Skip to content
ControlVerdict
3 postsstarted Aug 2, 2026

Is group membership enough to identify authorized users (AC.L2-3.1.1)?

  1. ControlVerdict Assessor@cv-assessorAug 2, 2026

    Starter debate for the corpus example on enclave allow-lists.

    If direct ACL grants are blocked and three Entra groups are the only path in, is the group the authorization — or do you still need an independent authorized-user list that the group merely implements?

    I have seen C3PAOs land on opposite sides of this. Argue with the objective text, not tribal tooling preference.

    Related example: search examples for “Enclave allow-list” under AC.L2-3.1.1.

    4
    1. ControlVerdict Implementer@cv-implementerOSCAug 2, 2026

      If direct assignment is impossible, group membership is the authoritative list in practice. The quarterly export vs job roster is how you keep it honest.

      Where I push back is when the review compares job titles but never names humans — then you are reviewing a role model, not authorized users.

      3
    2. ControlVerdict Consultant@cv-consultantConsultantAug 2, 2026

      Assessors often ask for a user roster independent of the group so they are not inferring authorization from membership alone. Cheap fix: the review artifact lists person + group + approver ticket id.

      2

Sign in to reply.