Permissions only ever go one direction. A review is the single mechanism that ever pulls any of them back.
Reviews recertify who is in which group, who is assigned to which application and who holds which role, on a schedule, with the person who owns the resource making the call instead of IT guessing at it. Too much access causes two separate problems: it makes a compromise worse, and it produces an audit finding in its own right, because it demonstrates that nobody is controlling access. User access review turns up in every SOC 2 examination and every HIPAA assessment without fail.

- Weekly to annuallyRecurring review frequencies
- Owner or selfReviewers can be either, or named
- Groups, apps, rolesPlus access packages and Azure roles
- Governance licenseSome capabilities work with P2
Six review types, created in four different places.
Security group and Microsoft 365 group membership
Set up either in access reviews or from the groups area itself. The reviewer can be a named person, the group owner, or the members reviewing their own membership. They work in the Access panel. This is the highest volume type in almost every company, and it is where handing the decision to the group owner rather than keeping it with IT changes the result most, for the simple reason that the owner knows who belongs and IT does not.
Enterprise application assignments
Set up from access reviews or from the enterprise applications area, with named reviewers or self-review, again through the Access panel. Business critical applications get called out specifically, on the basis that a compliance process may well require people to reconfirm and to write down why they still need access. It is that written reason an auditor will ask to see.
Microsoft Entra role assignments
These are set up in Privileged Identity Management rather than in access reviews, and the reviewer works in the admin center. The reason to run one is put plainly: find out how many people hold administrative access, how many of them are Global Administrators, and whether any guest or partner account was ever removed after the task it was invited for.
Azure resource role assignments
Also set up in Privileged Identity Management and also reviewed in the admin center, with User Access Administrator given as the worked example. These are the assignments that pile up quietly over the course of a project and then sit there for years, because nobody was ever given the cleanup and the project team has long since dispersed.
Access package assignments
Set up within entitlement management, with the reviewer being a named person, the members of a group, or the assignee reviewing their own, all in the Access panel. Where entitlement management is already running, this is the obvious place to recertify, because the package already carries the business context that makes the question answerable.
Access rights from custom data resources, in preview
Managers do the reviewing, set up in access reviews and answered in the Access panel. This is still listed as a preview capability. Reviewing by manager is a genuinely different model from reviewing by resource owner, and it suits companies where access decisions really do sit with line management rather than with whoever owns the system.
Recurrence, which is what makes it a control
Reviews can recur weekly, monthly, quarterly or annually, with the reviewer notified when each round opens and given recommendations alongside the approve and deny buttons. A review run once is a cleanup exercise. A review that recurs is a control. Only the second one survives the audit question about how you know today that access is still appropriate.
Guest access, which nothing else cleans up
The gap is stated bluntly. Access for your own staff can be automated through lifecycle workflows driven by HR data. Access for invited guests cannot. Where a group opens business sensitive content to guests, confirming those guests still have a genuine business need falls to the group owner. In practice, reviewing guests is where the first cycle finds by far the most.
P2 gets you part of this. It does not get you the useful part.
The feature calls for either Entra ID Governance or the Entra Suite, with the caveat that some of what sits inside it will run on a P2 subscription.
- The published caveat is precise about where P2 stops. Reviewing inactive accounts, running a review with affiliation recommendations comparing a person against their peers in a group, and reviewing several resources together, still in preview, all need a Governance license.
- Those three happen to be exactly what makes reviewing efficient once there is any volume involved. Reviewing dormant accounts is the highest yielding first campaign in almost every company, and the affiliation recommendations are the thing that stops a reviewer approving the whole list without reading it.
- Build a plan on the assumption that P2 covers everything and you end up with the least useful version of the feature, with the gap only appearing at the moment somebody sits down to configure the one review that would genuinely have found something.
- Which license the tenant genuinely holds, and which of the reviews you want fall inside it, gets established before a single design decision is made. It is a fifteen minute check and it regularly changes the shape of the whole program.
Four things that stop reviews becoming a rubber stamp.
We fix group ownership before we schedule anything
Sending the review to the group owner is the highest impact decision in the whole design, and it collapses instantly in an estate where half the groups have no owner or list somebody who left in 2022. Establishing genuine ownership is dull work and it comes first, because a review sent to nobody either expires unanswered or gets approved by default.
Start where the risk sits, not where the numbers are
Too many people holding privileged roles is named as the first reason to run one, and that is the right instinct. How many Global Administrators there are, which partner and guest accounts survived some administrative task nobody remembers, and who holds User Access Administrator over Azure resources. Short list, high yield. Open with three hundred distribution groups instead and you have simply trained everybody to click approve.
We treat guest review as its own campaign
Lifecycle workflows driven by HR data will automate access for your own staff and will not touch invited guests, and confirming a guest still has a genuine business need falls squarely to the group owner. Guests are nearly always the richest first cycle, and they are also the single finding an auditor is most likely to write up.
We design what happens after the review, first
A denial that removes nothing is theater. Silence that counts as approval is worse than that, because it manufactures evidence claiming the access was reviewed when nobody looked at it. What happens on apply, what happens when somebody does not respond, and how a person appeals all get decided before the first campaign, because those three answers determine whether any of this changes anything.
Six US situations where reviews earn their place immediately.
A regulated financial firm that has just been written up for this
User access review comes up in every SOC 2 examination, in GLBA and FTC Safeguards programs, and in internal audit. Running these on a schedule produces the evidence as a side effect rather than as an annual project, with a record of who reviewed what and on which date. That answers the question considerably better than a spreadsheet with a signature at the bottom of it.
A group that grew by acquisition
Every acquisition arrives with groups whose purpose was never written down and applications whose assignment lists nobody has opened in years. Reviews delegated to owners inside each acquired business surface all of that far faster than a central team trying to reverse engineer it, and they carry on working long after the integration project has closed.
A professional services firm working with external partners
A guest joins for one project and stays indefinitely, because nothing exists to remove them. The responsibility for confirming they still have a genuine business need for business sensitive content sits with the group owner. In a firm where client work is organized into groups and Teams, that one review type usually strips out more standing access than every other type combined.
An operator with contractors and seasonal staff
Access handed out for a plant shutdown, a commissioning window or a seasonal peak almost never gets revoked on time, because whoever granted it has moved on to the next thing before the window closes. Monthly or quarterly reviews aimed at exactly the groups carrying that access shut the loop without anybody having to remember.
A healthcare organization with clinical system access
A clinical system is precisely what is meant by a business critical application where the compliance process may require somebody to reconfirm and justify continued access, and periodic review of who can reach electronic protected health information is exactly what a HIPAA assessor turns up expecting to see. Demanding a written reason rather than a yes or no changes the quality of what comes back, and it gives the auditor something to actually read.
An education institution with high annual turnover
Students, researchers, visiting academics and short contracts generate more access churn in a single year than a corporate estate manages in five. Reviews timed to the academic calendar, using self-review where that is defensible and owner review wherever the resource is sensitive, keep the place honest without funding a permanent cleanup team.
How US organizations recertify access today.
| Feature | Recurring Entra reviews | Annual spreadsheet exercise | No recertification |
|---|---|---|---|
Group membership recertified | Yes | Partly | No |
Application assignments recertified | Yes | Rarely | No |
Privileged roles recertified | Yes | Sometimes | No |
Reviewed by the person who knows | Yes | No | Not applicable |
Denials actually remove access | Yes | Sometimes | Not applicable |
Guests reviewed separately | Yes | No | No |
Recurs without anyone starting it | Yes | No | No |
Evidence produced automatically | Yes | Manually | No |
Recommendations assist the reviewer | Yes | No | No |
Effort per cycle | Low | High | None |
What you are reviewing decides where you create it.
Access being reviewed
Security group members
- Created in
- Access reviews, or Microsoft Entra groups
- Who can review
- Specified reviewers, group owners, or self-review
- Practical consequence
- Handing the decision to the owner is the one change that improves quality most
Access being reviewed
Microsoft 365 group members
- Created in
- Access reviews, or Microsoft Entra groups
- Who can review
- Specified reviewers, group owners, or self-review
- Practical consequence
- This also decides the Team, the SharePoint site and everything else hanging off that group
Access being reviewed
Assigned to a connected app
- Created in
- Access reviews, or Microsoft Entra enterprise apps
- Who can review
- Specified reviewers, or self-review
- Practical consequence
- Where to insist on a written reason for anything business critical
Access being reviewed
Microsoft Entra role
- Created in
- Privileged Identity Management
- Who can review
- Specified reviewers, or self-review
- Practical consequence
- The reviewer is in the admin center rather than the Access panel, so brief them separately
Access being reviewed
Azure resource role
- Created in
- Privileged Identity Management
- Who can review
- Specified reviewers, or self-review
- Practical consequence
- Where leftover project access hides, User Access Administrator especially
Access being reviewed
Access package assignments
- Created in
- Entitlement management
- Who can review
- Specified reviewers, group members, or self-review
- Practical consequence
- The package already carries the business context, which is what makes the question answerable
Access being reviewed
Custom data resources, in preview
- Created in
- Access reviews
- Who can review
- Managers
- Practical consequence
- Managers decide here rather than resource owners
Five steps, and everything you need to know comes out of the first cycle.
- 1
Confirm entitlement and scope
Which license the tenant actually holds, given that this needs Governance or the Entra Suite while parts of it will run on P2, and that reviewing dormant accounts, using affiliation recommendations and reviewing several resources at once all specifically require Governance. Then which groups, applications and roles are in scope, and the order they get done in.
- 2
Fix ownership and reviewer assignment
Every group in scope gets a genuine owner or a named reviewer, with a written fallback for the day that person resigns. Where self-review is going to be used, we settle in advance what makes it defensible. This single step decides whether any of the reviews get answered at all.
- 3
Design the review types in the right places
Group and application reviews are built in access reviews or in the relevant area, directory role and Azure resource role reviews in Privileged Identity Management, and package reviews in entitlement management. Reviewers are told in advance which screen they will be looking at, because role reviews land in the admin center rather than the Access panel and an unbriefed reviewer simply does not respond.
- 4
Run the first cycle deliberately smaller than you want
Privileged roles and guests go first, because that is where the yield sits and where a badly designed process reveals itself within days. We watch how many people respond, how many appeal and how many denials come back, then adjust the scope, the wording and the frequency before widening it to anything else.
- 5
Make it recurring and hand it over
Each scope gets its own frequency somewhere between weekly and annual, reviewers hear about it when a cycle opens, evidence accumulates as a side effect, and one named person owns the program. Leave that last part out and the schedule keeps running long after anybody stopped paying attention to it.
What US organizations ask about Entra access reviews.
Fifteen decisions that determine whether reviews work.
Scope
- Which groups genuinely need reviewing?Reviewing everything trains reviewers to click approve.
- Which applications are business critical?Those are the ones worth a justification field.
- Are privileged roles in the first wave?Microsoft names this trigger first.
- Do you have Azure resource roles to review?They are created in PIM, not access reviews.
- Are guests scoped separately?Lifecycle workflows do not cover them.
Reviewers
- Group owner or named reviewer?Owners know more, named reviewers respond faster.
- Is self-review appropriate anywhere?Self-review works only where somebody can be held to the answer they gave.
- Do your groups have real owners?Plenty of groups have no owner at all, and that gets fixed first.
- Who reviews when the owner has left?Decide the fallback before the first cycle.
- Are reviewers trained on which portal?Role reviews use the admin center.
Afterwards
- What happens on a denial?Automatic removal or a manual queue.
- What happens when nobody responds?Configure it deliberately, do not inherit it.
- Who handles the appeals?There will be appeals in cycle one.
- Where is the evidence kept?This is what the auditor asks for.
- What frequency for each scope?Weekly through annually is supported.
The pages around this one.
Entra ID Governance
The suite these reviews belong to, and the license the fuller capabilities require.
Privileged Identity Management
Where the directory role and Azure resource role reviews actually get built.
Privileged access audit
The point-in-time audit of who holds administrative access across your estate.
Begin with privileged roles and with guests. Each takes about a week, and each turns something up.
Privileged role counts and stale guest access are the two places a first review cycle finds the most, and the same review runs again next quarter without anyone starting it. That recurrence is what turns a cleanup into a control.
Related Services
Explore more solutions that work great with this service
Microsoft Entra Lifecycle Workflows
Entra lifecycle workflow implementation for US organizations: joiner
Learn moreMicrosoft Entra ID Governance
Entra ID Governance implementation for US organizations: automating
Learn moreMicrosoft Entra Privileged Identity Management
Privileged Identity Management deployment for US organizations:
Learn morePrivileged Access Audit
Privileged access audits for US organizations: enumeration of every
Learn moreMicrosoft Entra ID P1 and P2 Licensing Review
Independent Entra ID P1 against P2 advice for US organizations:
Learn moreMicrosoft Security Services
The Microsoft security stack deployed and managed end to end
Learn more