📖 What is Microsoft Entra ID Access Reviews?
Microsoft Entra ID Access Reviews is a governance feature that allows administrators to periodically review and certify the access rights of users to groups, applications, or privileged roles. This ensures the principle of least privilege is consistently maintained.
"Focus on the 'Self-Review' option for the exam, as it shifts the burden of justification to the user rather than the manager."
📚 Certification: Microsoft 365 Administrator (MS-102)
🔑 What are the Key Concepts of Microsoft Entra ID Access Reviews?
- ▸ Supports auditing access for groups, applications, and privileged roles to ensure users only possess the permissions necessary for their current job functions.
- ▸ Allows configuration of reviewers, including group owners, managers, or the users themselves through the self-review mechanism to justify their continued access.
- ▸ Includes a 'default action' setting that automatically removes or approves access if the designated reviewer fails to respond within the specified timeframe.
- ▸ Integrates with Entra ID Governance to provide a documented audit trail of who approved access and when, supporting regulatory compliance requirements.
🎯 How does Microsoft Entra ID Access Reviews appear on the MS-102 Exam?
You may be asked to implement a process that forces users to justify their access to a high-security application every 90 days without increasing manager workload.
A scenario might describe a need to automatically revoke access to a sensitive security group if the group owner fails to complete a quarterly review.
Expect questions about selecting the appropriate reviewer type when the primary goal is to shift the burden of justification from administrators to the end users.
❓ Frequently Asked Questions
How do Access Reviews differ from Privileged Identity Management (PIM)?
PIM focuses on just-in-time activation for temporary access, while Access Reviews are periodic audits to determine if that access should still exist at all.
What is the primary advantage of enabling the 'Self-Review' option?
Self-review reduces administrative overhead by requiring the user to provide a business justification for their access, which the system then logs for auditing purposes.
What happens if a reviewer ignores an Access Review notification?
The system executes the pre-configured 'default action.' This can be set to either 'Remove access' for higher security or 'Approve access' for lower friction.