For ECC 2-2-3, the most useful entra id iam audit reports are exports and screenshots proving unique user identities, remote-access MFA enforcement, role and group authorization, privileged access controls, and periodic access reviews. An assessor will also expect the approved IAM and password policies, evidence that the controls are operating, and a clear link between Entra ID evidence and systems outside Microsoft’s platform. Prepare these as a dated evidence pack rather than relying on live portal demonstrations.
What does an assessor actually check for ECC 2-2-3?
Assessors generally do not award compliance because an organization can show an Entra ID dashboard. They test whether policy, configuration, approval, and day-to-day operation agree. For a finance or COO owner, the practical question is whether the evidence pack demonstrates that the organization has funded and governed a repeatable control—not merely purchased Microsoft licensing.
- Approved requirements and policies: the IAM policy, password management policy, remote-access MFA procedure, privileged access management policy, and periodic access-review plan. Each should show formal approval by the head of the organization, system owner, or authorized deputy, including an approval date and version.
- Unique identity and password-control evidence: an Entra ID user export showing unique
userPrincipalName, employee identifiers where available, account status, and account type; plus password-policy evidence for cloud identities and corresponding Active Directory policy evidence for hybrid identities. Entra ID reports alone do not prove all password settings if on-premises Active Directory remains authoritative. - Remote-access MFA enforcement: Conditional Access policies requiring MFA for the VPN, remote desktop gateway, virtual desktop, or other remote-access applications; sign-in logs showing successful MFA challenges; and the remote-access system configuration that trusts Entra ID or otherwise enforces the second factor.
- Authorization and segregation evidence: group membership, enterprise application assignments, administrative role assignments, access-request approvals, and access-review results. The assessor should be able to follow one selected employee from business need and manager approval through to the access actually granted.
- Privileged-access and review evidence: privileged role assignments, Privileged Identity Management activation history where used, named emergency-access accounts, audit logs, and completed access recertifications. Evidence should show that administrators use separate privileged accounts and that excessive or stale access is removed.
ECC 2-2-3-1 through 2-2-3-4 and the periodic-review requirement are connected. A strong evidence pack makes those connections explicit: a unique employee identity receives only approved group membership; remote access requires MFA; elevated rights are separately controlled; and all access is periodically reviewed.
Which entra id iam audit reports should be mapped before the audit?
The following map assigns every important item to a system location and accountable owner. This matters because audit delays commonly occur when IT assumes HR owns identity data, HR assumes security owns access reviews, and neither team has assembled the final proof.
| Evidence or tool | Report, configuration, or artifact | Location | Accountable owner |
|---|---|---|---|
| Microsoft Entra admin center | Users export: display name, UPN, employee ID, account enabled status, user type, creation date | Identity > Users > All users > Download users |
IAM manager |
| Microsoft Entra Conditional Access | Named policy exports and screenshots showing Grant: Require multifactor authentication for VPN and remote-access applications |
Protection > Conditional Access > Policies |
Security operations manager |
| Microsoft Entra sign-in logs | Sample of remote-access sign-ins showing authentication requirement, MFA result, user, application, IP address, and timestamp | Monitoring & health > Sign-in logs |
Security operations manager |
| Microsoft Entra ID Governance | Completed access reviews for privileged groups and sensitive enterprise applications, including reviewer decisions and removed users | Identity governance > Access reviews |
IAM manager with application owners |
| Microsoft Entra Privileged Identity Management | Eligible and active role assignments, activation history, approval settings, justification requirement, and emergency-access account register | Identity governance > Privileged Identity Management |
Infrastructure manager |
| Microsoft Entra audit logs | Changes to users, groups, application assignments, Conditional Access policies, and directory roles during the audit period | Monitoring & health > Audit logs |
Security operations manager |
| ITSM platform | Access requests containing requester identity, business justification, target asset, duration, manager approval, and fulfillment record | ServiceNow > Request > Access catalog |
IT service management owner |
| Policy repository | Approved IAM, password, PAM, MFA, and periodic-review policies with version history and executive approval | SharePoint > Governance > Approved Policies |
Compliance manager |
Save exported Entra IAM audit evidence in a controlled audit folder using a consistent convention such as ECC-2-2-3_CA-VPN-MFA_2026-07-15.pdf. Include a short index stating what each file proves, its collection date, its source, and which ECC objective it supports. This reduces assessor time and prevents expensive follow-up requests.
What are the top three gotchas that fail IAM audits?
- MFA is enabled, but remote access is not demonstrably covered. Security teams may show a broad MFA policy without proving that the VPN, remote desktop gateway, or third-party remote support tool is within scope. Assessors look for the application assignment, policy conditions, exclusions, and sign-in evidence. A policy in report-only mode is not enforcement.
- Privileged accounts are mixed with everyday accounts. An administrator who reads email, browses the web, and manages production systems with the same account defeats the PAM intent of ECC 2-2-3-4. Entra directory-role reports may show the assignment, but operating evidence must show separate named admin accounts, limited activation, and review.
- Access reviews are scheduled but not completed. An access-review configuration is only a plan. The assessor will ask for completed review cycles, named reviewers, decisions, evidence of removals, and exceptions approved by accountable managers. “No changes required” is not credible if reviewers did not actually attest.
For example, Atlas Freight Services, a 1,200-person transportation company operating Microsoft 365, a cloud transport-management system, warehouse handheld devices, and a third-party VPN, initially believed its Entra setup covered the control. Its gap analysis found that warehouse supervisors retained transport-management access after transfers and that the VPN Conditional Access policy excluded a legacy contractor group. The remediation was not a new platform purchase: it was a documented approval workflow, a corrected group design, quarterly reviews, and evidence showing the exclusion was removed.
What should the seven-day pre-audit countdown include?
- Day 7: Confirm audit scope, systems, legal entities, review period, and evidence owners. Identify systems not federated with Entra ID so they are not omitted.
- Day 6: Obtain final approved versions of IAM, password, MFA, PAM, and access-review policies. Verify approval authority and dates.
- Day 5: Export user, group, enterprise application, directory-role, Conditional Access, sign-in, and audit-log evidence. Preserve originals and create readable PDF copies.
- Day 4: Select samples: a new hire, a transferred employee, a terminated employee, a VPN user, a contractor, and a privileged administrator. Trace each sample through request, approval, provisioning, review, and removal where applicable.
- Day 3: Reconcile Entra reports with HR records, VPN records, Active Directory, and key applications. Investigate duplicates, guest accounts, disabled accounts with active privileges, and inactive users.
- Day 2: Complete any overdue access-review decisions and document exceptions with business owner approval, expiry date, and compensating controls. Do not backdate records.
- Day 1: Conduct a 30-minute evidence walkthrough with the IAM lead, HR representative, security lead, and application owner. Ensure each person can explain their portion without contradicting the policy.
What should management do during the assessor interview?
Keep the interview evidence-led and concise. Start with the approved IAM requirements, then show one end-to-end employee access sample, one remote-access MFA sample, one privileged-access sample, and one completed review cycle. Answer the question asked; if a report needs validation, commit to providing it after the session rather than searching live across multiple portals.
A COO or finance sponsor should focus on governance: who owns each control, how exceptions are approved, how remediation is funded, and how management knows reviews occur on time. At Atlas Freight Services, the COO could credibly explain that application owners certify access quarterly, the IAM team executes removals within five business days, and unresolved exceptions appear in the monthly risk register. That is more persuasive than attempting to explain Conditional Access policy syntax.
If an assessor identifies a gap, record it accurately, state the current risk treatment, name the remediation owner, and provide a realistic target date. Avoid claiming that an undocumented practice is a formal control. Auditors are usually more comfortable with a transparent, funded remediation plan than with incomplete or inconsistent evidence.
Next step: Ask your IAM and compliance leads to produce the evidence map and seven-day countdown as a budgeted, named-owner deliverable before the audit date is fixed.