Solutions / SOX ITGC
SOX Section 404 IT General Controls, on Microsoft 365.
External auditors testing Section 404 IT General Controls come with a fixed checklist: who can approve production changes, who has access to financial systems, when access was reviewed, and where the audit trail is. Identra configures Privileged Identity Management, access reviews, Sentinel workbooks and Purview audit retention so the ITGC evidence pack for financial-application access is generated from live tenant data, not hand-assembled the week before the walkthrough.
- Regulation
- Sarbanes-Oxley Act Section 404
- Framework alignment
- COBIT 2019, COSO 2013
- License footprint
- M365 E3 or E5 + Entra P2 for PIM
- Delivery
- Fixed scope, fixed price
01 / What we configure
Four ITGC control domains, mapped to Microsoft 365 features.
- 01
Privileged access management
Global Administrator, Application Administrator, and Exchange Administrator roles moved from permanent assignments to just-in-time PIM activations with approval, MFA, and time-boxed access. Break-glass accounts documented, monitored, and reviewed monthly.
PIMJITBreak-glass - 02
Access review evidence
Quarterly access reviews on every Entra group that reaches an in-scope financial system (ERP, close software, treasury). Reviewer decisions and reviewer identity captured in the audit trail. Attestation exports formatted for the auditor working-paper template.
Access reviewsAttestationWorking papers - 03
Change audit trail
Sentinel workbook produces the ITGC change register for privileged role additions, Conditional Access policy edits, application consent grants, and DLP rule changes. Change ticket reference required in the associated Azure DevOps or ServiceNow workflow.
SentinelChange registerTicket linkage - 04
Segregation of duties
Entra role assignments audited against SoD conflict rules (developer + approver, requester + reviewer, admin + auditor). Conflicts flagged during PIM activation. Quarterly SoD report for the internal audit team.
SoDPIMInternal audit
02 / What it looks like
Three engagements, same SOX ITGC ask.
Different industries, different ERP stacks, same auditor questions on Microsoft 365 posture.
IT Compliance Manager at a US-listed manufacturer
Situation. External auditor deficiency last cycle: no evidence that Global Administrator access was reviewed. Compliance team hand-drafted a spreadsheet after the fact and the auditor accepted it with a management-letter comment.
Outcome. PIM turned on for every privileged Entra role. Sentinel workbook produces the review evidence quarterly. Deficiency cleared at the next audit cycle without management-letter follow-up.
CISO at a NYSE-listed financial services firm
Situation. Auditor asked for a full change log on Conditional Access policies over the fiscal year. Available data went back 90 days. Compliance had to reconstruct the earlier 9 months from meeting notes.
Outcome. Purview audit retention set to the fiscal-year full window. Sentinel workbook filters CA policy edits and pairs each with the change ticket reference. Change register exports as a CSV the auditor can filter directly.
Controller at a NASDAQ-listed SaaS company
Situation. ERP admin role held by two members of the finance team who also had approval authority on journal entries above threshold. Auditor flagged the SoD conflict at Q3 review.
Outcome. PIM approvers configured so that ERP admin activation requires approval from a person outside the finance chain. SoD report added to the audit committee monthly pack. Conflict cleared before year-end.
03 / Frequently asked
What buyers ask first.
- Does SOX apply to us?
- SOX applies to companies with equity registered under Section 12 of the Securities Exchange Act (public companies on US exchanges) and to their consolidated subsidiaries. Section 404 requires management to assess and the auditor to attest to the effectiveness of internal control over financial reporting, which in modern audits explicitly includes IT General Controls over systems that store, process, or report financial data.
- What are ITGC?
- IT General Controls are the enterprise-wide controls that govern the systems supporting financial reporting: access provisioning and de-provisioning, privileged access, change management, segregation of duties, backup and recovery, and system operations. ITGC differ from application-level controls (which live inside the ERP) because ITGC operate across all financial systems. When ITGC fail, application controls cannot be relied on.
- Which Microsoft 365 features are in-scope for SOX?
- Any Microsoft 365 feature that stores, processes, or protects financial data or the access to it. Typically Entra ID (identity and access to the ERP), Exchange (financial correspondence), SharePoint and Teams (financial workpapers), Purview (audit retention on financial data), and Defender (endpoint protection on finance devices). Feature scope is set during the year-end scoping exercise with the external auditor.
- What is the auditor going to actually ask for?
- Six evidence buckets. Access provisioning tickets tied to the joiner workflow, privileged access activation logs from PIM, access review completions per financial-system-scoped group, change register with ticket linkage for CA and DLP edits, break-glass account use log, and the SoD conflict report. Identra generates the six exports as a bound quarterly pack.
- How long does a SOX ITGC engagement take?
- First-year setup runs 10 to 14 weeks: 3 weeks to scope with the external auditor, 6 weeks to configure PIM and access reviews, 3 weeks to build the Sentinel workbook and evidence-pack export. Subsequent years require 2 to 3 weeks of adjustment work at the start of each fiscal year to align scope changes.
04 / Related
Where this fits.
Identity
Microsoft Entra consulting
Conditional Access, PIM, ID Protection turned on to enforcement, with a documented handover.
Framework
NIST 800-53 Rev 5 mapping
Control-by-control mapping of Microsoft 365 tenant settings to 800-53 control families.
Industry
Financial services
Microsoft 365 configuration for banking, insurance, asset management, and fintech.