All Posts

How Microsoft Entra ID Supports SACS-210 Access Controls for Saudi SMEs

Last Updated August 20, 2026
Microsoft Entra ID for SACS-210 access controls including IAM MFA SSO and access evidence for Saudi SMEs

Microsoft Entra ID can help Saudi suppliers implement several of the identity and access-control requirements in SACS-210, particularly centralized identity management, unique user accounts, MFA, Single Sign-On and access evidence.

But Entra ID is not a shortcut to SACS-210 compliance.

The standard defines security requirements. Microsoft Entra provides technical capabilities that can support some of those requirements when they are correctly licensed, configured and operated.

If you first need the vendor-neutral requirements themselves, start with our SACS-210 Access Control guide.

Quick Answer: What Entra ID Can and Cannot Do for SACS-210

For a small Saudi supplier, Microsoft Entra ID can provide a strong foundation for:

  • centralized user identities;
  • unique user accounts;
  • MFA enforcement;
  • Conditional Access;
  • SSO to integrated applications;
  • role and group management;
  • sign-in and audit evidence; and
  • technical account deprovisioning.

However, Entra ID does not by itself cover every requirement around access management.

The organization still needs business approvals, policies, HR onboarding and offboarding processes, annual access-review evidence, notification of externally managed proponent credentials, and secure authentication for technology assets that are not integrated with Entra.

The correct model is:

SACS-210 Requirement → Entra Capability → Limitation → Evidence

Microsoft Entra ID SACS-210 model from requirement to Entra capability limitation and implementation evidence
Microsoft Entra ID can support a SACS-210 requirement, but scope, licensing and systems outside Entra must still be considered before collecting implementation evidence.

SACS-210 to Microsoft Entra ID Mapping

SACS-210Entra ID SupportKey Limitation
TPC1.9 Centralized IAMUsers, groups, roles and Enterprise AppsOnly covers systems and apps actually managed or integrated with Entra
TPC1.10 Unique credentialsIndividual Entra user identitiesShared and unmanaged accounts still need governance
TPC1.11 Password/authentication rulesCloud password policy, Password Protection and MFAEntra cloud password rules do not exactly reproduce SACS-210’s 8–64 and composition rules
TPC1.12 MFAConditional Access and Entra MFAPolicies must cover all five applicable SACS-210 scenarios
TPC1.13 SSO + MFAEnterprise Apps + SSO + Conditional AccessApplications must actually be integrated and MFA enforced at authentication
TPC1.14 Annual access reviewManual exports; Access Reviews with appropriate higher licensingP1 alone does not provide automated Access Reviews
TPC1.15 Asset authenticationEntra authentication for integrated applications and assetsDoes not automatically cover firewalls, routers or every local technology asset
TPC1.4 OffboardingDisable account, remove assignments, revoke sessionsHR and documented offboarding remain separate processes
TPC1.33 Proponent credentialsInternal deprovisioning evidenceEntra cannot replace required notification to the proponent

This is why Microsoft Entra should be treated as an implementation platform, not as the definition of the SACS-210 controls.

TPC1.9–TPC1.10: Centralized Identity and Unique Users

TPC1.9 requires user authorizations to systems and applications to be managed through a centralized corporate IAM solution.

Microsoft Entra ID can support this through centralized users, groups, directory roles and Enterprise Applications.

For a small organization, a practical structure is:

User → Group or Role → Application/Resource → Approved Access

This is stronger than administering separate user accounts independently in every SaaS platform.

TPC1.10 also requires unique authentication credentials. Individual Entra accounts support that objective well, provided employees are not bypassing the model through shared interactive accounts or unmanaged credentials.

The business approval itself should still be documented outside or alongside Entra. An Entra group membership shows what access exists; it may not prove why access was approved.

TPC1.11: The Microsoft Entra Password Policy Limitation

This is an important limitation that suppliers should understand.

SACS-210 TPC1.11 specifies passwords or passphrases between 8 and 64 characters and lists lowercase, uppercase, numbers and special characters among its password-management rules.

Microsoft’s current cloud password policy is different.

For passwords created or changed directly in Microsoft Entra ID, Microsoft documents a minimum of 8 characters and a maximum of 256 characters. It also applies its own complexity model rather than allowing administrators to configure an exact SACS-210-style 8–64 policy.

Therefore, do not claim:

“Microsoft Entra ID P1 enforces the exact SACS-210 password policy.”

It does not.

In hybrid environments, an on-premises password policy can affect synchronized identities, and Microsoft documents circumstances where the on-premises policy takes precedence for length and complexity.

For cloud-only environments, the correct approach is to document the platform configuration and limitation accurately rather than creating evidence that implies an exact technical match that does not exist.

TPC1.12–TPC1.13: Conditional Access, MFA and SSO

This is where Microsoft Entra ID P1 becomes particularly useful.

SACS-210 TPC1.12 requires MFA for:

  1. remote access, including Internet access;
  2. cloud services;
  3. company email through web or mobile devices;
  4. Internet-facing applications; and
  5. privileged accounts.

Conditional Access allows an organization to create policies that target users, applications and authentication conditions and require MFA. Microsoft states that Conditional Access requires at least Microsoft Entra ID P1; Microsoft 365 Business Premium includes access to Conditional Access.

The key point is scope.

A supplier should not build one administrator-only MFA policy and consider TPC1.12 complete. Policies should be reviewed against all five applicable SACS-210 scenarios.

TPC1.13 permits SSO when MFA is applied on initial login. Microsoft Entra can act as the identity provider for integrated Enterprise Applications and supports several SSO approaches, including SAML and OpenID Connect.

A useful implementation pattern is therefore:

Entra identity → MFA → SSO → assigned application

with evidence showing both the SSO configuration and the authentication controls applied to the relevant users.

Security Defaults vs Entra ID P1

Security Defaults and Conditional Access should not be treated as the same thing.

Microsoft Security Defaults provide a useful baseline and are available without an Entra ID P1 license. However, Microsoft describes Security Defaults as essentially an on/off baseline without the customization available in Conditional Access.

CapabilitySecurity DefaultsEntra ID P1
Basic MFA security baselineYesYes
Custom Conditional Access policiesNoYes
Application/user targetingLimited baselineGranular
Suitable for explicit SACS-210 MFA mappingLimited visibility/controlMuch stronger
Microsoft Entra licensing boundary for SACS-210 showing Security Defaults Entra ID P1 and P2 or ID Governance capabilities
Licensing enables Microsoft Entra capabilities; SACS-210 compliance still depends on correct configuration, operational processes and evidence.

This does not mean Security Defaults are inherently “non-compliant.”

It means Conditional Access gives the organization much better control over how MFA enforcement is mapped to the specific TPC1.12 scenarios and much clearer configuration evidence.

For Saudi SMEs standardizing on Microsoft 365, Microsoft 365 Business Premium includes Microsoft Entra ID P1, including Conditional Access capability.

NHR Alemtithal is a Microsoft CSP Partner, and organizations that decide Business Premium is appropriate for their environment can purchase Microsoft 365 Business Premium from the NHR store.

Licensing enables capabilities; it does not by itself establish SACS-210 compliance.

TPC1.14: Annual Access Reviews and Licensing

TPC1.14 requires user accounts and access rights to be reviewed at least annually.

You do not need Microsoft’s automated Access Reviews feature simply to perform the SACS-210 review.

An organization using Entra ID P1 can export or review:

  • active users;
  • group memberships;
  • application assignments; and
  • privileged roles,

then perform a documented business review and retain the findings, approvals and remediation records.

If the organization wants Microsoft Entra to automate recurring access reviews, licensing changes.

Microsoft’s current documentation places Access Reviews within Microsoft Entra ID Governance, while some access-review scenarios can also operate with Microsoft Entra ID P2. P1 alone should therefore not be presented as including automated Access Reviews.

For a small supplier, a well-controlled manual annual review can be perfectly practical if it produces reliable evidence.

TPC1.15: What Microsoft Entra Does Not Cover

TPC1.15 requires secure authentication for all Third Party technology assets.

Microsoft Entra can help where an application, workstation or service is integrated into the Microsoft identity environment.

But the requirement may also cover technology such as:

  • network firewalls;
  • routers and switches;
  • locally administered appliances;
  • security platforms; and
  • applications that do not authenticate through Entra.

The supplied CCC assessment template itself includes examples such as workstations, Active Directory, on-premises security solutions, network firewalls and network devices when requesting evidence for TPC1.15.

Therefore:

Entra ID can support TPC1.15, but it cannot be treated as proof that every technology asset is securely authenticated.

The supplier still needs an asset-level review.

A Practical Entra ID P1 Baseline for a Small Supplier

For a smaller Microsoft-based environment, a useful implementation baseline is:

  1. Maintain unique Entra identities for employees and contractors.
  2. Review unnecessary shared and default interactive accounts.
  3. Manage access through controlled groups, roles and Enterprise Application assignments.
  4. Build Conditional Access policies covering all applicable TPC1.12 MFA scenarios.
  5. Ensure privileged identities are protected by MFA.
  6. Integrate suitable business applications with Entra SSO.
  7. Connect HR/offboarding events to account disablement, assignment removal and session revocation.
  8. Perform an annual access review, manually if the organization does not license Entra ID Governance or the required higher-tier capability.

Microsoft documents methods for disabling user access and revoking sessions, but these technical actions should be part of a broader documented offboarding process.

For a broader implementation checklist beyond Entra, use the SACS-210 Technical Implementation Checklist.

What Evidence Can Microsoft Entra Produce?

Useful Entra evidence may include:

AreaPractical Evidence
IdentityUser and group records
AuthorizationGroup, role and application assignments
MFAConditional Access policy configuration
AuthenticationSign-in records and authentication results
SSOEnterprise Application and SSO configuration
AdministrationAudit logs showing user, group or role changes
OffboardingAccount disablement and assignment/session-removal records
Access reviewExported review records or native Access Review results where licensed

Microsoft Entra provides sign-in logs for authentication activity and audit logs for changes made to users, groups, applications and other directory resources.

However:

Screenshot ≠ complete compliance evidence.

The assessment model may also require policy, approval, review and remediation evidence. For broader preparation, see the Aramco CCC Audit Readiness Guide.

What Still Must Be Done Outside Microsoft Entra ID?

Several important activities remain outside the identity platform:

Policies and procedures: SACS-210 requires documented governance, not only technical settings.

Business access approvals: Entra can show assignments, but management should be able to demonstrate why access was granted.

HR onboarding and offboarding: Account actions should be linked to formal personnel processes.

TPC1.33 notification: Disabling an internal Entra account does not notify the proponent that externally issued credentials are no longer required.

Non-Entra technology assets: Firewalls, network appliances and other systems may require their own authentication controls.

Annual management review: A user export becomes stronger evidence when responsible managers or asset owners review it and corrective actions are recorded.

This distinction is what prevents a Microsoft deployment from becoming a misleading “compliance checkbox.”

Common Microsoft Entra to SACS-210 Mapping Mistakes

Avoid these five common claims:

  • “Entra ID P1 enforces the exact SACS-210 8–64 password policy.” It does not.
  • “Users are enrolled in MFA, so TPC1.12 is complete.” Enforcement and scope must be verified.
  • “We protect VPN, cloud and admins, so MFA scope is complete.” TPC1.12 also includes web/mobile email and Internet-facing applications.
  • “P1 includes automated Access Reviews.” It does not.
  • “Disabling the Entra account handles all offboarding.” External and proponent-managed credentials may require separate action.

Need Microsoft and SACS-210 Implementation Support?

Organizations that need help translating the SACS-210 requirements into policies, configurations and evidence can review our Aramco CCC Compliance Kit service.

For organizations that need guided technical remediation and implementation across the environment, see our Aramco Cybersecurity Compliance Certificate implementation service.

NHR Alemtithal provides implementation and cybersecurity support. Formal CCC assessment and certification remain the responsibility of an authorized audit firm.

Conclusion

Microsoft Entra ID can be a strong platform for implementing SACS-210 identity and access controls—especially centralized identities, MFA, Conditional Access and SSO.

But the correct question is not:

“Does Entra ID make us SACS-210 compliant?”

It is:

“Which SACS-210 requirements can Entra implement, what are the platform and licensing limitations, and what additional processes and evidence do we still need?”

For many Saudi SMEs, Entra ID P1 or Microsoft 365 Business Premium can provide a practical technical foundation.

The remaining work is to configure it correctly, connect it to business processes, cover systems outside Entra, and retain evidence that demonstrates the controls in operation.

Official Microsoft References

Share this article
Fast-Track Your Compliance

Need help with Aramco CCC Certification?

Get a Free Expert Consultation.

Protected with anti-spam controls.

Our Certified Expertise and Technology Partnerships

We work with leading cybersecurity vendors to deliver reliable solutions tailored for Saudi businesses.

Microsoft
Microsoft
Microsoft CSP Partner
Bitdefender
Bitdefender
Gold Partner
Fortinet
Fortinet
Authorized Partner
Acronis
Acronis
Certified Partner

Ready to Secure Your Business?

Our cybersecurity experts are here to help you achieve compliance and protect your digital assets. Contact us for a free, no-obligation assessment of your cybersecurity needs.

Rapid response commitment
Free initial consultation
Team holding recognized certifications