---
name: IRAP Control Evidence
description: Produce control-by-control IRAP assessment evidence for in-scope Microsoft 365 security controls, read-only, mapped to the ISM.
lastReviewed: 2026-09-30
---

# IRAP Control Evidence

> **TL;DR:** This skill inspects your Microsoft 365 tenant read-only and produces structured, control-by-control evidence that supports an IRAP assessment against the Australian Government Information Security Manual.

## What does control-by-control IRAP evidence for Microsoft 365 mean?

Control-by-control IRAP evidence for Microsoft 365 is a per-control record of how your tenant is configured, gathered so an endorsed IRAP assessor can independently assess it against the Australian Government Information Security Manual. The Australian Cyber Security Centre governs IRAP, and this skill reads Microsoft Entra Conditional Access settings without changing them.

Microsoft's own IRAP assessments cover Microsoft as a cloud service provider. They do not assess your tenant configuration, so you remain responsible for engaging an assessor to evaluate your implementation as deployed.

## When should you run this skill?

Run this skill when you need read-only evidence of Microsoft Entra Conditional Access and authentication strength settings ahead of an IRAP assessment. It suits teams seeking approval to operate in line with the ISM, because you remain responsible for engaging an assessor and for controls within your own organisation.

- "We have an IRAP assessment booked and need evidence for our Microsoft Entra controls."
- "Prepare control-by-control evidence before our assessor arrives."
- "Show me whether our Conditional Access policies require phishing-resistant MFA."
- "Identify gaps between our tenant and the control set our assessor gave us."

## How this skill works, step by step

1. Confirm the assessment scope and the control set your assessor is using, then list the in-scope controls to be evidenced.
2. Read Microsoft Entra Conditional Access policies, including the grant controls each policy uses.
3. Identify which policies use the **Require authentication strength** control and which built-in or custom authentication strength each one applies: Multifactor authentication strength, Passwordless MFA strength or Phishing-resistant MFA strength.
4. Record the observed value, the ISM control identifier your assessor supplied, and the source of each evidence item.
5. Compare each observed value against the expected configuration for the target classification level.
6. Compile the findings into a control-by-control evidence table and mark any control that cannot be evidenced read-only for manual attestation.

## Output format

The skill emits one row per in-scope control. The ISM control identifier comes from your assessor's control set, not from this skill.

| ISM control | Microsoft 365 source | Observed state | Expected (target level) | Evidence status |
| --- | --- | --- | --- | --- |
| Supplied by assessor | Microsoft Entra Conditional Access | Policy grants access with MFA | Per assessor's control set | Met, Partially met or Not met |
| Supplied by assessor | Microsoft Entra authentication strengths | Multifactor authentication strength applied | Phishing-resistant MFA strength required | Not met |

A short summary accompanies the table:

- Total in-scope controls evidenced and the count Met, Partially met, and Not met.
- The controls requiring remediation before authorisation.
- The target classification level the evidence was assessed against.
- A note on any control that could not be evidenced read-only and needs manual attestation.

## Licensing and permissions

- Conditional Access, and therefore authentication strengths, requires a Microsoft Entra ID P1 licence.
- Grant the account running the skill read-only access to Conditional Access configuration only. Confirm the exact role and Microsoft Graph permission on Microsoft Learn before granting it.

## Scope and safety

This skill is read-only by default and changes no tenant configuration.

This skill does NOT:

- Modify, create, or delete any policy or setting.
- Issue or grant an IRAP authorisation or replace an endorsed IRAP assessor, who provides the independent assessment.
- Export or copy customer content or message bodies; it reads configuration metadata only.
- Evaluate on-premises or non-Microsoft systems outside the Microsoft 365 tenant.

## Related skills

- [ISM Control Pack](/purview/ism-control-pack): run before this to map tenant configuration to ISM controls.
- [Audit Log Retention and Coverage Validator](/purview/audit-log-retention-validator): run before this to confirm audit retention meets IRAP needs.
- [Sentinel Data Connector Coverage](/purview/sentinel-data-connector-coverage): run alongside this to find log source gaps that weaken IRAP evidence.
- [IRAP Evidence Trail](/purview/irap-evidence-trail): run after this to organise governance documents by ISM family.
- [Australian Compliance for Microsoft 365 Copilot and AI](/purview/australian-copilot-compliance): pillar page on Australian compliance evidence, including IRAP.

## Sources

Reviewed 2026-09-30: removed ISM control identifiers, licence, role, Microsoft Graph permission, Essential Eight, risk-scoring and Purview, Defender and OFFICIAL: Sensitive references that no cited page supports; replaced a broken Microsoft Learn link; narrowed the scope to Microsoft Entra Conditional Access.

- [Australian Government Information Security Registered Assessor Program (IRAP), Microsoft Learn](https://learn.microsoft.com/compliance/regulatory/offering-irap-australia) - ACSC governance of IRAP, endorsed assessors, PROTECTED classification, and the customer's responsibility to engage an assessor.
- [Conditional Access authentication strengths, Microsoft Learn](https://learn.microsoft.com/entra/identity/authentication/concept-authentication-strengths) - Microsoft Entra ID P1 requirement, the Require authentication strength control and the three built-in strengths.
