Agent Foskett Academy • Microsoft Entra • Module 1 • Lesson 8

Lesson 8 — Identity Governance Fundamentals

Granting access is only the beginning.

Microsoft Entra ID Governance helps organisations decide who should have access, what they should access, how long they should retain it and how that access should be reviewed throughout the identity lifecycle.

This lesson introduces identity lifecycle management, entitlement management, access packages, access reviews and the governance controls that reduce stale, excessive and unmonitored access.

Identity governance ensures that access remains appropriate after it has been granted.
Agent Foskett Microsoft Entra Identity Governance Fundamentals lesson
What you will learn

This lesson explains how Microsoft Entra governs access throughout the joiner, mover and leaver lifecycle.

Identity lifecycle management
Entitlement management
Access packages and reviews
Governance investigation workflow

Learning objectives

After completing this lesson, you should be able to explain how Microsoft Entra ID Governance controls access throughout an identity's lifecycle.

  • Explain identity governance and why it matters.
  • Describe joiner, mover and leaver processes.
  • Understand entitlement management and access packages.
  • Explain access reviews and recurring certification.
  • Recognise stale-access and governance investigation signals.

The problem this solves

Users often accumulate access as they change roles, join projects or work with external organisations.

Without governance, temporary access can become permanent, former staff may retain permissions and nobody may be able to explain why access still exists.

What is identity governance?

Identity governance is the set of policies, processes and technologies used to ensure that the right people have the right access to the right resources for the right amount of time.

Identity request │ ├── Who is requesting access? ├── What resources are required? ├── Who approves the request? ├── How long should access remain? ├── What conditions must be accepted? └── When must access be reviewed or removed?
Agent Foskett principle:

Access should have an owner, a business reason, an approval path and an expiry or review point.

Joiners

Joiner processes provide new users with the accounts, groups, applications and resources required for their role.

Good governance avoids copying another employee's permissions without validating whether all access is genuinely required.

Movers

Movers change roles, departments, locations or responsibilities.

They often receive new permissions without losing old ones, which creates access accumulation and separation-of-duties risk.

Leavers

Leaver processes remove access when employment, contracts or partnerships end.

Employment ends │ ├── Block sign-in ├── Revoke sessions ├── Remove group memberships ├── Remove application assignments ├── Remove privileged roles ├── Transfer owned resources └── Preserve evidence and records as required

Lifecycle workflows

Lifecycle workflows automate repeatable joiner, mover and leaver tasks based on identity attributes and organisational events.

Automation reduces delay and inconsistency, but workflows must be tested and monitored to ensure that critical access is not missed or retained.

Sources of identity truth

Human resources systems, contractor databases and other authoritative sources can drive identity lifecycle decisions.

Incorrect or delayed source data can create incorrect access, so ownership and data quality remain essential.

What is entitlement management?

Entitlement management helps organisations manage access to groups, applications and SharePoint sites through structured access packages.

It is especially useful when users require a collection of resources for a project, department, partner relationship or temporary assignment.

Access package │ ├── Microsoft Entra groups ├── Enterprise applications ├── SharePoint sites ├── Approval policy ├── Expiration policy └── Access review policy

Access packages

An access package bundles multiple resources into one governed request.

Instead of asking separate administrators for each permission, the requester follows a defined policy with approvals, duration and review controls.

Catalogues

Catalogues organise resources and access packages for a business area, project or external collaboration scenario.

Catalogue owners control which resources are available for governance and who can manage them.

Access package request flow

User requests access │ ├── Request policy checks eligibility ├── Business justification is provided ├── Manager or resource owner approves ├── Terms of use may be accepted ├── Access is granted for a defined period └── Access expires or enters review

Internal users

Employees can request access based on department, role, location, group membership or other eligibility rules.

Policies should prevent users from requesting access that conflicts with their responsibilities.

External users

Entitlement management can govern partner, supplier and guest access.

External identities should have clear sponsors, expiry dates and review cycles because their organisational relationship may change without internal administrators being notified.

Access reviews

Access reviews require reviewers to confirm whether users still need access to groups, applications, roles or access packages.

Review targetTypical reviewerQuestion
Group membershipGroup owner or managerDoes this user still require membership?
Application accessApplication ownerDoes this user still need the application?
Guest accessSponsor or resource ownerDoes the external relationship still exist?
Privileged rolesRole owner or security teamDoes this user still need privileged eligibility?
Access package assignmentManager or package ownerIs the original business purpose still valid?

Recurring reviews

Reviews can run monthly, quarterly, six-monthly or on another schedule appropriate to the risk.

High-impact, privileged and external access generally requires more frequent review.

Review decisions

Reviewers can approve, deny or defer decisions depending on the configuration.

Automatic recommendations can help, but reviewers remain responsible for validating the business need.

Terms of use

Terms of use can require users to acknowledge organisational conditions before accessing protected resources.

They may support acceptable-use, privacy, confidentiality or external collaboration requirements, but acceptance does not replace technical security controls.

Separation of duties

Separation of duties prevents one person from holding conflicting permissions that could enable fraud, unauthorised approval or unmonitored changes.

Governance policies should detect or prevent incompatible access combinations.

Access ownership

Every governed resource should have an accountable owner who understands who needs access and why.

Security teams can provide oversight, but business owners are often best positioned to validate ongoing need.

Governance investigation workflow

1. Identify the unexpected or stale access 2. Determine how the access was granted 3. Review the access package or assignment policy 4. Identify the requester, approver and resource owner 5. Review the original business justification 6. Check expiration and access-review history 7. Review Entra audit logs and sign-in activity 8. Determine whether the access was used 9. Remove or remediate inappropriate access 10. Document the control failure and improve the policy
Investigation question:

Do not ask only who has access. Ask why they have it, who approved it, when it expires and whether anyone has reviewed it.

Real-world scenario: the contractor left six months ago

1. A quarterly review identifies an external guest account 2. The contractor's project ended six months earlier 3. The account still belongs to two project groups 4. The guest retains access to a SharePoint site and enterprise application 5. No sponsor is assigned 6. The original access package had no expiration 7. Previous access reviews were never completed 8. Sign-in logs show recent authentication from a new country 9. Access is removed and sessions are revoked 10. The package is updated with sponsorship, expiry and recurring reviews

Investigate access use

Stale access becomes more serious when it has recently been used.

Review sign-in logs, application activity, SharePoint access, mailbox activity and Defender XDR telemetry to understand what occurred.

Investigate the approval path

Determine whether the request was approved by the correct person and whether the approver understood the resources being granted.

Weak approval paths can turn governance into a rubber-stamping exercise.

Common mistakes

MistakeWhy it creates riskBetter practice
Access packages without expirationTemporary access becomes permanent.Use appropriate assignment durations and renewal controls.
No named resource ownerNobody is accountable for validating access.Assign owners and maintain ownership when staff change.
Reviews that are never completedAccess remains even when business need has ended.Use reminders, escalation and automatic removal where suitable.
Managers approving unfamiliar accessThe reviewer may not understand the resource or risk.Include application and resource owners in the approval process.
Ignoring mover eventsUsers accumulate permissions across roles.Remove obsolete access whenever responsibilities change.
Unmanaged guest accountsExternal access may outlive the business relationship.Require sponsors, expiry and recurring guest reviews.

Key takeaways

  • Identity governance controls who receives access, why it is granted and how long it remains.
  • Joiner, mover and leaver processes must remove obsolete permissions as well as grant new ones.
  • Entitlement management uses access packages to bundle governed access.
  • Access reviews provide recurring confirmation that permissions are still required.
  • External and privileged access should have strong ownership, expiration and review controls.
  • Governance investigations connect approvals, assignments, reviews, audit logs and actual resource use.

Continue learning

Continue through Microsoft Entra identity governance, or return to the academy roadmap.
⬅ Previous lesson
Lesson 7 — Microsoft Entra Roles and Administrative UnitsReview built-in roles, least privilege and scoped administration.
🏠 Academy home
Microsoft Entra AcademyReview the roadmap and continue through the identity security learning path.
📘 Next lesson
Lesson 9 — Access Reviews and Entitlement ManagementExplore access review configuration, reviewer decisions, access packages and assignment policies in greater depth.

Microsoft Entra Identity Governance Fundamentals

Microsoft Entra ID Governance helps organisations manage identity lifecycle, access packages, entitlement management, access reviews, guest access and ongoing access certification.

Microsoft Entra Academy Lesson 8 — Identity Governance Fundamentals

This Agent Foskett lesson explains joiner, mover and leaver processes, lifecycle workflows, access packages, access reviews, ownership, expiration and identity governance investigations.