Agent Foskett Academy • Microsoft Entra • Module 1 • Lesson 10

Lesson 10 — Access Reviews in Microsoft Entra

Access that was appropriate six months ago may no longer be appropriate today.

Microsoft Entra access reviews help organisations regularly confirm whether users still require access to groups, applications, privileged roles and access packages.

This lesson explains review scope, reviewer selection, recurrence, recommendations, decisions, automatic remediation and the investigation evidence created by an access review campaign.

Access reviews turn ongoing access from an assumption into a documented and repeatable decision.
Agent Foskett Microsoft Entra Access Reviews lesson
What you will learn

This lesson explains how Microsoft Entra verifies and removes access that is no longer justified.

Review scope and reviewers
Recurrence and review stages
Recommendations and decisions
Access review investigations

Learning objectives

After completing this lesson, you should be able to plan, interpret and investigate Microsoft Entra access reviews.

  • Explain why recurring access certification is required.
  • Identify suitable review scopes and reviewers.
  • Describe recurrence, duration and multi-stage reviews.
  • Understand recommendations, default decisions and automatic remediation.
  • Investigate suspicious or poorly completed review campaigns.

The problem this solves

Access often survives staff transfers, completed projects, expired contracts and changes in business responsibility.

Without recurring reviews, organisations may know how access was originally granted but not whether it is still justified.

What is an access review?

An access review is a Microsoft Entra ID Governance process that asks designated reviewers to confirm whether users should retain or lose specific access.

Access granted │ ├── User changes role ├── Project finishes ├── Contractor engagement ends ├── Application is no longer used └── Privileged access remains assigned │ ▼ Access review campaign │ Approve, deny or remove access
Agent Foskett principle:

Granting access is only the first decision. Secure identity governance requires the organisation to make the decision again later.

Review scope

The scope defines exactly which access relationships are being reviewed.

A narrow, business-focused scope produces better decisions than one large campaign containing unrelated users and resources.

Common review targets

Access reviews can be used for Microsoft Entra groups, enterprise applications, privileged role assignments and access package assignments.

Each target requires reviewers who understand both the business need and the security impact.

Review targets compared

Review targetTypical questionUseful reviewer
Group membershipShould this user remain a member of the group?Group owner or business manager.
Enterprise application accessDoes the user still need access to the application?Application owner or data owner.
Privileged role assignmentIs this administrative role still required?Privileged role owner, security team or senior approver.
Access package assignmentDoes the user still need the package and its bundled resources?Manager, sponsor or resource owner.

Who should review?

The reviewer must have enough context to make a meaningful decision.

A reviewer who does not understand the user, resource or business purpose may simply approve everything to clear the task.

Reviewer accountability

Review ownership should be visible, documented and supported by clear instructions.

Security teams can monitor completion and risk, but business and resource owners should remain accountable for the access decision.

Reviewer models

Reviewer modelStrengthLimitation
User self-reviewThe user knows whether the task continues.Users may approve their own access without considering risk.
Manager reviewThe manager understands current responsibilities.The manager may not understand the application or data sensitivity.
Resource owner reviewThe owner understands the resource and its risk.The owner may not know why each user originally received access.
Sponsor reviewUseful for contractors, partners and guest users.The sponsor may have left or changed role.
Multi-stage reviewCombines business and resource context.More stages require clear timing and escalation.

Recurrence

Reviews can run once or recur on a schedule such as monthly, quarterly, six-monthly or annually.

Frequency should reflect the sensitivity of the access and the speed at which the business relationship may change.

Review duration

Each review campaign needs enough time for reviewers to investigate and respond.

Very short campaigns cause rushed decisions; very long campaigns delay remediation and reduce urgency.

Designing the review cycle

Define scope │ ├── Select users and resources ├── Select reviewer or review stages ├── Set start date and duration ├── Set recurrence ├── Enable recommendations where useful ├── Configure reminders and escalation └── Define what happens when the review ends

Multi-stage reviews

A review can require more than one stage, such as manager review followed by resource-owner review.

This is valuable when no single person has enough context to assess both business need and technical risk.

Fallback reviewers

Fallback reviewers help prevent a review from stalling when the primary reviewer is unavailable, inactive or missing.

Fallback assignments should be tested before the campaign starts.

Recommendations and evidence

Microsoft Entra can provide recommendations based on signals such as recent sign-in activity.

EvidenceWhat it may indicateImportant caution
Recent sign-in activityThe user may still be actively using the application.Use does not automatically prove legitimate business need.
No recent sign-inThe access may be stale or unnecessary.Some resources are used infrequently but remain business-critical.
Manager or sponsor contextThe role or relationship still exists.The reviewer may not know the resource sensitivity.
Resource-owner contextThe user is still authorised for the data or system.The owner may not know whether the user's role changed.

Reviewer decisions

Reviewers typically approve, deny or leave an item unanswered.

Comments and justification improve auditability, especially when sensitive access is retained despite limited activity.

Default decisions

A policy may define what happens when a reviewer does not respond.

Automatically approving unanswered items can preserve stale access and weaken the control.

Applying review results

Review decision │ ├── Approve → access remains ├── Deny → access is removed ├── Not reviewed → default decision applies └── Recommendation → reviewer evaluates evidence │ ▼ Results applied automatically or manually

Automatic application improves consistency, but administrators should understand exactly which memberships, assignments or package entitlements will be removed.

Automatic remediation

When configured, Microsoft Entra can automatically remove denied access after the review completes.

This closes the gap between identifying stale access and actually revoking it.

Manual result application

Manual application may be appropriate when the organisation requires additional validation before removal.

However, unresolved review results can create a backlog where risky access remains despite a deny decision.

Access review investigation workflow

1. Identify the user and access under review 2. Confirm the review scope and campaign dates 3. Identify the assigned reviewer and fallback reviewer 4. Review recommendations and sign-in evidence 5. Check the reviewer decision and justification 6. Confirm whether the result was applied 7. Inspect audit logs for campaign and policy changes 8. Determine whether access was used after a deny decision 9. Remove inappropriate access and revoke active sessions if required 10. Correct reviewer, recurrence or remediation settings
Investigation question:

Did the user retain access because the reviewer made an informed decision, because the reviewer lacked context, or because the review result was never applied?

Real-world scenario: every user was approved

1. A quarterly review covers a sensitive finance application 2. The application owner is assigned as reviewer 3. The campaign contains 146 users 4. The owner receives no clear review instructions 5. Every user is approved within twelve minutes 6. Several users have not signed in for more than one year 7. Two users changed departments six months earlier 8. Audit records show no comments or individual investigation 9. The review is repeated with managers first and the resource owner second 10. Stale access is denied and automatically removed

Investigate review configuration

Review the scope, recurrence, reviewer assignment, fallback reviewers, recommendations, default decisions and result-application settings.

A poorly configured campaign may appear complete while failing to remove any access.

Investigate reviewer behaviour

Look for unusually fast bulk approvals, repeated approvals without comments and decisions that contradict available evidence.

These patterns may indicate review fatigue, insufficient context or deliberate control bypass.

Common mistakes

MistakeWhy it creates riskBetter practice
Review scope is too broadReviewers cannot meaningfully assess hundreds of unrelated assignments.Create focused campaigns by resource, role or business purpose.
Wrong reviewer selectedThe reviewer lacks business or resource context.Choose managers, sponsors or resource owners based on the decision required.
No fallback reviewerThe campaign stalls when the primary reviewer is unavailable.Configure and test fallback reviewers.
Automatic approval for unanswered itemsStale access remains when reviewers ignore the campaign.Use deny, remove or escalation for sensitive access.
Results are never appliedDenied access remains active.Enable automatic remediation or track manual completion.
Recommendations treated as final decisionsSign-in activity alone may not reflect business need.Combine recommendations with reviewer investigation and context.

Key takeaways

  • Access reviews confirm whether existing access remains justified.
  • Review scope should be focused and aligned with a clear business decision.
  • Managers, sponsors and resource owners provide different forms of context.
  • Recurrence should reflect the sensitivity and change rate of the access.
  • Recommendations support reviewers but do not replace judgement.
  • Review results must be applied for the control to reduce risk.
  • Investigations should connect review configuration, reviewer behaviour, decisions, remediation, audit logs and actual access use.

Continue learning

Continue through Microsoft Entra identity governance, or return to the academy roadmap.

Microsoft Entra Access Reviews

Microsoft Entra access reviews help organisations regularly verify group membership, enterprise application access, privileged roles and access package assignments.

Microsoft Entra Academy Lesson 10 — Access Reviews in Microsoft Entra

This Agent Foskett lesson explains review scope, reviewers, recurrence, recommendations, decisions, automatic remediation and access review investigation workflows.