Entra ID Governance: Entitlement Management, Access Reviews, and Lifecycle Workflows

Five days of identity posts have secured how access is used. Today closes the loop on how access is granted, reviewed, and removed, the lifecycle problem that every audit finding traces back to: the contractor who left in March with accounts alive in September, the engineer who changed teams and kept both teams’ access, the share nobody can explain. Entra ID Governance is the product answer.

Entitlement Management: Access as Packages

The unit is the access package: a bundle of groups, application assignments, and SharePoint roles representing something a human understands, “Payments Team Developer” or “Vendor X Collaboration”. Users request packages from a catalog; policies per package define who may request (internal users, specific connected organizations for external partners), what approval chain applies, mandatory questions, and, the crucial part, expiry: every assignment ends or renews, nothing is forever by default. Auto assignment policies grant packages from user attributes, department equals Payments gets the payments package on day one and loses it on transfer, which is birthright access implemented as rules instead of tickets. For partner access this composes beautifully with External ID: a connected organization’s users request the package, approval fires, the guest account is created, and when the assignment expires the guest access dies with it, solving guest sprawl at the source rather than with periodic purges.

Access Reviews With Teeth

Reviews already appeared in the PIM post for privileged roles; governance extends them to groups, applications, and packages. The settings that separate theater from control: reviewers who actually know (managers for team access, resource owners for application access, self review only for low risk), decision helpers surfacing last sign in so reviewers act on data, auto apply results so approval fatigue does not become a second grant path, and, non negotiably, deny on non response for anything sensitive, because a review where silence means keep is a reminder email, not a review. Cadence quarterly for sensitive scopes, semiannual for the long tail, and pipe completion metrics to the same dashboards as everything else; a review cycle with 40 percent response is itself a finding.

Lifecycle Workflows: Joiner, Mover, Leaver as Code

Lifecycle workflows automate the sequences HR events should trigger. Joiner: before the start date, generate the temporary access pass and notify the manager; on day one, add to birthright groups, send the welcome. Leaver: on the last day, disable sign in, revoke sessions and refresh tokens, remove from groups; days later, remove licenses and delete or archive. Mover: on department change, run the package reassignment and trigger targeted reviews of retained access. The triggers key off employment attributes flowing from your HR system through the provisioning connectors, which makes the real prerequisite data hygiene: employeeHireDate and employeeLeaveDateTime populated reliably. The leaver workflow is the one to build first and test hardest, token revocation especially, because a disabled account with a live refresh token is not disabled, and rehearse it with the same seriousness as the DR runbooks from September, since offboarding an admin under adverse circumstances is exactly a disaster recovery scenario. With packages granting, reviews attesting, and workflows revoking, the identity story this week built finally has a full lifecycle: access that arrives with a reason, persists under review, and leaves on schedule.

Cheers
Osama

Leave a comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.