A Microsoft 365 CUI access policy template should require documented, role-appropriate personnel screening before an individual receives an account, group membership, license, or administrative privilege that permits access to Controlled Unclassified Information (CUI). For NIST SP 800-171 Rev. 2 and CMMC 2.0 Level 2 practice PS.L2-3.9.1, the policy must establish who is screened, what evidence is required, who approves exceptions, and how the organization proves screening occurred before access authorization.
Why must policy come before Microsoft 365 tooling?
Microsoft 365 can enforce many access decisions through Microsoft Entra ID, Privileged Identity Management, Conditional Access, sensitivity labels, and SharePoint permissions. It cannot independently determine whether a new employee, temporary worker, subcontractor, or administrator has completed the organization-defined screening required for the position. That determination is a personnel-security decision, not an identity-platform setting.
For an internal auditor responding to a new DFARS 252.204-7012 flow-down, the policy is the evidence bridge between Human Resources, contracting, security, and Microsoft 365 administration. An assessor should be able to trace a sampled user from a CUI-enabled Microsoft 365 group back to a screening record dated before the user’s access was authorized. Authentication controls under IA.L2-3.5.2 confirm that a person can log in; PS.L2-3.9.1 establishes that the person was eligible to receive CUI access in the first place.
The template below intentionally separates screening approval from technical provisioning. This prevents a manager’s email request, an Entra ID account creation date, or a completed security-awareness course from being treated as a substitute for documented screening.
What should a Microsoft 365 CUI access policy template say?
Customize the following policy body with your organization’s names, retention periods, contract-specific requirements, and screening criteria. Bracketed text identifies information that must be defined locally. Do not remove the requirement that screening be completed before authorization; an assessor will typically test that sequence using dated records.
POLICY TITLE: Personnel Screening for Microsoft 365 CUI Access POLICY OWNER: [Director of Information Security / Facility Security Officer] APPROVING AUTHORITY: [Executive Title] EFFECTIVE DATE: [Month Day, Year] VERSION: [Version Number] 1. PURPOSE [Organization Name] screens individuals before authorizing access to organizational systems containing Controlled Unclassified Information (CUI). This policy supports NIST SP 800-171 Rev. 2 requirement 3.9.1 and CMMC 2.0 Level 2 practice PS.L2-3.9.1. 2. SCOPE This policy applies to employees, temporary employees, contractors, subcontractors, consultants, interns, managed service provider personnel, and other non-employees who require access to CUI in Microsoft 365, including Microsoft Teams, SharePoint Online, OneDrive for Business, Exchange Online, Microsoft Purview, Microsoft Defender, and Microsoft Entra ID administrative functions. 3. POLICY REQUIREMENT No individual shall be granted access to a CUI-designated Microsoft 365 resource until [Human Resources / Security / Contract Administration] has documented completion of screening appropriate to the individual’s role, position sensitivity, contractual obligations, and level of access. 4. SCREENING CRITERIA At a minimum, screening for CUI access shall include: a. Verification of identity and employment or contractual relationship; b. Confirmation that the individual has a legitimate business need for CUI; c. Review of role-based screening requirements established by [Human Resources / Facility Security / Legal]; d. Confirmation of required nondisclosure, acceptable-use, and CUI handling acknowledgments; and e. Verification of any contract-required eligibility, citizenship, export-control, background investigation, or customer-specific condition. Additional screening is required for privileged Microsoft 365 roles, including Global Administrator, Privileged Role Administrator, Exchange Administrator, SharePoint Administrator, Security Administrator, Compliance Administrator, and personnel able to modify CUI access controls. 5. SCREENING APPROVAL AND ACCESS AUTHORIZATION [Human Resources / Security Office] shall issue a dated screening approval record after required screening is complete. The approval record shall identify the individual, role, screening level, reviewer, approval date, and any access limitations. The Microsoft 365 Access Administrator may provision CUI access only after receiving an approved access request that includes the screening approval record or a verified reference to the record in [ticketing system name]. Managers may request access but may not override screening requirements. 6. TECHNICAL PROVISIONING REQUIREMENTS CUI access shall be assigned through approved Microsoft Entra ID security groups or Microsoft 365 groups designated in the CUI Access Register. Direct user permissions to CUI SharePoint sites, Teams, and OneDrive locations are prohibited unless approved as a documented exception. Privileged access shall use separate administrative accounts, multifactor authentication, and Microsoft Entra Privileged Identity Management where available. Privileged role eligibility shall not be activated until required enhanced screening is documented. 7. SCREENING FAILURES, PENDING STATUS, AND EXCEPTIONS Individuals with incomplete, expired, unsuccessful, or unverifiable screening shall not receive CUI access. Their accounts may be provisioned for non-CUI business services only when technically segregated from CUI. Exceptions require written approval from [CISO], [Human Resources Lead], and [Contract Administrator], must state the business justification, compensating safeguards, expiration date, and affected resources, and may not conflict with contract, law, or customer requirements. No exception may authorize access where screening is expressly required by law, contract, or customer direction. 8. RE-SCREENING AND ACCESS REVIEW Screening status shall be revalidated upon role change, transfer to a CUI-related program, conversion from employee to contractor or vice versa, material change in contractual requirements, or every [12/24] months, whichever occurs first. CUI access owners shall review membership in CUI-designated Microsoft 365 groups at least every [90] days. 9. TERMINATION AND REMOVAL Upon termination, contract completion, role change, failed re-screening, or loss of business need, [Human Resources / Contract Administration] shall notify the Access Administrator through [ticketing system] within [one business day]. CUI access shall be removed within [four hours / one business day] according to the severity and circumstance of the event. 10. RECORDS AND RETENTION [Organization Name] shall retain screening approvals, access requests, approval workflows, group membership evidence, review records, exceptions, and revocation records for [three years after contract completion / period required by contract or records schedule]. Records shall be protected from unauthorized modification and made available for assessment or audit. 11. ENFORCEMENT Violations of this policy may result in removal of access, disciplinary action, contract remedies, and other actions permitted by applicable law, contract, and organizational policy.
Which attachments and exhibits should support the policy?
A policy alone rarely satisfies an external assessor. The following attachments provide the operational evidence that the policy is implemented consistently rather than existing only as approved language.
| Attachment or exhibit | Required contents | Primary evidence owner |
|---|---|---|
| CUI Access Request Form | User name, manager, contract or program, requested Microsoft 365 resource, business need, screening approval reference, and approver signatures. | Access Administration |
| Screening Determination Record | Identity verification, screening type, completion date, reviewer, role sensitivity, limitations, and re-screening due date. | Human Resources or Security |
| CUI Access Register | CUI SharePoint sites, Teams, shared mailboxes, Entra ID groups, resource owners, and whether privileged access is permitted. | Information Security |
| Microsoft Entra ID Group Export | Current membership of groups such as CUI-Project-Atlas-Members and CUI-SharePoint-Contributors, exported with date and reviewer. |
Microsoft 365 Administration |
| Quarterly Access Review Certification | Resource-owner certification of continuing need, removals requested, unresolved discrepancies, and review completion date. | System or Data Owner |
| Exception Register | Exception ID, approvers, compensating controls, affected resource, start and expiration dates, and closure evidence. | Information Security |
For Microsoft 365, preserve technical corroboration alongside personnel records. Useful evidence includes ServiceNow or Jira approval tickets, Entra ID audit logs showing group-add events, Purview audit records for SharePoint permission changes, and Privileged Identity Management activation history for privileged roles. The access event should occur after the screening approval date; where it does not, document the incident, remediation, and whether CUI access was actually available during the gap.
How often should the policy be approved and reviewed?
The approving authority should approve the policy before it is used to support the new DFARS flow-down, and the policy owner should review it at least annually. A more frequent targeted review is appropriate when a new contract adds citizenship restrictions, customer background-screening terms, export-control conditions, a new managed service provider, or a material change to the Microsoft 365 CUI boundary.
- Policy review: Every 12 months and after material contractual, regulatory, organizational, or system changes.
- CUI group membership review: Every 90 days, with documented owner certification.
- Privileged role review: Every 30 days for standing eligibility and active assignments.
- Screening revalidation: At role change, reassignment to a CUI program, or the organization-defined interval.
- Evidence sampling: Quarterly, by internal audit or security governance, using a sample of newly authorized users.
For assessment readiness, retain a simple approval history showing policy version, approver, effective date, change summary, and next review date. Assessors commonly ask whether the policy in force during the sampled access event was approved and whether the procedure used by administrators matches that version.
What common edits are needed by industry?
Defense contractors: Add contract number, program identifiers, DD254 references where applicable, subcontractor-flow-down responsibilities, and a statement that contract-specific eligibility conditions override general access approval. This is particularly important when the DFARS 252.204-7012 flow-down reaches external engineering, help-desk, or managed-service personnel.
Aerospace and export-controlled manufacturers: Add a screening determination for U.S.-person status or export authorization where required. Avoid treating citizenship as a universal CUI rule; state that the requirement applies only when the contract, export classification, or customer direction requires it.
Healthcare and life sciences organizations: Distinguish screening for CUI systems from workforce requirements associated with protected health information. If a Microsoft 365 tenant contains both CUI and regulated health data, define the stricter screening trigger and identify the responsible compliance owner.
Professional services and technology providers: Expand the non-employee clause for contractors, offshore support, subcontractors, and managed service providers. Require the sponsoring organization to provide screening attestation before a guest account, B2B collaboration invitation, or administrative access is enabled.
Small manufacturers: Keep the approval path lean but independent: a manager establishes business need, HR or a designated security official verifies screening, and a Microsoft 365 administrator provisions access only from the documented approval. A small team does not eliminate separation of duties; it makes written evidence more important.
Next, map this Microsoft 365 CUI access policy template to your current Entra ID CUI groups and test five recent access approvals for proof that screening preceded authorization.