Skip to content
Browse all topics
Microsoft Entra (Identity)

Microsoft Entra ID Access Reviews

By Emil Björk · Microsoft ecosystem consultant, Gothenburg

How access reviews keep group memberships and role assignments healthy over time — periodic recertification at scale.

6 min read

Share as imagePNG

Access reviews in Microsoft Entra ID are periodic recertification processes that force someone — the user themselves, their manager, a group owner, a named reviewer — to confirm whether each user still needs the access they currently have. Without access reviews, group memberships and role assignments accumulate forever, decoupled from actual need.

What can be reviewed

Access reviews can cover:

  • Microsoft 365 Group / security group membership — recertify each member.
  • Entra ID role eligibility in PIM — recertify who can activate Global Admin, etc.
  • Application user assignments — for SAML / OIDC apps integrated with Entra.
  • Guest user access — periodic review of external guests.
  • Privileged role assignments — separate from PIM eligibility, the actual active role holders.
  • Access package assignments (in Entitlement Management).
  • Microsoft 365 Group ownership — confirm owners are still active.

Each review is scoped to a specific population and recurs on a schedule.

How a review works

A typical access review:

  1. Admin configures the review — scope, reviewer, cadence.
  2. Review fires on schedule.
  3. Reviewer is notified — email, Teams notification, link to the review portal.
  4. Reviewer evaluates each access entry:
    • Approve — user still needs this access.
    • Deny — user doesn't need this access; remove it.
    • Don't know — defer to a more senior reviewer or self-attestation.
  5. Decisions apply — denials remove the access automatically.
  6. Audit log captures every decision and the eventual outcome.

For a 100-user group, reviewing 100 entries quarterly is a manageable task for the right reviewer.

One access review, start to finishAn admin configures the review, it fires on schedule, the reviewer is notified, then evaluates each entry as approve, deny, or don't know. All three outcomes feed into decisions applying, which are then written to the audit log.Admin configuresscope, reviewer, cadenceReview fireson scheduleReviewer notifiedemail + TeamsReviewer evaluateseach access entryApproveDenyaccess removedDon't knowdefer / escalateDecisions applyauto-apply removes denied accessAudit logevery decision recorded
One access review, start to finish. Each review recurs on its own schedule, so this whole sequence repeats: an admin configures scope, reviewer, and cadence once, then the review fires automatically each cycle. The reviewer’s three possible decisions are not equivalent — deny is what removes access when auto-apply is on, while don’t know defers the decision rather than resolving it. Every outcome, including a deferral, is written to the audit log.

Reviewer choices

The right reviewer depends on the scope:

  • Self-review — the user themselves attests they still need the access. Lightest weight. Works for low-risk access.
  • Manager review — the user's direct manager attests. Stronger oversight. Common for moderate-risk access.
  • Group owner review — for group memberships, the group owner is often the right reviewer (they know who should be in their group).
  • Named approvers — for high-risk access (privileged roles), specific named reviewers (security team).
  • Multi-stage — first the manager, then the security team. Stronger but slower.

Common access-review patterns

Quarterly review of group memberships

For every Microsoft 365 Group:

  • Group owner reviews quarterly.
  • Self-attestation for users who haven't logged in recently.
  • Removal of users not in the directory anymore.

Catches departed employees still in groups, mis-added members, etc.

Semi-annual review of privileged roles

For every PIM-eligible privileged role:

  • Security team reviews eligibility every 6 months.
  • Confirm continued need; remove the eligible if no longer needed.

Catches the "I needed this for a project that ended a year ago" pattern.

Guest user review

Every 6 months:

  • Review guest users in the tenant.
  • For each: still active in their home tenant? Still needed for collaboration? Sponsor still confirms?
  • Disable / remove guests no longer needed.

Catches orphaned guests accumulating in the tenant.

Application access review

For each SaaS app integrated via SSO:

  • App owner reviews assigned users annually.
  • Confirm continued business need.

Catches users who got access during a trial or pilot but never legitimately used it.

Operational considerations

  • Don't over-review — reviewing trivial groups quarterly is busy-work. Risk-tier the access; review high-risk frequently, low-risk less often.
  • Clear reviewer notification — the email / Teams notification should make the task obvious and time-bounded.
  • Default action on no response — typically "remove access" so passive non-response defaults to safer.
  • Self-attestation discipline — if users always approve themselves without thought, the review is ceremonial. Require justification text, audit randomly.
  • Audit the decisions — track approval rates over time; very-high or very-low rates suggest the review isn't honest.

Licensing

Access reviews require Microsoft Entra ID Governance licensing (formerly part of Entra ID P2, now part of the broader Identity Governance SKU).

For organisations with serious identity governance maturity, access reviews are the discipline that prevents identity sprawl. Without them, today's reasonable access list is next year's audit-failing mess.

The four decisions that shape a review programme

  1. What to review, at what cadence. Not every group needs a quarterly review. A pragmatic pattern: privileged Entra role eligibility every 3 months, sensitive-data group membership every 3–6 months, general M365 groups annually, low-risk groups on request only. A programme with quarterly reviews on 400 groups produces reviewer fatigue and rubber-stamp approvals within two cycles.
  2. Who reviews. Manager review is the default, but the manager rarely knows what a security-scoped group is really for. Group-owner review is more accurate for content-scoped groups; a named security-team reviewer is right for privileged roles. Self-review has a role for very low-risk access as long as it requires justification text.
  3. What happens on no response. Remove access is the safer default for anything above trivial. Take reviewer recommendations uses sign-in activity as an input, and is a good middle ground when reviewers are busy. Never leave the default as no change on a privileged-role review.
  4. Whether decisions apply automatically. Reviews without auto-apply produce a report and nothing else. Every organisation that reports "our access reviews do nothing" turns out to have reviews configured this way. Turn auto-apply on, or do not bother running the review.

Reviewer experience: the friction that kills the programme

The reviewer's experience is the single biggest determinant of whether reviews stay honest. Design for it:

  • Notification arrives in email and Teams, not just email.
  • Deadline is 7–14 days, long enough to be reasonable, short enough to stay on the radar.
  • The portal shows sign-in activity and group description alongside each row so the reviewer has something to base a decision on.
  • Bulk approve is available but requires justification text for approvals over a threshold (say, 20 rows). This is the tuning knob that separates real review from click-through-in-30-seconds.
  • Reminder at day 3, day 7, day 12; escalation to the reviewer's manager on day 14.

Wrong-fit signals

Access reviews disappoint when:

  • The catalogue of groups is a mess. Reviews expose the mess (Reviewer: "I have no idea what this group does"). Fix the group hygiene before enabling reviews.
  • The reviewer population is too broad. 300 managers each reviewing 8 groups a quarter with no coaching produces uniform rubber-stamping.
  • There is no consequence for missed reviews. Reviews that produce a report and no removal become theatre within one cycle.
  • The organisation confuses reviews with lifecycle. When someone leaves, joiner-mover-leaver removes the access; access reviews catch drift between JML events. Reviews are not a substitute for a working JML workflow.

Common wrong turns

  • Auto-apply off. Reviews without enforcement are ceremonial.
  • Manager review on group-owner-scoped groups. The manager approves by default because they do not know what the group does.
  • Self-review with no justification requirement. Every review passes and the audit trail is meaningless.
  • Reviewing groups synced from on-prem AD. Removals do not stick if AD is source-of-authority; the sync re-adds the user next cycle. Review at the source, not in Entra.

Signals worth watching

  • Approval rate by reviewer — 100% approvers are rubber-stamping; sub-30% approvers may be misinterpreting scope.
  • Missed-review percentage by cycle — creeping up is the leading indicator of reviewer fatigue.
  • Group-owner completion rate vs manager completion rate — often reveals which reviewer type actually engages.
  • Access removed per cycle — the number that answers "what did the review programme do this quarter"; if it is zero, either the estate is genuinely tidy (unlikely) or the review is not being enforced.

Frequently asked questions

What can Entra access reviews review?
Membership of security and Microsoft 365 groups, Teams, guest users, application assignments, Entra directory roles and Azure resource roles (via PIM), and access packages. Reviewers can be group owners, managers, named users, or the users themselves.
Do access reviews remove access automatically?
Only if configured. With auto-apply enabled, users denied by the reviewer or not responded to (depending on settings) are removed when the review ends. Reviews without auto-apply only produce a report, which is why some organisations think reviews do nothing.
Which licence do access reviews need?
Entra ID P2 for reviewers and reviewed users in most scenarios — included in E5 and E5 Security. Reviews of guest users and some group reviews are also covered by the Entra ID Governance licence.

Was this useful?

Spot something wrong or want a topic covered? Send it through the contact form.