Product

Microsoft Entra ID Governance

Track documentation and Message Center changes for Microsoft Entra ID Governance.

Microsoft Learn documentation ↗

Latest Microsoft Entra ID Governance changes

Automatic Governance Relationships

Governance

When you create a new Microsoft Entra tenant using the secure add-on tenant creation feature, you're prompted to select an existing subscription and resource group from your billing account. When you create your new tenant, Microsoft generates a new billing asset called **Entra ID Free** under that subscription and resource group, which links to the newly created tenant.

Create a configuration monitor

Governance

Learn how to create a configuration monitor in Microsoft Entra Tenant Governance to evaluate a tenant against a configuration baseline and report drift

Create a governed workforce tenant

Governance

Learn how to securely create a governed Microsoft Entra workforce tenant and establish governance from your home tenant.

Create configuration snapshots

Governance

Learn how to create configuration snapshots in Microsoft Entra Tenant Governance to capture tenant configuration for baselines or audit evidence

Cross-tenant delegated administration

Governance

Learn about cross-tenant delegated administration and the GDAP-based permission model for managing tenants in Microsoft Entra.

Customize Workflow Email

Governance

In the message body, you can customize the email text to personalize it for each recipient. You can optionally include built-in user attributes, custom security attributes, directory extensions, and on-premises extension attributes by embedding them in the text. Before the email is sent, the placeholders are replaced with the actual user information.

Governance Policy Templates

Governance

- Manage the governed tenant without needing a local or business-to-business (B2B) account in that tenant.

Interpret tenant discovery data

Governance

Learn how to interpret tenant discovery data, signals, and metrics in Microsoft Entra Tenant Governance to assess related tenants

Lifecycle Workflow Tasks

Governance

With customized emails, you're able to include dynamic attributes within the subject and body to personalize these emails. You can include built-in user attributes, custom security attributes, directory extensions, and on-premises extension attributes. The list of dynamic attributes that can be included are as follows:

Related tenants in Tenant Governance

Governance

Learn how Microsoft Entra Tenant Governance discovers related tenants through identity, application, and billing signals across your organization

Lifecycle Workflow Inactive Users

Governance

1. Under the **Days of inactivity**, enter the number of days you want the trigger to run for if exceeded, and then select **Next**.

Lifecycle Workflow Templates

Governance

The **Pre-Offboard inactive users** template is designed to configure tasks that must be completed before offboarding inactive users.

Governance Policy Templates

Governance

Learn about governance policy templates and how to use them to enforce consistent governance across tenants in Microsoft Entra

Entitlement Management Access Package Assignments

Governance

In entitlement management, you can see who is assigned to access packages, their policy, status, and identity lifecycle (preview). If an access package has an appropriate policy, you can also directly assign identities to an access package. This article describes how to view, add, and remove assignments for access packages.

Entitlement Management Access Package Manage Lifecycle

Governance

Guest users that already existed in your tenant by being invited are ungoverned. After an ungoverned guest that requests access packages lose their last access package assignment, they'll remain in the tenant indefinitely. If there are guests that have an access package assignment, and only need access from that access package, and there's no other need for them to remain in the tenant, you can convert them to be governed during the time they have that access package assignment. You can directly convert those ungoverned users to be governed by using the **Mark Guests as Governed** functionality in the top menu bar of an access package.

Entitlement Management Delegate

Governance

To determine the least privileged role for a task, you can also reference [Least privileged roles by task in Microsoft Entra ID](../identity/role-based-access-control/delegate-by-task.md#entitlement-management-least-privileged-roles).

Microsoft Entra Suite workshop delivery guide

Architecture

This article is for use by the delivery expert that plans on delivering the Microsoft Entra Suite Workshop to customers. It aims to provide delivery experts with a comprehensive overview of the tasks that is required to successfully deliver the Microsoft Entra Suite Workshop to customers. It's structured chronologically following the standard and typical flow of a workshop delivery. It outlines how to use the Microsoft Entra Suite Workshop to deploy all the components of the suite. It gives organizations and IT admins a detailed plan to design and deploy Microsoft Entra ID Governance, Microsoft Entra Private Access, Microsoft Entra Internet Access, and Microsoft Entra Verified ID.

Licensing Fundamentals

Fundamentals

Account Discovery requires the Microsoft Entra ID Governance add-on or Microsoft Entra Suite. This feature allows administrators to discover existing user accounts in target applications and identify which users have matching Entra accounts or are orphan accounts. For more information, see [Discover identities in target applications with Account Discovery](../identity/app-provisioning/how-to-account-discovery.md).

Identity Governance Overview

Fundamentals

Microsoft Entra ID Governance enables you to balance your organization's need for security and end user productivity with the right processes and visibility.

Migrate From Sap Idm

Governance

In SAP IDM, the Identity Store represents identity data through entry types such as `MX_PERSON`, `MX_ROLE`, or `MX_PRIVILEGE`.

Lifecycle Workflow Tasks

Governance

Lifecycle Workflows allow you to automate the updating of user attributes for users in your organization. You're able to customize the task name and description for this task in the Microsoft Entra admin center.

Create a monitor (preview)

Governance

Learn how to create and configure a tenant configuration monitor in Microsoft Entra Tenant Governance to track configuration drift

Enable tenant discovery (preview)

Governance

Learn how to enable tenant discovery in Microsoft Entra Tenant Governance to identify related tenants across your organization

Pim How To Add Role To User

Governance

1. Select a role you want to assign, select a member you want to assign to the role, and then select **Next**.

Update or delete a monitor (preview)

Governance

Learn how to update or delete a configuration monitor in Microsoft Entra Tenant Governance when baselines or requirements change

Microsoft Entra Id Governance Licensing For Guest Users

Governance

| Access Reviews | [Access Review – inactive users](../identity/users/clean-up-stale-guest-accounts.md#monitor-guest-accounts-at-scale-with-inactive-guest-insights) | Bill when guest user is included in review.<br><br>**API**<br> https://graph.microsoft.com/v1.0/identityGovernance/accessReviews/definitions where inactive guest reviews are included in the policy for a group resource. | Decision item summary. |

Approve activation requests for group members and owners

Governance

With Privileged Identity Management (PIM) and Microsoft Entra ID, you can configure activation of group membership and ownership to require approval. You can also choose users or groups from your Microsoft Entra organization as delegated approvers.

Approve or deny requests for Azure resource roles in Privileged Identity Management

Governance

Microsoft Entra Privileged Identity Management (PIM) enables you to configure roles so that they require approval for activation, and choose users or groups from your Microsoft Entra organization as delegated approvers. Select two or more approvers for each role to reduce workload for the Privileged Role Administrator. Delegated approvers have 24 hours to approve requests. If a request isn't approved within 24 hours, then the eligible user must resubmit a new request. The 24-hour approval time window isn't configurable.

Approve or deny requests for Microsoft Entra roles in Privileged Identity Management

Governance

Privileged Identity Management (PIM) in Microsoft Entra ID allows you to configure roles to require approval for activation, and choose one or multiple users or groups as delegated approvers. Delegated approvers have 24 hours to approve requests. If a request isn't approved within 24 hours, then the eligible user must re-submit a new request. The 24-hour approval time window isn't configurable.

Assign Microsoft Entra roles in Privileged Identity Management

Governance

With Microsoft Entra ID, a Global Administrator can make **permanent** Microsoft Entra admin role assignments. These role assignments can be created using the [Microsoft Entra admin center](~/identity/role-based-access-control/permissions-reference.md) or using [PowerShell commands](/powershell/module/azuread/#directory_roles).

Bring groups into Privileged Identity Management

Governance

In Microsoft Entra ID, you can use Privileged Identity Management (PIM) to manage just-in-time membership in the group or just-in-time ownership of the group. Use groups to provide access to Microsoft Entra roles, Azure roles, and various other scenarios. To manage a Microsoft Entra group in PIM, you must bring it under management in PIM.

Complete an access review of Azure resource and Microsoft Entra roles in PIM

Governance

Privileged Role Administrators can review privileged access once an [access review starts](./pim-create-roles-and-resource-roles-review.md). Privileged Identity Management (PIM) in Microsoft Entra ID automatically sends an email that prompts users to review their access. If a user doesn't receive an email, you can send them the instructions for [how to perform an access review](./pim-perform-roles-and-resource-roles-review.md).

Configure security alerts for Microsoft Entra roles in Privileged Identity Management

Governance

Privileged Identity Management (PIM) generates alerts when there's suspicious or unsafe activity in your organization in Microsoft Entra ID. When an alert is triggered, it shows up on the Privileged Identity Management dashboard. Select the alert to see a report that lists the users or roles that triggered the alert.

Create an access review of Azure resource and Microsoft Entra roles in PIM

Governance

The need for access to privileged Azure resource and Microsoft Entra roles by your users changes over time. To reduce the risk associated with stale role assignments, you should regularly review access. You can use Microsoft Entra Privileged Identity Management (PIM) to create access reviews for privileged access to Azure resource and Microsoft Entra roles. You can also configure recurring access reviews that occur automatically. This article describes how to create one or more access reviews.

Discovery and insights (preview) for Microsoft Entra roles (formerly Security Wizard)

Governance

If you're starting out using Privileged Identity Management (PIM) in Microsoft Entra ID to manage role assignments in your organization, you can use the **Discovery and insights (preview)** page to get started. This feature shows you who is assigned to privileged roles in your organization and how to use PIM to quickly change permanent role assignments into just-in-time assignments. You can view or make changes to your permanent privileged role assignments in **Discovery and insights (preview)**. It's an analysis tool and an action tool.

Email notifications in PIM

Governance

Privileged Identity Management (PIM) lets you know when important events occur in your Microsoft Entra organization, such as when a role is assigned or activated. Privileged Identity Management keeps you informed by sending you and other participants email notifications. These emails might also include links to relevant tasks, such as activating or renewing a role. This article describes what these emails look like, when they are sent, and who receives them.

Extend or renew Azure resource role assignments in Privileged Identity Management

Governance

Microsoft Entra Privileged Identity Management (PIM) provides controls to manage the access and assignment lifecycle for Azure resources. Administrators can assign roles using start and end date-time properties. When the assignment end approaches, Privileged Identity Management sends email notifications to the affected users or groups. It also sends email notifications to administrators of the resource to ensure that appropriate access is maintained. Assignments might be renewed and remain visible in an expired state for up to 30 days, even if access isn't extended.

Extend or renew Microsoft Entra role assignments in Privileged Identity Management

Governance

Microsoft Entra Privileged Identity Management (PIM) provides controls to manage the access and assignment lifecycle for roles in Microsoft Entra ID. Administrators can assign roles using start and end date-time properties. When the assignment end approaches, Privileged Identity Management sends email notifications to the affected users or groups. It also sends email notifications to Microsoft Entra administrators to ensure that appropriate access is maintained. Assignments might be renewed and remain visible in an expired state for up to 30 days, even if access isn't extended.

Extend or renew PIM for groups assignments

Governance

Privileged Identity Management (PIM) in Microsoft Entra ID provides controls to manage the access and assignment lifecycle for group membership and ownership. Administrators can assign start and end date-time properties for group membership and ownership. When the assignment end approaches, Privileged Identity Management sends email notifications to the affected users or groups. It also sends email notifications to administrators of the resource to ensure that appropriate access is maintained. Assignments might be renewed and remain visible in an expired state for up to 30 days, even if access isn't extended.

Plan a Privileged Identity Management deployment

Governance

**Privileged Identity Management (PIM)** provides a time-based and approval-based role activation to mitigate the risks of excessive, unnecessary, or misused access permissions to important resources. These resources include resources in Microsoft Entra ID, Azure, and other Microsoft Online Services such as Microsoft 365 or Microsoft Intune.

Privileged Identity Management (PIM) for Groups

Fundamentals

Microsoft Entra ID allows you to grant users just-in-time membership and ownership of groups through Privileged Identity Management (PIM) for Groups. Groups can be used to control access to a variety of scenarios, including Microsoft Entra roles, Azure roles, Azure SQL, Azure Key Vault, Intune, other application roles, and third-party applications.

Roles you can't manage in Privileged Identity Management

Governance

You can manage just-in-time assignments to all [Microsoft Entra roles](~/identity/role-based-access-control/permissions-reference.md) and all [Azure roles](/azure/role-based-access-control/built-in-roles) using Privileged Identity Management (PIM) in Microsoft Entra ID. Azure roles include built-in and custom roles attached to your management groups, subscriptions, resource groups, and resources. However, there are a few roles that you can't manage. This article describes the roles you can't manage in Privileged Identity Management.

Start using Privileged Identity Management

Governance

Use Privileged Identity Management (PIM) to manage, control, and monitor access within your Microsoft Entra organization. With PIM you can provide as-needed and just-in-time access to Azure resources, Microsoft Entra resources, and other Microsoft online services like Microsoft 365 or Microsoft Intune.

View audit history for Microsoft Entra roles in Privileged Identity Management

Fundamentals

You can use the Microsoft Entra Privileged Identity Management (PIM) audit history to see the role assignment changes and activations done through PIM. Data is available for the past 30 days. If you want to retain audit data for longer than the default retention period, you can use Azure Monitor to route it to an Azure storage account. For more information, see [Archive Microsoft Entra logs to an Azure storage account](~/identity/monitoring-health/howto-archive-logs-to-storage-account.md). To see full audit history of Microsoft Entra ID activity including administrator, end user, and synchronization activity, you can use the [Microsoft Entra security and activity reports](~/identity/monitoring-health/overview-monitoring-health.md).

What is Microsoft Entra Privileged Identity Management?

Fundamentals

Privileged Identity Management (PIM) is a service in Microsoft Entra ID that enables you to manage, control, and monitor access to important resources in your organization. These resources include resources in Microsoft Entra ID, Azure, and other Microsoft Online Services such as Microsoft 365 or Microsoft Intune. The following video explains important PIM concepts and features.

Entitlement Management Access Package Create App

Governance

1. If your scenario requires the ability to override a separation of duties check, then you can also [set up additional access packages for those override scenarios](entitlement-management-access-package-incompatible.md#configuring-multiple-access-packages-for-override-scenarios).

Identity Governance Applications Existing Users

Fundamentals

Now that you have provided the connectivity details and matching attribute as part of your provisioning configuration, Microsoft Entra can discover the existing users in your application. Click on the [discover identities](~/identity/app-provisioning/how-to-account-discovery.md) button in the provisioning overview page. Once the report is generated, you will have a view of all the users in your application, which users in the application match with a Microsoft Entra ID user, which users are already assigned to the enterprise application in Microsoft Entra ID, and which users in the application are not matched with a Microsoft Entra ID user).

Microsoft Entra: Cross-tenant security group synchronization

Message CenterMC1198077 on mc.merill.net ↗Stay informed
Fundamentals

Microsoft Entra introduces cross-tenant security group synchronization to simplify collaboration and centralize group management across tenants. Public preview starts late January 2026; general availability by end of May 2026. Admins can enable sync by updating attribute mappings and access policies. No compliance issues identified.

Microsoft Entra ID Governance Account Discovery

Message CenterMC1287372 on mc.merill.net ↗Stay informed
Governance

Microsoft Entra ID Governance introduces Account Discovery to identify local and orphaned application accounts outside Entra ID, improving access visibility and control. Public preview starts mid-April 2026; general availability begins August 2026. The feature is off by default and requires admin opt-in, with no user impact unless acted upon.

Automatic Governance Relationships

Governance

If you defined a default [governance policy template](governance-policy-templates.md), a new governance relationship forms between the home (governing) tenant and the newly created add-on (governed) tenant, using the default policy template.

Microsoft Entra ID Governance: Azure subscription required to continue using guest governance features

Message CenterMC1225192 on mc.merill.net ↗Major updatePlan for change
Governance

Starting January 30, 2026, Microsoft Entra ID Governance requires tenants to link an Azure subscription to use guest governance features. Without this, creating or updating guest-scoped policies will be blocked. Existing policies run, but new actions need subscription-linked billing under the Monthly Active User model.

Microsoft Entra license usage insights

Fundamentals

Learn how to use the license usage insights page in the Microsoft Entra admin center to monitor license usage and entitlements.

Entitlement Management Catalog Create

Governance

This article shows you how to create and manage a catalog of resources and access packages in entitlement management. Catalogs are also used in [access reviews (preview)](catalog-access-reviews.md).

Entitlement Management Overview

Fundamentals

| access package | A bundle of resources that a team or project needs and is governed with policies. An access package is always contained in a catalog. You would create a new access package for a scenario in which identities need to request access for themselves. |