Example, read only. A sample account that shows what finished CMMC looks like.

← Back to the 15 safeguards
AC · Access ControlMET

Safeguard 1 of 15 · AC.L1-b.1.i

AC.L1-3.1.1 · FAR 52.204-21 (b)(1)(i) · NIST SP 800-171 3.1.1

Authorized Access Control

Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems)

What it means

Only people you've approved can log in to systems that handle government contract information.

Why it matters

If a former employee still has a login, or a vendor has access they no longer need, that's a finding. Primes will ask you to prove you actively manage who has access.

How to do it, Microsoft 365

  1. 1Go to admin.microsoft.com (Microsoft 365 admin center)
  2. 2Click Users → Active users
  3. 3Make sure the visible columns include Display Name, Username, and Status
  4. 4Take a full-window screenshot

Capture: Screenshot of the Active users list showing every account on your tenant. If you have more than 20 users, also export as CSV and upload both files.

The proof on file

  • quarterly-access-review-q2.xlsxReviewed, sufficient

Every file is checked by Charlie the moment it is uploaded, so a gap is caught on the spot, not at the assessment.

The narrative on file

Only the five named Cedar Ridge staff who work federal jobs have accounts in the Federal Programs tenant. Accounts are created in Microsoft Entra ID by the owner, reviewed each quarter, and disabled the same day a person leaves. Shop floor machinists without a federal role have no access to this tenant.

You answer in plain English; Charlie writes the official narrative for your System Security Plan.

What makes it pass

  • Screenshot or export shows the FULL list of authorized users (not a partial view)
  • Each user has a Display Name and Username/Email visible
  • A Status column (Active / Enabled / Authorized) is visible for every account
  • The capture date is visible (system clock in screenshot OR file metadata)
  • If using the manual roster: every row signed and dated by the owner

Assessment objectives, NIST SP 800-171A

[a] Authorized users are identified
MET
[b] Processes acting on behalf of authorized users are identified
MET
[c] Devices (and other systems) authorized to connect are identified
MET
[d] System access is limited to authorized users
MET
[e] System access is limited to processes acting on behalf of authorized users
MET
[f] System access is limited to authorized devices (including other systems)
MET

This is one of 15

Answer in plain English, drop the proof, confirm it MET.

Cedar Ridge Machine Works, LLC walked all 15 the same way. The platform explains each one in plain English, tells you exactly what to grab, checks it, and writes the paperwork, and you confirm each one MET. The self assessment stays your act. Start free, or book a call.