Lesson 10 — Access Reviews in Microsoft Entra
Access that was appropriate six months ago may no longer be appropriate today.
Microsoft Entra access reviews help organisations regularly confirm whether users still require access to groups, applications, privileged roles and access packages.
This lesson explains review scope, reviewer selection, recurrence, recommendations, decisions, automatic remediation and the investigation evidence created by an access review campaign.

What you will learn
This lesson explains how Microsoft Entra verifies and removes access that is no longer justified.
Learning objectives
After completing this lesson, you should be able to plan, interpret and investigate Microsoft Entra access reviews.
- Explain why recurring access certification is required.
- Identify suitable review scopes and reviewers.
- Describe recurrence, duration and multi-stage reviews.
- Understand recommendations, default decisions and automatic remediation.
- Investigate suspicious or poorly completed review campaigns.
The problem this solves
Access often survives staff transfers, completed projects, expired contracts and changes in business responsibility.
Without recurring reviews, organisations may know how access was originally granted but not whether it is still justified.
What is an access review?
An access review is a Microsoft Entra ID Governance process that asks designated reviewers to confirm whether users should retain or lose specific access.
Granting access is only the first decision. Secure identity governance requires the organisation to make the decision again later.
Review scope
The scope defines exactly which access relationships are being reviewed.
A narrow, business-focused scope produces better decisions than one large campaign containing unrelated users and resources.
Common review targets
Access reviews can be used for Microsoft Entra groups, enterprise applications, privileged role assignments and access package assignments.
Each target requires reviewers who understand both the business need and the security impact.
Review targets compared
| Review target | Typical question | Useful reviewer |
|---|---|---|
| Group membership | Should this user remain a member of the group? | Group owner or business manager. |
| Enterprise application access | Does the user still need access to the application? | Application owner or data owner. |
| Privileged role assignment | Is this administrative role still required? | Privileged role owner, security team or senior approver. |
| Access package assignment | Does the user still need the package and its bundled resources? | Manager, sponsor or resource owner. |
Who should review?
The reviewer must have enough context to make a meaningful decision.
A reviewer who does not understand the user, resource or business purpose may simply approve everything to clear the task.
Reviewer accountability
Review ownership should be visible, documented and supported by clear instructions.
Security teams can monitor completion and risk, but business and resource owners should remain accountable for the access decision.
Reviewer models
| Reviewer model | Strength | Limitation |
|---|---|---|
| User self-review | The user knows whether the task continues. | Users may approve their own access without considering risk. |
| Manager review | The manager understands current responsibilities. | The manager may not understand the application or data sensitivity. |
| Resource owner review | The owner understands the resource and its risk. | The owner may not know why each user originally received access. |
| Sponsor review | Useful for contractors, partners and guest users. | The sponsor may have left or changed role. |
| Multi-stage review | Combines business and resource context. | More stages require clear timing and escalation. |
Recurrence
Reviews can run once or recur on a schedule such as monthly, quarterly, six-monthly or annually.
Frequency should reflect the sensitivity of the access and the speed at which the business relationship may change.
Review duration
Each review campaign needs enough time for reviewers to investigate and respond.
Very short campaigns cause rushed decisions; very long campaigns delay remediation and reduce urgency.
Designing the review cycle
Multi-stage reviews
A review can require more than one stage, such as manager review followed by resource-owner review.
This is valuable when no single person has enough context to assess both business need and technical risk.
Fallback reviewers
Fallback reviewers help prevent a review from stalling when the primary reviewer is unavailable, inactive or missing.
Fallback assignments should be tested before the campaign starts.
Recommendations and evidence
Microsoft Entra can provide recommendations based on signals such as recent sign-in activity.
| Evidence | What it may indicate | Important caution |
|---|---|---|
| Recent sign-in activity | The user may still be actively using the application. | Use does not automatically prove legitimate business need. |
| No recent sign-in | The access may be stale or unnecessary. | Some resources are used infrequently but remain business-critical. |
| Manager or sponsor context | The role or relationship still exists. | The reviewer may not know the resource sensitivity. |
| Resource-owner context | The user is still authorised for the data or system. | The owner may not know whether the user's role changed. |
Reviewer decisions
Reviewers typically approve, deny or leave an item unanswered.
Comments and justification improve auditability, especially when sensitive access is retained despite limited activity.
Default decisions
A policy may define what happens when a reviewer does not respond.
Automatically approving unanswered items can preserve stale access and weaken the control.
Applying review results
Automatic application improves consistency, but administrators should understand exactly which memberships, assignments or package entitlements will be removed.
Automatic remediation
When configured, Microsoft Entra can automatically remove denied access after the review completes.
This closes the gap between identifying stale access and actually revoking it.
Manual result application
Manual application may be appropriate when the organisation requires additional validation before removal.
However, unresolved review results can create a backlog where risky access remains despite a deny decision.
Access review investigation workflow
Did the user retain access because the reviewer made an informed decision, because the reviewer lacked context, or because the review result was never applied?
Real-world scenario: every user was approved
Investigate review configuration
Review the scope, recurrence, reviewer assignment, fallback reviewers, recommendations, default decisions and result-application settings.
A poorly configured campaign may appear complete while failing to remove any access.
Investigate reviewer behaviour
Look for unusually fast bulk approvals, repeated approvals without comments and decisions that contradict available evidence.
These patterns may indicate review fatigue, insufficient context or deliberate control bypass.
Common mistakes
| Mistake | Why it creates risk | Better practice |
|---|---|---|
| Review scope is too broad | Reviewers cannot meaningfully assess hundreds of unrelated assignments. | Create focused campaigns by resource, role or business purpose. |
| Wrong reviewer selected | The reviewer lacks business or resource context. | Choose managers, sponsors or resource owners based on the decision required. |
| No fallback reviewer | The campaign stalls when the primary reviewer is unavailable. | Configure and test fallback reviewers. |
| Automatic approval for unanswered items | Stale access remains when reviewers ignore the campaign. | Use deny, remove or escalation for sensitive access. |
| Results are never applied | Denied access remains active. | Enable automatic remediation or track manual completion. |
| Recommendations treated as final decisions | Sign-in activity alone may not reflect business need. | Combine recommendations with reviewer investigation and context. |
Key takeaways
- Access reviews confirm whether existing access remains justified.
- Review scope should be focused and aligned with a clear business decision.
- Managers, sponsors and resource owners provide different forms of context.
- Recurrence should reflect the sensitivity and change rate of the access.
- Recommendations support reviewers but do not replace judgement.
- Review results must be applied for the control to reduce risk.
- Investigations should connect review configuration, reviewer behaviour, decisions, remediation, audit logs and actual access use.
Related Agent Foskett resources
Continue learning
Microsoft Entra Access Reviews
Microsoft Entra access reviews help organisations regularly verify group membership, enterprise application access, privileged roles and access package assignments.
Microsoft Entra Academy Lesson 10 — Access Reviews in Microsoft Entra
This Agent Foskett lesson explains review scope, reviewers, recurrence, recommendations, decisions, automatic remediation and access review investigation workflows.
