Microsoft Entra ID Governance
Governance

Externally determine the approval requirements for an access package using custom extensions

In brief

The entitlement management dynamic approval article received spelling corrections covering custom extensions, Logic Apps, approval setup, and HTTP trigger configuration.

What Entra admins need to know

The guidance is clearer for administrators; no action is required.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

In entitlement management, approvers for access package requests can either be directly assigned, or determined dynamically. Entitlement management natively supports dynamically determining approvers such as the requestors manager, their second-level manager, or a sponsor from a connected organization:

:::image type="content" source="media/entitlement-management-dynamic-approval/native-support-diagram.png" alt-text="Screenshot of native support of approvers in Entitlement management." lightbox="media/entitlement-management-dynamic-approval/native-support-diagram.png":::

With the introduction of custom extensions calling out to Azure Logic Apps you are now able to dynamically determine approval requirements for each access package assignment request based on your organizations specific business logic. The access package assignment request process will pause until your business logic hosted in Azure Logic Apps returns a approval stage which will then be leveraged in the subequentsubsequent approval process via the My Access portal. For example, if access requests must be approved by the department head of the person requesting an access package this feature allows you to query an external system, such as your human resources (HR) system, to on-the-fly look up the current department head and assign them as the approver for the given access request.

:::image type="content" source="media/entitlement-management-dynamic-approval/dynamic-extensibility-diagram.png" alt-text="Screenshot of example of determining approvers using custom extensions." lightbox="media/entitlement-management-dynamic-approval/dynamic-extensibility-diagram.png":::

Prerequisites

Create the custom extension and Azure Logic App

:::image type="content" source="media/entitlement-management-dynamic-approval/custom-extension-approval-stage.png" alt-text="Screenshot of the custom extension approval stage option.":::
  1. On the Details page, choose a subscription, resource group, and name for the logic app being created. Once you've entered this information, select Create a logic app. Once the logic app is created, select Next.

  2. On the Review + create page, make sure all your details are correct, then select Create.

Reference the custom extension in an access package assignment policy

  1. On the access package overview page, select Policies, and select the policy to edit. :::image type="content" source="media/entitlement-management-dynamic-approval/access-package-policies-list.png" alt-text="Screenshot of the policies list for an access package.":::
  2. On the Edit policy page under Requests, set the Require approval box to yes, and you're able to add your custom extension as an approver. The example here shows the custom extension being used as the first approver. :::image type="content" source="media/entitlement-management-dynamic-approval/custom-extension-approver.png" alt-text="Screenshot of the custom extension as first approver in access package policy.":::
  3. Select Update.

Once updated, you can go to the edited policy, and confirm the change by selecting Approval stage details.

:::image type="content" source="media/entitlement-management-dynamic-approval/access-package-approval-stage-details.png" alt-text="Screenshot of edited approval stage details.":::

Set logic app assigned identity and assign its role

:::image type="content" source="media/entitlement-management-dynamic-approval/enable-logic-app-identity.png" alt-text="Screenshot of enabling logic app system assigned managed identity.":::
  1. Select Save.

  2. Back in the Microsoft Entra admin center as at least the role of Catalog owner, go to the catalog where you created the custom extension, and select Roles and administrators.

  3. On the roles and administrators page, select Add access package assignment manager, and select the logic app you created. :::image type="content" source="media/entitlement-management-dynamic-approval/add-logic-app-role.png" alt-text="Screenshot of adding logic app as access package assignment manager for a catalog.":::

Configure the logic app and corresponding business logic

- Authentication Type: Managed identity
- Managed Identity: System-assigned managed identity
- Audience: https://graph.microsoft.com
  1. Under HTTP Settings, disable Asynchronous Pattern. :::image type="content" source="media/entitlement-management-dynamic-approval/disable-asynchronous-pattern.png" alt-text="Screenshot of disabling asynchronous pattern in a logic app http call.":::
  2. After you've made changes to the HTTP trigger, select Save.

Add business logic to the logic app

  1. On the requests page, select the request you want to view details of and confirm that the access package was successfully delivered. :::image type="content" source="media/entitlement-management-dynamic-approval/access-package-request-details.png" alt-text="viewing the details of the request for the access package.":::

HTTP action example

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…