ID Posture
ISO/IEC 27001:2022

Map your identity controls to ISO/IEC 27001:2022 Annex A.

ID Posture reports technical indicators for the identity-related Annex A controls Microsoft Entra ID data can actually show, alongside the ACSC Essential Eight, not instead of it.

The five controls ID Posture maps to

5 of ISO/IEC 27001:2022's 93 Annex A controls: the identity/access-relevant Organizational and Technological controls Entra ID data can directly evidence.

5.16
Identity Management
Flags stale member and guest accounts, apps and groups without an owner, admins without a dedicated privileged account, and accounts left active past when offboarding should have removed them.
5.17
Authentication Information
Flags application secrets and certificates with no expiry, expiring soon, or already expired, so credential values are never left unmanaged.
5.18
Access Rights
Maps Contributor sprawl, guest RBAC assignments, standing PIM-eligible access, overly broad custom directory roles, and permissive guest invite/consent defaults.
8.2
Privileged Access Rights
Maps standing vs. PIM-eligible privileged roles, excessive Global Admins, break-glass account hygiene, subscription Owner assignments, and over-privileged managed identities.
8.5
Secure Authentication
Maps MFA registration coverage, Conditional Access gaps and policy conflicts, legacy authentication protocol usage, and Security Defaults status.

Technical indicators, not a certification assessment

ID Posture reports technical indicators for the 5 ISO/IEC 27001:2022 Annex A controls most directly observable from Microsoft Entra ID data. This is not a certification assessment. ISO 27001 has 93 Annex A controls in total, and satisfying even these 5 requires documented policies and procedures no automated scan can observe.

  • A control shown with zero open findings means no relevant technical misconfiguration was detected, not that the control is certified as met.
  • ISO 27001 has no official per-control maturity tiers, unlike the Essential Eight, so this page shows open-finding counts, never a pass/fail badge or maturity level.

Satisfying an Annex A control for certification purposes requires a documented policy and process an auditor reviews, something no automated scan of Entra ID data alone can confirm.

ID Posture also maps identity findings to the ACSC Essential Eight, E8-5 (restrict administrative privileges) and E8-7 (multi-factor authentication).

See where you stand against ISO 27001's identity controls.

A live walkthrough on your own tenant, no slideware.

Book a demo