ISO 27001 A.5.18 evidence for Microsoft 365 access reviews
Control A.5.18 of ISO/IEC 27001:2022 says access rights must be provisioned, reviewed, modified and removed according to your access control policy. The review part is where most audits find gaps, because the evidence is a spreadsheet from last year.
What control A.5.18 requires
A.5.18 "Access rights" reads: access rights to information and other associated assets shall be provisioned, reviewed, modified and removed in accordance with the organization’s topic-specific policy on and rules for access control. It sits next to A.5.15 (access control), A.5.16 (identity management) and A.8.2 (privileged access rights).
The implementation guidance in ISO/IEC 27002:2022 adds that access rights should be reviewed regularly and after changes such as a role change or termination, and that privileged access deserves closer review.
What auditors ask to see
- The access control policy, including who reviews what and how often.
- A record of completed reviews: which object, which reviewer, what date, what decision.
- Evidence that removals decided in a review were carried out.
- How leavers are handled, and how fast their access and their ownerships are reassigned.
For Microsoft 365, the hard part is the objects that do not belong to one person: shared mailboxes, Teams, SharePoint sites and service principals. Nobody is obviously responsible for reviewing them, so they are often left out.
How Ownership Registry covers it
| Audit question | Where the answer comes from |
|---|---|
| What is in scope? | The scheduled Graph scan inventory, including service principals and custom object types |
| Who is responsible? | The named primary and backup owner of each object |
| Was it reviewed, by whom, when? | The attestation record: one click by the owner, timestamped |
| What happened when nobody answered? | Two reminders a week apart, then an escalation email to your service desk |
| Can the record be trusted? | Append-only audit log, enforced by a database trigger |
| How are leavers handled? | Owners are re-validated against Entra ID on every scan, and the backup owner takes over automatically |
The review cadence is set per object (monthly, six-monthly or yearly), so the frequency written in your policy is the frequency the registry runs. The same trail answers SOC 2 and NIS2 questions about access review.
ISO 27001 questions
Does ISO 27001 say how often access must be reviewed?
No. A.5.18 requires reviews in line with your own access control policy, and the auditor checks that you follow what the policy says. Choose a risk-based cadence, write it down, and make sure the evidence shows it being met.
Do we still need the 2013 control numbers?
No. The transition period for ISO/IEC 27001:2013 certificates ended on 31 October 2025, so certificates now refer to the 2022 Annex A, where access rights are control A.5.18 (formerly A.9.2.5 among others).
Does it cover access inside our business applications?
No. It covers Microsoft 365 objects and service accounts, plus anything you register as a custom object type. Access inside an ERP or CRM needs that application’s own review.
Bring evidence, not a spreadsheet
See the audit trail on your own tenant in a 30-minute read-only demo. Security details are on the security page. Book a demo