JJC SystemsBook a Consultation
Microsoft Defender · Public Sector

Third-party risk in public supply chains

Public sector organizations work with many suppliers, and each one that reaches your systems extends the attack surface into an organization whose security you do not control.

PublishedFebruary 15, 2026
Length13 pages · 14 min read
SectorPublic Sector
PlatformMicrosoft Defender
Service areaManaged IT & Security
Abstract

Third-party risk in public supply chains

Summary

Most public sector organizations have never established how many third parties can reach their systems. Building the inventory from the directory rather than from procurement records is usually the finding in itself.

This paper examines why supplier access accumulates invisibly, why procurement and IT jointly owning third-party risk reliably means neither does, and what a proportionate control set looks like for an organization with more suppliers than security staff.

Key findings

Four things this paper argues

If you read nothing else, read these. The analysis that follows sets out the evidence for each.

01

The directory and procurement records disagree, and the gap is the finding

Access granted for a project that ended is the most common single entry, and the easiest to remediate.

02

Supplier accounts are frequently exempted from MFA for convenience

They are also among the most targeted accounts in any estate, which makes this the exemption that matters most.

03

Time-bound access is the only kind that reliably expires

Manual revocation depends on somebody remembering after a project ended and they have moved on.

04

Split ownership between procurement and IT means nobody reviews it

Third-party risk needs one accountable person, and the split is the most common reason it goes unmanaged.

Analysis

The argument in full

Why it accumulates

Access is granted for a reason, by somebody with authority, for a project with an end date that is not recorded anywhere the access system can see.

The project ends. The people involved move on. The access remains, because removing it requires somebody to notice it exists, establish that it is no longer needed, and take an action that has no deadline attached to it.

Add equipment vendors with standing remote support access granted at commissioning, suppliers who have granted their own subcontractors access on your behalf, and the estate extends considerably further than any diagram shows.

  • A complete inventory built from the directory, not from procurement records
  • Every entry naming a supplier, a purpose and an internal owner
  • Access granted for concluded projects identified and removed
  • Supplier-to-supplier access surfaced, which is more common than expected
  • Equipment vendor remote maintenance access included in scope

Proportionate controls

Multi-factor authentication without exception, because supplier accounts are heavily targeted and the exemption is almost always for convenience rather than for a technical reason.

Access scoped to the minimum required rather than to a general administrative role granted because it was quicker. Time-bound rather than standing, so expiry happens without anybody needing to act. Activity logged with retention, because you will need it during an incident and cannot create it retrospectively.

Conditional access restricting where and how third parties connect is proportionate and rarely implemented, and it is inexpensive relative to the exposure it addresses.

The contractual half

Security obligations in the contract rather than only in a policy the supplier has not signed. Breach notification requirements with a stated timescale — the clause most often missing. Subcontracting addressed and requiring your agreement, so you do not learn about a supplier's supplier from an audit log. A right to assurance evidence on a defined cadence. Exit provisions covering data return and access revocation with a timescale.

These are procurement's to write and IT's to enforce, which is precisely why the ownership question has to be settled first.

Framework

Something you can apply without us

Every paper in this series ends with a framework you can run internally. We would rather you used it and reached your own conclusion than took ours on trust.

Framework

Managing third-party access

Five stages. The first produces a number that funds the rest.

1

Inventory

Build from the directory. The gap against procurement records is your finding.

2

Own

One accountable person for third-party risk. Split ownership means nobody reviews it.

3

Constrain

MFA without exception, least privilege, and conditional access on location and device.

4

Time-bound

Access that expires automatically, linked to contract end rather than to memory.

5

Contract

Obligations, notification timescales, subcontracting consent and exit provisions in writing.

Implications

What this means, depending on your seat

The same argument lands differently across an executive team. These are the three versions worth separating.

For the CIO

For procurement

For the Monitoring Officer or audit committee

References

Where to check this for yourself

Microsoft's own documentation for the product behaviour described above. We would rather you verified the basis than accepted our summary of it.

01
Microsoft Entra External ID and B2B collaboration
02
Entitlement management and access packages
03
Conditional Access policy design
04
Access reviews in Microsoft Entra ID Governance
05
Microsoft Defender for Cloud Apps

On these references: each entry names a Microsoft Learn article or documentation area by title, because deep links change while titles are stable. Searching the title on learn.microsoft.com will reach the current version. Where we have cited a figure or a product behaviour, it is Microsoft's statement rather than ours; where we have given a number of our own it is labelled as such in the text.

Recognise the situation?

We will build the third-party access inventory from your directory and produce a prioritised remediation list, which usually starts with a number nobody expected.

Discuss this paper Run the related checklist We reply to every message within one business day.
Keep reading

Related papers

azure
public-sector15 pages

Cloud economics in the public sector

Public cloud programmes fail at procurement and governance far more often than at technical migration. This paper examines why and proposes a procurement approach that survives review.

June 28, 2026 · 15 pages · 16 min readRead
purview
public-sector13 pages

The cost of keeping everything

Most agencies have a documented retention schedule and delete nothing. The bill arrives with the next records request.

May 10, 2026 · 13 pages · 14 min readRead
Get In Touch

Tell us what you're trying to fix

Describe the situation in your own words.

Please enter your first name.
Please enter your last name.
Please enter a valid email address.
Please enter your company name.
Please choose an option.
Please add a short description.

We reply to every message within one business day.