Lesson 9 — Entitlement Management and Access Packages
Access should not be granted through informal requests, copied permissions or permanent group membership.
Microsoft Entra entitlement management provides a structured way to package resources, define who may request them, require approval, set expiration and review access throughout its lifecycle.
This lesson explains catalogues, access packages, request policies, approval workflows, assignment duration, renewals, connected organisations and the investigation evidence behind governed access.

What you will learn
This lesson explains how Microsoft Entra packages and governs access for employees, contractors and external users.
Learning objectives
After completing this lesson, you should be able to design and investigate Microsoft Entra entitlement management workflows.
- Explain catalogues and access packages.
- Describe resources, roles and assignment policies.
- Understand approvals, questions and business justification.
- Configure expiration, renewal and recurring reviews conceptually.
- Investigate unexpected or inappropriate access package assignments.
The problem this solves
Users often need several resources at once for a project, department or external engagement.
Without entitlement management, every resource may require a separate request, approval and manual removal, creating inconsistency and stale access.
What is entitlement management?
Entitlement management is a Microsoft Entra ID Governance capability that automates access request, approval, assignment, expiration and review processes.
An access package is not just a collection of permissions. It is a governed lifecycle for those permissions.
Catalogues
A catalogue is a container for resources and access packages owned by a business area, project or governance team.
Catalogue owners decide which groups, applications and SharePoint resources may be included.
Catalogue ownership
Ownership should sit with people who understand the business purpose and risk of the resources.
Security teams can provide standards and oversight, but resource owners should remain accountable for access decisions.
Access packages
An access package combines multiple resource roles into a single governed access offering.
| Resource type | Example role in the package | Purpose |
|---|---|---|
| Microsoft Entra group | Member or owner | Provide team, licensing or application access through group membership. |
| Enterprise application | User or application-specific role | Grant access to a SaaS or line-of-business application. |
| SharePoint site | Member or visitor | Provide project files, records or collaboration access. |
Resource roles
Each resource can expose one or more roles, such as group member, group owner, application user or SharePoint visitor.
Package designers should choose the least-privileged role that supports the business task.
Package design
Access packages should represent a clear business purpose such as Project Phoenix Contributor, External Auditor or Finance Reporting User.
Avoid oversized packages that grant unrelated access simply for administrative convenience.
Request policies
Request policies determine who can request an access package and under what conditions.
Business justification
Requesters can be required to explain why they need access.
Justification should be specific enough for an approver and investigator to understand the business purpose later.
Custom questions
Packages can collect additional information such as project name, sponsor, cost centre, expected end date or data-handling requirement.
Good questions improve approval quality and provide useful investigation evidence.
Approval workflows
| Approval model | When it may fit | Risk consideration |
|---|---|---|
| No approval | Low-risk access for a tightly controlled eligible population. | Eligibility and expiration must still be appropriate. |
| Manager approval | The manager understands the user's role and need. | The manager may not understand the technical resource risk. |
| Resource owner approval | The owner understands the application, group or site. | The owner may not understand the requester's business role. |
| Multi-stage approval | High-impact, sensitive or external access. | Too many stages can cause delays and rubber-stamping. |
Approval timeout
Requests should not remain open indefinitely.
Policies can define what happens when an approver does not respond, including escalation to an alternate approver.
Approver quality
An approver should understand either the requester's need, the resource risk or both.
Approval should not be treated as a notification or automatic formality.
Assignment duration and expiration
Time-limited assignment is one of the strongest entitlement management controls because temporary business access is automatically removed.
Renewal
Renewal allows an assignment to continue after the original expiration when the business need remains valid.
Renewal should require fresh justification and, for sensitive access, renewed approval.
Automatic removal
When an assignment expires or is removed, Microsoft Entra removes the resource roles delivered through the package.
Investigators should confirm whether any separately assigned access remains outside the package.
Connected organisations and external access
Connected organisations represent external directories or partner relationships that may request access packages.
Guest sponsorship
External users should have a sponsor who understands why the relationship exists and when it should end.
Missing or inactive sponsors are strong indicators that external access may be stale.
External lifecycle
When an external user's last governed assignment ends, the organisation should decide whether the guest account should remain or be automatically removed.
This prevents unused guest identities from accumulating indefinitely.
Access reviews for package assignments
Access reviews can periodically ask whether users still require their access package assignments.
| Reviewer | Useful when | Key question |
|---|---|---|
| User self-review | The user can confirm whether the task or project continues. | Do I still need this access? |
| Manager | The manager understands the user's responsibilities. | Does this role still require the package? |
| Resource owner | The owner understands the data or application risk. | Should this user retain access to my resource? |
| Sponsor | The assignment belongs to an external user. | Does the partner relationship still exist? |
Review recommendations
Microsoft Entra may provide recommendations based on sign-in activity or other signals.
Recommendations help reviewers, but they do not replace business context or investigation.
Default decisions
Policies may define what happens when reviewers do not respond.
For sensitive access, automatically approving unanswered reviews can undermine the purpose of certification.
Entitlement management investigation workflow
Was the access inappropriate because the request was malicious, the approval was weak, the package was badly designed or the assignment simply outlived its business need?
Real-world scenario: the project access never expired
Investigate package changes
Review audit logs for changes to package resources, request policies, approvers, assignment duration and review configuration.
An attacker or careless administrator may weaken governance without directly assigning access.
Investigate actual use
Determine whether the access was used and what actions occurred in the application, group or SharePoint site.
Entitlement records explain how access was granted; workload telemetry explains what the user did with it.
Common mistakes
| Mistake | Why it creates risk | Better practice |
|---|---|---|
| Packages that include too many resources | Users receive access unrelated to their task. | Create purpose-specific packages using least privilege. |
| No expiration | Temporary access becomes permanent. | Set a duration or specific end date and require renewal. |
| Manager-only approval for sensitive applications | The manager may not understand the resource risk. | Include the resource owner or use multi-stage approval. |
| Weak business justification | Approvers and investigators cannot validate the request. | Require specific justification and useful custom questions. |
| No access review | Assignments continue after projects or roles change. | Schedule recurring reviews based on access sensitivity. |
| Ignoring separately assigned access | Removing the package may not remove every permission. | Check direct, group-based and privileged assignments separately. |
Key takeaways
- Catalogues organise governed resources and access packages.
- Access packages bundle groups, applications and SharePoint roles around a clear business purpose.
- Request policies define who may request, who approves and what information must be provided.
- Expiration, renewal and access reviews prevent temporary access from becoming permanent.
- Connected organisations help govern external and guest access.
- Investigations should connect the request, approval, assignment, review, audit and actual resource activity.
Related Agent Foskett resources
Continue learning
Microsoft Entra Entitlement Management and Access Packages
Microsoft Entra entitlement management helps organisations govern access through catalogues, access packages, request policies, approval workflows, expiration, renewal and access reviews.
Microsoft Entra Academy Lesson 9 — Entitlement Management and Access Packages
This Agent Foskett lesson explains access package resources, catalogue ownership, assignment policies, connected organisations, external user governance and access investigations.
