Most tenants grow access the same way: someone adds a user to a group, invites a guest or assigns an app, and nobody ever takes it away. Microsoft Entra ID Governance gives you two tools to fix that. Access reviews ask the right person whether access is still needed, and entitlement management packages access so that it's requested, approved and expires on its own. In this post I'll cover what both do, how to set them up, and a small starter plan that delivers results without a six-month project.
Prerequisites#
- Licensing: both features are licensed through Microsoft Entra ID Governance (also in Microsoft Entra Suite). Capabilities that were generally available in Entra ID P2 keep working with P2, but newer ones such as inactive-user reviews, machine-learning recommendations, auto-assignment policies, custom extensions and Verified ID checks need Governance, and Microsoft has said no new governance features will be added to the P2 SKU. Licences aren't assigned per user, but you need enough to cover every member user in scope plus reviewers and approvers. Guests are billed per monthly active user through an Azure subscription.
- Roles: Identity Governance Administrator creates reviews and access packages; reviews of Microsoft Entra roles are created in PIM by a Privileged Role Administrator; group owners can review their own groups once you enable the delegation setting below.
- Clean data: manager attributes populated, groups with owners, apps integrated with Entra ID. Reviews and approvals route to these people, and empty attributes become fallback-reviewer work.
Step 1: Understand where each review lives#
| What you review | Where you create it | Reviewers decide in |
|---|---|---|
| Security and Microsoft 365 group members, Teams, guests | ID Governance › Access Reviews | My Access portal |
| Users assigned to an enterprise app | ID Governance › Access Reviews | My Access portal |
| Microsoft Entra roles and Azure resource roles | Privileged Identity Management | Microsoft Entra admin center |
| Access package assignments | Entitlement management (per access package policy) | My Access portal |
Reviewers can be group owners, selected users or groups, the users themselves or their managers, with a fallback reviewer for users without a manager or groups without an owner.
Step 2: Create your first review#
- Go to ID Governance › Access Reviews › New access review.
- Under Select what to review, choose Teams + Groups or Applications. For groups, All Microsoft 365 groups with guest users is the quickest win: one recurring series covering guests in every team, with exclusions. Otherwise pick specific groups; each selected group or app becomes its own review.
- Scope it to Guest users only or Everyone. Group reviews can also target only Inactive users, with a tenant-level threshold of up to 730 days (Governance licence).
- On the Reviews tab, pick reviewers, a fallback, the duration in days, the start date and how the series ends.
- On Settings, decide Auto apply results to resource and If reviewers don't respond (No change, Remove access, Approve access or Take recommendations). Guest-only reviews can also block a denied guest for 30 days and then delete the account. Turn on the decision helpers No sign-in within 30 days and, with Governance, User-to-Group Affiliation, plus justification, email notifications and reminders.
- Name the review and create it. Reviewers receive an email shortly after it starts.
Watch out: Remove access or Take recommendations combined with auto-apply can strip everyone's access if reviewers simply ignore the email. Start recurring reviews with No change, confirm reviewers engage, then tighten.
Multi-stage reviews#
Tick Multi-stage review to chain two or three sets of reviewers, each with its own duration. You choose which reviewees move on (approved, denied, not reviewed, marked "don't know", or all) and whether later stages see earlier decisions. A common pattern is manager first, then resource owner for the approved users. B2B direct connect users in shared channels only appear in single-stage reviews.
Delegate to group owners#
Under ID Governance › Access Reviews › Settings, set Group owners can create and manage access reviews for groups they own to Yes when you want owners to self-serve. The default is No.
Step 3: Build an access package#
Entitlement management works with three objects. A catalog is a container of resources and packages used for delegation; a catalog owner can only add resources they own, while an administrator can add any. An access package bundles resource roles: membership of security groups, Microsoft 365 groups or Teams, assignment to enterprise applications, SharePoint Online sites, and in preview Microsoft Entra roles and PIM for Groups eligibility. A policy defines who can request, how approval works and when the assignment expires; a package can have several, for example one for employees and one for a partner's connected organization.
- Go to ID Governance › Entitlement management › Access packages › New access package, name it and pick or create a catalog. A package can't move to another catalog later.
- On Resource roles, add the groups, apps and sites with the role (member, owner, a SharePoint permission level, an app role).
- On Requests, choose who can get access: specific users and groups, all members excluding guests, all users including guests, users from specific or all connected organizations, or None (administrator direct assignments only). Then set approval: requestor justification, one to three stages, manager or specific approvers with fallbacks, the number of days a decision can take before the request is denied automatically, and optional alternate approvers.
- On Requestor information, add questions the requester must answer; approvers see the answers.
- On Lifecycle, set expiry on a date, after a number of days (0 to 3,660) or hours, or never; whether users can extend and whether extensions need approval; and whether to require an access review of the package.
- Create it. Leave Hidden at No so it appears in the My Access portal, or hide it and share the direct link.
Approved external requesters are created as guests without an invitation email, and by default the guest account is blocked and then deleted once its last assignment expires. That's the lifecycle people spend months building by hand.
A practical starter plan#
- Month 1: one quarterly review series, All Microsoft 365 groups with guest users, group owners as reviewers with a governance team as fallback, No change on no response, recommendations on. Fix the groups with no owners it exposes.
- Month 2: move two or three high-value groups (finance shares, admin tool access) into a catalog and an access package with manager approval and 180-day expiry. Replace ad hoc group adds with the request link.
- Month 3: add a PIM review of Global Administrator and a semi-annual self-review for your business-critical app. Switch the guest review to Remove access with auto-apply once reviewers respond reliably.
Verify#
- The review shows progress on its Overview and each decision, reviewer and recommendation under Results. After the end date the status moves through Applying to Applied, and denied users leave the group within minutes.
- Audit logs record who applied decisions and who approved requests.
- Request an access package yourself from the My Access portal: the request appears under the package's Requests, the approver gets the email, and after approval the assignment and the group membership show up.
Tips & gotchas#
- A review snapshots access when each instance starts; changes during the review appear in the next recurrence.
- Nested groups are flattened in group reviews, and a denied user is removed only from direct membership.
- Only the group owners present when the instance starts are reviewers.
- Guests invited as reviewers must redeem their invitation before they receive review emails.
- Objects in a restricted management administrative unit can't be governed with access reviews.
- Everything is scriptable:
New-MgIdentityGovernanceAccessReviewDefinitionandNew-MgEntitlementManagementAccessPackagein the Microsoft Graph PowerShell SDK, with theAccessReview.ReadWrite.AllandEntitlementManagement.ReadWrite.Allscopes.