitivity, limitations, and re-screening due date. Human Resources or Security
CUI Access Register CUI SharePoint sites, Teams, shared mailboxes, Entra ID groups, resource owners, and whether privileged access is permitted. Information Security
Microsoft Entra ID Group Export Current membership of groups such as CUI-Project-Atlas-Members and CUI-SharePoint-Contributors, exported with date and reviewer. Microsoft 365 Administration
Quarterly Access Review Certification Resource-owner certification of continuing need, removals requested, unresolved discrepancies, and review completion date. System or Data Owner
Exception Register Exception ID, approvers, compensating controls, affected resource, start and expiration dates, and closure evidence. Information Security

For Microsoft 365, preserve technical corroboration alongside personnel records. Useful evidence includes ServiceNow or Jira approval tickets, Entra ID audit logs showing group-add events, Purview audit records for SharePoint permission changes, and Privileged Identity Management activation history for privileged roles. The access event should occur after the screening approval date; where it does not, document the incident, remediation, and whether CUI access was actually available during the gap.

How often should the policy be approved and reviewed?

The approving authority should approve the policy before it is used to support the new DFARS flow-down, and the policy owner should review it at least annually. A more frequent targeted review is appropriate when a new contract adds citizenship restrictions, customer background-screening terms, export-control conditions, a new managed service provider, or a material change to the Microsoft 365 CUI boundary.

  • Policy review: Every 12 months and after material contractual, regulatory, organizational, or system changes.
  • CUI group membership review: Every 90 days, with documented owner certification.
  • Privileged role review: Every 30 days for standing eligibility and active assignments.
  • Screening revalidation: At role change, reassignment to a CUI program, or the organization-defined interval.
  • Evidence sampling: Quarterly, by internal audit or security governance, using a sample of newly authorized users.

For assessment readiness, retain a simple approval history showing policy version, approver, effective date, change summary, and next review date. Assessors commonly ask whether the policy in force during the sampled access event was approved and whether the procedure used by administrators matches that version.

What common edits are needed by industry?

Defense contractors: Add contract number, program identifiers, DD254 references where applicable, subcontractor-flow-down responsibilities, and a statement that contract-specific eligibility conditions override general access approval. This is particularly important when the DFARS 252.204-7012 flow-down reaches external engineering, help-desk, or managed-service personnel.

Aerospace and export-controlled manufacturers: Add a screening determination for U.S.-person status or export authorization where required. Avoid treating citizenship as a universal CUI rule; state that the requirement applies only when the contract, export classification, or customer direction requires it.

Healthcare and life sciences organizations: Distinguish screening for CUI systems from workforce requirements associated with protected health information. If a Microsoft 365 tenant contains both CUI and regulated health data, define the stricter screening trigger and identify the responsible compliance owner.

Professional services and technology providers: Expand the non-employee clause for contractors, offshore support, subcontractors, and managed service providers. Require the sponsoring organization to provide screening attestation before a guest account, B2B collaboration invitation, or administrative access is enabled.

Small manufacturers: Keep the approval path lean but independent: a manager establishes business need, HR or a designated security official verifies screening, and a Microsoft 365 administrator provisions access only from the documented approval. A small team does not eliminate separation of duties; it makes written evidence more important.

Next, map this Microsoft 365 CUI access policy template to your current Entra ID CUI groups and test five recent access approvals for proof that screening preceded authorization.

 

Quick & Simple

Discover Our Cybersecurity Compliance Solutions:

Whether you need to meet and maintain your compliance requirements, help your clients meet them, or verify supplier compliance we have the expertise and solution for you

 CMMC Level 1 Compliance App

CMMC Level 1 Compliance

Become compliant, provide compliance services, or verify partner compliance with CMMC Level 1 Basic Safeguarding of Covered Contractor Information Systems requirements.
 NIST SP 800-171 & CMMC Level 2 Compliance App

NIST SP 800-171 & CMMC Level 2 Compliance

Become compliant, provide compliance services, or verify partner compliance with NIST SP 800-171 and CMMC Level 2 requirements.
 HIPAA Compliance App

HIPAA Compliance

Become compliant, provide compliance services, or verify partner compliance with HIPAA security rule requirements.
 ISO 27001 Compliance App

ISO 27001 Compliance

Become compliant, provide compliance services, or verify partner compliance with ISO 27001 requirements.
 FAR 52.204-21 Compliance App

FAR 52.204-21 Compliance

Become compliant, provide compliance services, or verify partner compliance with FAR 52.204-21 Basic Safeguarding of Covered Contractor Information Systems requirements.
 ECC Compliance App

ECC Compliance

Become compliant, provide compliance services, or verify partner compliance with Essential Cybersecurity Controls (ECC – 2 : 2024) requirements.