Microsoft Entra ID Governance
Architecture

Microsoft Entra ID Governance deployment guide to assign employee access

In brief

The documentation updates wording across deployment scenarios, entitlement management, access reviews, separation of duties, birthright assignment, and Logic Apps guidance without changing the described capabilities or procedures.

What Entra admins need to know

No administrator action is required.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Microsoft Entra ID Governance deployment guide to assign employee access

Deployment scenarios are guidance on how to combine and test Microsoft Security products and services. Learn how capabilities work together to improve productivity, strengthen security, and more easily meet compliance and regulatory requirements.

The following products and services appear in this guide:

Use this scenario to help determine the need for Microsoft Entra ID Governance to create and grant access for your organization. Learn how you can simplify the employee experience with automated workflows, access assignments, access reviews, and expiration.

Timelines

Timelines show approximate delivery stage duration and are based on scenario complexity. Times are estimations and vary depending on the environment.

  1. Entitlement management - 1 hour
  2. Auto assignment policy - 1 hour
  3. Custom extensions - 2 hours
  4. Access reviews - 2 hours

Access requests: workflows and approvals

Entitlement management is an identity governance feature to manage employee access to resources. Automate access request workflows, access assignments, access reviews, and expiration. Provide users with self-service resource access requests. To do so, define self-service policy and workflow:

  • Enable multistage approval workflows, separation of duties enforcement, and recurring access recertification
  • Use custom workflows for access lifecycles with Azure Logic Apps
  • Configure time-limited access

Deploy entitlement management

Separation of duties

In entitlement management, you can configure policy for user groups and access packages. Conversely, with separation of duties, you can disable requests if a user is assigned to other access packages, or the user is a member of an incompatible group. Generate reports of users with incompatible access rights. Create alerts when users are granted access to applications.

You can learn to configure separation of duties checks for an access package.

Create an autoassignment policy

In this area of access policy, birthright assignment refers to automatically granting resource access based on user properties. Creating assignments works similarly. User properties match, or don’t match, a policy's membership rules. Use rules to determine access package assignment based on user properties, similar to dynamic groups. Add or remove assignments, based on rule criteria.

In the following screenshot see the Edit policy dialog, with the Create auto assignment policy tab.

Screenshot of the Create auto assignment policy tab on the Edit policy dialog.

Custom workflows with Azure Logic Apps

Create and run automated workflows with Azure Logic Apps, using the visual designer and prebuilt operations.

To extend governance workflows, integrate Logic Apps with entitlement management:

  • An access package request is created or approved
  • An access package assignment is granted or removed
  1. Go to Trigger Azure Logic Apps with custom extensions in entitlement management.
  2. Use the instructions to create and add a custom extension to a catalog.
  3. Edit the custom extension.
  4. Add custom extensions to an access package.

See the following video to learn about custom extenstionsextensions and access packages in Microsoft Entra ID Governance.

[!VIDEO 4fdc4503-b3c9-42b7-b36b-375aea3024a9]

Access recertification: Access reviews

For access recertification, you can review access rights with recurring access reviews. Manage group membership, resource access, and role assignments, also meet compliance requirements.

Administrators determine review scope, then create reviews in access reviews, Microsoft Entra enterprise apps, Privileged Identity Management (PIM), or entitlement management.

Diagram of review creation for administrators.

The New access review dialog appears with the Review type tab. Find options for review type, scope, and other configuration details.

Reviewers

The My Access dashboard shows a reviewer's pending approvals and recommendations.

Diagram of pending reviews.

Multistage reviews

Multistage reviews reduce the burden on individual reviewers and help achieve consensus across reviewers. Fallback reviewers help decide unreviewed decisions. Review stage configuration includes indicating the number of stages.

Diagram of the access funnel.

Use the New access review dialog, and Reviews tab to configure review stages, reviewers, duration, and more.

Diagram of the New access review dialog.

Automated decision criteria

During access review configuration, you can indicate various decision criteria, including reviewer decision helpers. Other options include:

  • Response triggers
  • Account inactivity
  • Justification requirements
  • Alerts and notifications

The New access review dialog, and Settings tab, with decision helper options highlighted.

Inactive user reviews

If users haven't signed in to the tenant within a designated duration, they're considered inactive. This behavior is adjusted for application assignment reviews, or a user's last activity in an app. To get started, define what inactive means for your organization.

Learn how to detect and investigate inactive user accounts.

The New access review dialog, and Review type tab, with inactivity options highlighted.

Screenshot of the New access review dialog and the Review type tab.

Review recommendations

Reviewers can use machine-learning derived recommendations to help make access decisions. Recommendations detect User-to-Group Affiliation, based on reporting-structure proximity. Users distant from group members have low affiliation.

Access review for PIM for Groups

You can grant users just-in-time (JIT) membership and group ownership with Privileged Identity Management (PIM) for Groups. Reviews include active group members and eligible members.

Learn to create access reviews for PIM for Groups.

The New access review dialog, and Review type dialog with options for scope and more.

Screenshot of the New access review dialog, the Review type tab.

Access review history report

With access reviews, authorized users can create downloadable review-history reports for more insight on reviewer decisions, time frames, and more. Use filters to include review types and results.

The Identity Governance dialog, in the Review History area, with the Review History option highlighted.

Deploy access reviews

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…