The directory and procurement records disagree, and the gap is the finding
Access granted for a project that ended is the most common single entry, and the easiest to remediate.
Public sector organizations work with many suppliers, and each one that reaches your systems extends the attack surface into an organization whose security you do not control.
Most public sector organizations have never established how many third parties can reach their systems. Building the inventory from the directory rather than from procurement records is usually the finding in itself.
This paper examines why supplier access accumulates invisibly, why procurement and IT jointly owning third-party risk reliably means neither does, and what a proportionate control set looks like for an organization with more suppliers than security staff.
If you read nothing else, read these. The analysis that follows sets out the evidence for each.
Access granted for a project that ended is the most common single entry, and the easiest to remediate.
They are also among the most targeted accounts in any estate, which makes this the exemption that matters most.
Manual revocation depends on somebody remembering after a project ended and they have moved on.
Third-party risk needs one accountable person, and the split is the most common reason it goes unmanaged.
Access is granted for a reason, by somebody with authority, for a project with an end date that is not recorded anywhere the access system can see.
The project ends. The people involved move on. The access remains, because removing it requires somebody to notice it exists, establish that it is no longer needed, and take an action that has no deadline attached to it.
Add equipment vendors with standing remote support access granted at commissioning, suppliers who have granted their own subcontractors access on your behalf, and the estate extends considerably further than any diagram shows.
Multi-factor authentication without exception, because supplier accounts are heavily targeted and the exemption is almost always for convenience rather than for a technical reason.
Access scoped to the minimum required rather than to a general administrative role granted because it was quicker. Time-bound rather than standing, so expiry happens without anybody needing to act. Activity logged with retention, because you will need it during an incident and cannot create it retrospectively.
Conditional access restricting where and how third parties connect is proportionate and rarely implemented, and it is inexpensive relative to the exposure it addresses.
Security obligations in the contract rather than only in a policy the supplier has not signed. Breach notification requirements with a stated timescale — the clause most often missing. Subcontracting addressed and requiring your agreement, so you do not learn about a supplier's supplier from an audit log. A right to assurance evidence on a defined cadence. Exit provisions covering data return and access revocation with a timescale.
These are procurement's to write and IT's to enforce, which is precisely why the ownership question has to be settled first.
Every paper in this series ends with a framework you can run internally. We would rather you used it and reached your own conclusion than took ours on trust.
Five stages. The first produces a number that funds the rest.
Build from the directory. The gap against procurement records is your finding.
One accountable person for third-party risk. Split ownership means nobody reviews it.
MFA without exception, least privilege, and conditional access on location and device.
Access that expires automatically, linked to contract end rather than to memory.
Obligations, notification timescales, subcontracting consent and exit provisions in writing.
The same argument lands differently across an executive team. These are the three versions worth separating.
Microsoft's own documentation for the product behaviour described above. We would rather you verified the basis than accepted our summary of it.
On these references: each entry names a Microsoft Learn article or documentation area by title, because deep links change while titles are stable. Searching the title on learn.microsoft.com will reach the current version. Where we have cited a figure or a product behaviour, it is Microsoft's statement rather than ours; where we have given a number of our own it is labelled as such in the text.
We will build the third-party access inventory from your directory and produce a prioritised remediation list, which usually starts with a number nobody expected.
Public cloud programmes fail at procurement and governance far more often than at technical migration. This paper examines why and proposes a procurement approach that survives review.
Most agencies have a documented retention schedule and delete nothing. The bill arrives with the next records request.
Describe the situation in your own words.