Entra IDHow-to

Access reviews and entitlement management basics: a starter plan for Entra ID Governance

How access reviews and entitlement management fit together in Microsoft Entra ID Governance: licensing, creating reviews, catalogs and access packages, and a starter plan you can run this quarter.

Most tenants grow access the same way: someone adds a user to a group, invites a guest or assigns an app, and nobody ever takes it away. Microsoft Entra ID Governance gives you two tools to fix that. Access reviews ask the right person whether access is still needed, and entitlement management packages access so that it's requested, approved and expires on its own. In this post I'll cover what both do, how to set them up, and a small starter plan that delivers results without a six-month project.

How this guide is organised: Prerequisites → Step-by-step → A practical starter plan → Verify → Tips & gotchasFlow diagram of the article's sections in reading order: 1. Prerequisites. 2. Step-by-step (3 steps: Understand where each review lives; Create your first review; Build an access package). 3. A practical starter plan. 4. Verify. 5. Tips & gotchas. Toolbox: New-MgIdentityGovernanceAccessReviewDefinition, New-MgEntitlementManagementAccessPackage, Access Reviews › Settings, AccessReview.ReadWrite.All.1Prerequisites2Step-by-step3A practicalstarter plan4Verify5Tips & gotchas1Understand where eachreview lives2Create your first review3Build an access packageTOOLBOXNew-MgIdentityGovernanceAccessRev…New-MgEntitlementManagementAccess…Access Reviews › SettingsAccessReview.ReadWrite.AllHow this guide is organised: Prerequisites → Step-by-step → A practical starter plan → Verify → Tips & gotchasFlow diagram of the article's sections in reading order: 1. Prerequisites. 2. Step-by-step (3 steps: Understand where each review lives; Create your first review; Build an access package). 3. A practical starter plan. 4. Verify. 5. Tips & gotchas. Toolbox: New-MgIdentityGovernanceAccessReviewDefinition, New-MgEntitlementManagementAccessPackage, Access Reviews › Settings, AccessReview.ReadWrite.All.1Prerequisites2Step-by-step1Understand where each review lives2Create your first review3Build an access package3A practical starter plan4Verify5Tips & gotchasTOOLBOXNew-MgIdentityGovernanceAccessReviewDefiniti…New-MgEntitlementManagementAccessPackageAccess Reviews › SettingsAccessReview.ReadWrite.All
At a glance: how this guide is organised · 3 steps · 4 key settings and tools

Prerequisites#

  • Licensing: both features are licensed through Microsoft Entra ID Governance (also in Microsoft Entra Suite). Capabilities that were generally available in Entra ID P2 keep working with P2, but newer ones such as inactive-user reviews, machine-learning recommendations, auto-assignment policies, custom extensions and Verified ID checks need Governance, and Microsoft has said no new governance features will be added to the P2 SKU. Licences aren't assigned per user, but you need enough to cover every member user in scope plus reviewers and approvers. Guests are billed per monthly active user through an Azure subscription.
  • Roles: Identity Governance Administrator creates reviews and access packages; reviews of Microsoft Entra roles are created in PIM by a Privileged Role Administrator; group owners can review their own groups once you enable the delegation setting below.
  • Clean data: manager attributes populated, groups with owners, apps integrated with Entra ID. Reviews and approvals route to these people, and empty attributes become fallback-reviewer work.

Step 1: Understand where each review lives#

What you reviewWhere you create itReviewers decide in
Security and Microsoft 365 group members, Teams, guestsID Governance › Access ReviewsMy Access portal
Users assigned to an enterprise appID Governance › Access ReviewsMy Access portal
Microsoft Entra roles and Azure resource rolesPrivileged Identity ManagementMicrosoft Entra admin center
Access package assignmentsEntitlement management (per access package policy)My Access portal

Reviewers can be group owners, selected users or groups, the users themselves or their managers, with a fallback reviewer for users without a manager or groups without an owner.

Step 2: Create your first review#

  1. Go to ID Governance › Access Reviews › New access review.
  2. Under Select what to review, choose Teams + Groups or Applications. For groups, All Microsoft 365 groups with guest users is the quickest win: one recurring series covering guests in every team, with exclusions. Otherwise pick specific groups; each selected group or app becomes its own review.
  3. Scope it to Guest users only or Everyone. Group reviews can also target only Inactive users, with a tenant-level threshold of up to 730 days (Governance licence).
  4. On the Reviews tab, pick reviewers, a fallback, the duration in days, the start date and how the series ends.
  5. On Settings, decide Auto apply results to resource and If reviewers don't respond (No change, Remove access, Approve access or Take recommendations). Guest-only reviews can also block a denied guest for 30 days and then delete the account. Turn on the decision helpers No sign-in within 30 days and, with Governance, User-to-Group Affiliation, plus justification, email notifications and reminders.
  6. Name the review and create it. Reviewers receive an email shortly after it starts.

Watch out: Remove access or Take recommendations combined with auto-apply can strip everyone's access if reviewers simply ignore the email. Start recurring reviews with No change, confirm reviewers engage, then tighten.

Multi-stage reviews#

Tick Multi-stage review to chain two or three sets of reviewers, each with its own duration. You choose which reviewees move on (approved, denied, not reviewed, marked "don't know", or all) and whether later stages see earlier decisions. A common pattern is manager first, then resource owner for the approved users. B2B direct connect users in shared channels only appear in single-stage reviews.

Delegate to group owners#

Under ID Governance › Access Reviews › Settings, set Group owners can create and manage access reviews for groups they own to Yes when you want owners to self-serve. The default is No.

Step 3: Build an access package#

Entitlement management works with three objects. A catalog is a container of resources and packages used for delegation; a catalog owner can only add resources they own, while an administrator can add any. An access package bundles resource roles: membership of security groups, Microsoft 365 groups or Teams, assignment to enterprise applications, SharePoint Online sites, and in preview Microsoft Entra roles and PIM for Groups eligibility. A policy defines who can request, how approval works and when the assignment expires; a package can have several, for example one for employees and one for a partner's connected organization.

  1. Go to ID Governance › Entitlement management › Access packages › New access package, name it and pick or create a catalog. A package can't move to another catalog later.
  2. On Resource roles, add the groups, apps and sites with the role (member, owner, a SharePoint permission level, an app role).
  3. On Requests, choose who can get access: specific users and groups, all members excluding guests, all users including guests, users from specific or all connected organizations, or None (administrator direct assignments only). Then set approval: requestor justification, one to three stages, manager or specific approvers with fallbacks, the number of days a decision can take before the request is denied automatically, and optional alternate approvers.
  4. On Requestor information, add questions the requester must answer; approvers see the answers.
  5. On Lifecycle, set expiry on a date, after a number of days (0 to 3,660) or hours, or never; whether users can extend and whether extensions need approval; and whether to require an access review of the package.
  6. Create it. Leave Hidden at No so it appears in the My Access portal, or hide it and share the direct link.

Approved external requesters are created as guests without an invitation email, and by default the guest account is blocked and then deleted once its last assignment expires. That's the lifecycle people spend months building by hand.

A practical starter plan#

  1. Month 1: one quarterly review series, All Microsoft 365 groups with guest users, group owners as reviewers with a governance team as fallback, No change on no response, recommendations on. Fix the groups with no owners it exposes.
  2. Month 2: move two or three high-value groups (finance shares, admin tool access) into a catalog and an access package with manager approval and 180-day expiry. Replace ad hoc group adds with the request link.
  3. Month 3: add a PIM review of Global Administrator and a semi-annual self-review for your business-critical app. Switch the guest review to Remove access with auto-apply once reviewers respond reliably.

Verify#

  • The review shows progress on its Overview and each decision, reviewer and recommendation under Results. After the end date the status moves through Applying to Applied, and denied users leave the group within minutes.
  • Audit logs record who applied decisions and who approved requests.
  • Request an access package yourself from the My Access portal: the request appears under the package's Requests, the approver gets the email, and after approval the assignment and the group membership show up.

Tips & gotchas#

  • A review snapshots access when each instance starts; changes during the review appear in the next recurrence.
  • Nested groups are flattened in group reviews, and a denied user is removed only from direct membership.
  • Only the group owners present when the instance starts are reviewers.
  • Guests invited as reviewers must redeem their invitation before they receive review emails.
  • Objects in a restricted management administrative unit can't be governed with access reviews.
  • Everything is scriptable: New-MgIdentityGovernanceAccessReviewDefinition and New-MgEntitlementManagementAccessPackage in the Microsoft Graph PowerShell SDK, with the AccessReview.ReadWrite.All and EntitlementManagement.ReadWrite.All scopes.

References#

Written and checked against current Microsoft Learn documentation. Test changes with a pilot group before rolling them out to everyone, and if an admin center path has moved since, search for the setting name instead.

Spotted a mistake, or did this fix work differently for you? Email me or message me on LinkedIn — corrections are credited in the article.

OE
Written by

Omer Eltayeb

Independent Microsoft Intune consultant in Cairo, Egypt, former Microsoft Cloud Solutions Architect, Microsoft Certified Trainer and Microsoft Innovative Educator Expert (2024–26) and Microsoft Elevate Educator Expert (2026–27). I share practical, step-by-step guides, study plans, scripts and toolkits for Microsoft Intune, Microsoft Entra ID, Microsoft Defender and Exchange Online with the community.

Microsoft Certified Trainer (MCT) 2026Microsoft Innovative Educator Expert 2025–2026Microsoft Elevate Educator Expert 2026–2027ISC2 Certified Information Systems Security Professional (CISSP)Microsoft 365 Certified: Enterprise Administrator Expert (MS-102)