Somebody who left in March still holds access to something, and nobody is going to find it before an auditor does.
The product automates joining, moving and leaving, packages access up so that business owners approve it rather than IT guessing on their behalf, reviews entitlements on a schedule, and removes a guest the moment their access expires. It answers four questions the documentation states plainly, and they happen to be the same four a SOC 2 examiner, a HIPAA assessor or an acquiring company due diligence team will put to you.

- Joiner, mover, leaverAutomated from your HR source
- Access packagesApproved by owners, not IT
- GuestsRemoved automatically on expiry
- AuditableControls an auditor can verify
Eight capabilities, organized around the three lifecycles.
Identities originating in your HR system rather than in a ticket
Inbound provisioning from an HR source, with Workday and SuccessFactors both named in the documentation, keeps user identities current in Active Directory and Microsoft Entra ID without anybody intervening. The signal that somebody has joined arrives from the system that already knew, and that is the only form of onboarding which stays accurate over time. The same mechanism makes the leaver signal automatic too, and leavers are where the actual risk sits.
Lifecycle workflows at the moments that matter
Workflows fire at three key moments: ahead of a new employee scheduled start date, whenever their status changes during employment, and when they leave. A concrete example given is emailing a temporary access pass to the manager of a new starter, or sending a welcome email to the person themselves on their first day. The middle event is the one businesses forget about, and it is precisely where access quietly piles up.
Access packages, so the right person decides
With entitlement management you define how identities request access across packages combining group and team memberships, application roles and SharePoint Online roles. What changes is who decides. It moves away from IT, who have no way of knowing whether a given request is reasonable, and toward the manager, the department lead or the resource owner, who do. That single shift is usually the biggest practical improvement the product delivers.
Separation of duties, enforced at request time
Separation of duties checks can be enforced on an access request, which stops an incompatible combination at the moment somebody asks for it rather than surfacing it during an audit eighteen months later. Multi-stage approval is supported as well, and the example given has access to confidential customer data requiring sign-off from a manager, a resource owner and a security risk officer in turn.
Guests who arrive and leave without anybody chasing
You get to specify which other organizations are permitted to request access at all. An approved requester is added as a B2B guest automatically and assigned the right access, and the documentation is explicit that entitlement management then removes that guest from your directory the moment their access rights expire or get revoked. For any American business working with contractors, consultants and outside firms, this closes the one gap that never closes when it is handled manually.
Access reviews with AI assistance for the reviewers
Reviews recur to confirm people still need whatever they hold, with AI-powered suggestions helping reviewers make better informed decisions, including identifying peer outliers that may deserve closer scrutiny. That last capability addresses the genuine failure mode of manual reviews, which is a manager confronted with two hundred rows approving every one of them with a single click.
Privileged access as part of the same picture
Privileged Identity Management belongs to this same family, delivering just-in-time access and alerting on role changes across Entra roles, Microsoft 365 roles, Azure resource roles and group memberships, with access reviews providing recurring recertification for everyone holding a privileged administrator role. Governing ordinary access and administrative access under one model is considerably easier to evidence than running two disconnected processes and hoping they agree.
AI agent identities, currently in preview
Governance now extends to AI agent identities, and this carries a preview label. Every agent identity has to have a human sponsor accountable for its purpose, its lifecycle decisions and its access reviews, and should that sponsor leave the business, sponsorship transfers automatically to their manager. Agents get governed through the same access packages that govern people. The stated aim is put directly: preventing agent sprawl and shadow AI.
Four questions are published. Try answering each of them about your own business.
All four come from the product overview, and they make a better diagnostic than any feature list ever will. If you cannot answer them about your own business, the gap those questions expose is exactly what this product exists to close.
- Which identities should have access to which resources? Note the word should rather than do. In most businesses the answer to that lives inside the memory of whoever originally set it up, and the two lists have been drifting apart quietly for years.
- What are those identities actually doing with the access they hold? Answering that demands access be visible, attributable and reviewable, rather than dissolved into a nested group structure nobody has ever fully unpicked.
- Are there organizational controls governing how access gets managed? That means a defined process carrying an owner and a decision point, not a habit resting on one particular person continuing to remember.
- Can an auditor verify those controls are genuinely working? This is the question separating a policy from a control. A written procedure producing no evidence fails it outright, and failing it is what generates SOC 2 exceptions and audit findings.
Four things that stop a governance project turning into a two year program.
Leavers and guests come first, ahead of any target operating model
Real risk lives in the leaver path and the guest lifecycle. Both are also the easiest things to automate, and both produce a visible result inside a few weeks. Designing a complete role model before touching either is how these projects burn a year without delivering anything, and by the time that model is finished it is usually wrong in any case.
A handful of applications get packaged properly instead of all of them badly
This works when the access packages correspond to genuine business roles with genuine owners who understand what they are being asked to approve. Three or four well-designed packages covering access that genuinely matters will outperform forty packages assembled out of existing group names, because the latter simply relocates the existing mess into a nicer interface.
We design reviews that reviewers can actually complete
Put two hundred rows in front of a manager and the whole lot gets approved at once, evidencing precisely nothing. So reviews are scoped to what a person can honestly assess, the AI suggestions and peer outlier identification are used, and the cadence is set at something that will survive more than a single cycle. A review happening twice a year that is real beats a quarterly one that is theater.
We build for the auditor who will ask
The fourth of those four questions asks whether an auditor can verify the controls work, and that is the question generating findings. We configure things so a completed review, a request approval chain and a deprovisioning record can each be produced on demand, because that is exactly the evidence a SOC 2 examiner, a HIPAA assessor or an enterprise customer questionnaire asks to see.
Six US situations where manual access management has already failed.
Professional services with constant external collaboration
Consulting firms, law firms and agencies bring contractors and client-side users in continuously, and almost never take any of them out again. Entitlement management adds approved external requesters as B2B guests and removes them automatically once access expires or is revoked. That is the only version of this arrangement staying accurate without somebody chasing it down every month.
A regulated firm facing access management findings
Banks, lenders, insurers and advisory firms all get examined on the same four things: how access is granted, how it is changed, how it is removed and how it is recertified. Whether the framework is GLBA and the FTC Safeguards Rule, the New York DFS requirements, or a SOC 2 report an important customer insisted on, the platform produces that evidence as a byproduct of running normally rather than requiring somebody to assemble a pack in the fortnight before an examination.
A group that has acquired companies
Several HR systems, several directories, and no consistent view of who can reach what across the combined estate. Provisioning from authoritative sources and packaging access by business role is what makes that governable. It is also considerably cheaper than the alternative, which is discovering the gaps during due diligence on the next acquisition.
High-turnover operations
Construction, hospitality, logistics and retail move very large numbers of people in and out without pause, and no manual deprovisioning process survives that kind of volume. Automating the leaver path off the HR signal is the highest value single change available to any of them, and it is usually the first thing we implement, because the risk is concrete and the fix is contained.
Education, with an annual cycle nobody enjoys
Cohorts arrive and leave against a fixed calendar, staff change roles between terms, and visiting faculty and external examiners need access that ends on a date. Lifecycle workflows tied to the academic calendar, combined with access packages carrying a defined expiry, replace an annual scramble that swallows weeks of the IT team time and still leaves accounts behind afterwards.
An organization starting to deploy AI agents
Governance for agent identities sits in preview, and it is worth understanding now rather than after the sprawl has happened. Each agent identity needs a human sponsor accountable for its purpose and its access reviews. Sponsorship transfers to that person manager if they leave. And blueprints let an entire class of agents be governed, disabled or revoked in a single operation. The risk being addressed is named directly: agent sprawl and shadow AI.
How access is actually managed in most US organizations.
| Feature | Governance automated | Manual and documented | Ad hoc |
|---|---|---|---|
Joiners provisioned from an authoritative source | Yes | No | No |
Movers have old access removed | Yes | Rarely | No |
Leavers fully deprovisioned across applications | Yes | Partly | No |
Access approved by the business owner | Yes | Sometimes | No |
Separation of duties enforced at request | Yes | No | No |
Guests removed automatically on expiry | Yes | No | No |
Recurring access reviews with real evidence | Yes | Partly | No |
Privileged access governed in the same model | Yes | No | No |
An auditor can verify the controls work | Yes | Partly | No |
Frequency in the US mid-market | Uncommon | Common | Common in SMBs |
What ends up governed, and what tends to go wrong when it is not.
Lifecycle stage
Joiner
- The usual failure without governance
- Access pieced together from a ticket plus a guess at what somebody similar already holds
Lifecycle stage
Mover
- The usual failure without governance
- New access gets granted, the old access stays, and permissions pile up across years
Lifecycle stage
Leaver
- The usual failure without governance
- Accounts disabled, application access and group memberships left behind
Lifecycle stage
Guest access
- The usual failure without governance
- Partner accounts outlive by years the project that originally justified them
Lifecycle stage
Access requests
- The usual failure without governance
- IT approves it, with no basis whatsoever for judging whether it is reasonable
Lifecycle stage
Separation of duties
- The usual failure without governance
- Incompatible combinations found by an auditor, not prevented
Lifecycle stage
Recertification
- The usual failure without governance
- A spreadsheet, approved in bulk, evidencing nothing
Lifecycle stage
Privileged access
- The usual failure without governance
- Permanent, never reviewed, and held by considerably more people than anybody believes
Lifecycle stage
AI agent identities
- The usual failure without governance
- Created ad hoc, unsponsored, unreviewed and multiplying
Five steps, with something working in the first month.
- 1
Establish the current state against the four questions
Four things get established: who currently has access to what, how each grant happened, which controls exist around it, and what evidence those controls produce. It is a short exercise, and it makes the gap concrete, which is what turns a governance conversation from something abstract into something fundable.
- 2
Automate the leaver path first
This carries the highest risk and is the most contained piece of work available. A leaver signal from the authoritative source triggers removal of access across every application that matters, rather than leaving an account disabled while the application entitlements quietly persist behind it. On its own, this closes the finding most auditors raise.
- 3
Bring the guest lifecycle under entitlement management
You specify which external organizations are allowed to request access, define what each can request and for how long, then let the platform add and remove B2B guests automatically as that access is granted and later expires. It is visible, it happens quickly, and it addresses a population almost nobody reviews by hand.
- 4
Package a small number of applications with real owners
We build three or four access packages covering access that genuinely matters, route approval to whoever can actually judge the request, and add separation of duties checks wherever incompatible combinations exist. Extension comes afterwards, once the model has proven itself against something real.
- 5
Turn on reviews and connect the joiner path
Access reviews recur, scoped tightly enough that a reviewer can complete one honestly, drawing on the AI suggestions and peer outlier identification the platform provides. HR-driven provisioning for joiners and movers comes last, being the largest piece of work and best attempted once everything else is already running.
What US organizations ask about Entra ID Governance.
Fifteen questions worth answering first.
What is manual today
- How does IT learn that somebody has joined?Where the answer turns out to be an email, you have found your first gap.
- How does IT learn that somebody has changed role?The mover event is the one nobody handles.
- How does IT learn that somebody has left?And how long after their last day.
- Who approves an access request today?If it is IT, they are guessing.
- How are guest accounts removed?In most tenants, they are not.
What to automate first
- Do you have an HR system that could be the source?Microsoft names Workday and SuccessFactors among others.
- Which applications hold access worth packaging?Start with a few high-value ones, not everything.
- Do you work with external firms regularly?Guest lifecycle is often the quickest visible win.
- Are there combinations that must never co-exist?Separation of duties can be enforced at request time.
- Do you use non-Microsoft applications?Connectors cover many via SCIM, LDAP and SQL.
The audit driver
- Has an auditor asked how access is granted and removed?This is usually what starts the project.
- Can you evidence a completed access review?Evidence, not an assertion that one happened.
- Are you pursuing SOC 2, HIPAA or CMMC?All examine access provisioning and recertification directly.
- Do clients send you security questionnaires?Access lifecycle questions appear in nearly all of them.
- Have you confirmed licensing?It requires Entra ID Governance or Entra Suite licensing.
The pages around this one.
Entra access reviews
The recertification discipline inside the suite, and the highest-yield first campaign.
Privileged Identity Management
The privileged access half of this same model, covering just-in-time elevation, approval and audit history.
Compliance services
The American compliance frameworks whose access control requirements this platform evidences unusually well.
Begin with a list of everybody who has left in the past twelve months.
Then establish what each of them can still reach across your applications, rather than only checking whether the account was disabled. That exercise costs a day, it is uncomfortable in a productive way, and it settles whether this work is urgent or merely sensible.
Related Services
Explore more solutions that work great with this service
Microsoft Entra Lifecycle Workflows
Entra lifecycle workflow implementation for US organizations: joiner
Learn moreMicrosoft Entra Access Reviews
Entra access review programs for US organizations: entitlement
Learn moreMicrosoft Entra Entitlement Management
Access packages, catalogs and time-boxed entitlements
Learn moreMicrosoft Entra Privileged Identity Management
Privileged Identity Management deployment for US organizations:
Learn morePrivileged Access Audit
Privileged access audits for US organizations: enumeration of every
Learn moreMicrosoft Entra
Identity and access management solutions
Learn more