Lesson 8 — Identity Governance Fundamentals
Granting access is only the beginning.
Microsoft Entra ID Governance helps organisations decide who should have access, what they should access, how long they should retain it and how that access should be reviewed throughout the identity lifecycle.
This lesson introduces identity lifecycle management, entitlement management, access packages, access reviews and the governance controls that reduce stale, excessive and unmonitored access.

What you will learn
This lesson explains how Microsoft Entra governs access throughout the joiner, mover and leaver lifecycle.
Learning objectives
After completing this lesson, you should be able to explain how Microsoft Entra ID Governance controls access throughout an identity's lifecycle.
- Explain identity governance and why it matters.
- Describe joiner, mover and leaver processes.
- Understand entitlement management and access packages.
- Explain access reviews and recurring certification.
- Recognise stale-access and governance investigation signals.
The problem this solves
Users often accumulate access as they change roles, join projects or work with external organisations.
Without governance, temporary access can become permanent, former staff may retain permissions and nobody may be able to explain why access still exists.
What is identity governance?
Identity governance is the set of policies, processes and technologies used to ensure that the right people have the right access to the right resources for the right amount of time.
Access should have an owner, a business reason, an approval path and an expiry or review point.
Joiners
Joiner processes provide new users with the accounts, groups, applications and resources required for their role.
Good governance avoids copying another employee's permissions without validating whether all access is genuinely required.
Movers
Movers change roles, departments, locations or responsibilities.
They often receive new permissions without losing old ones, which creates access accumulation and separation-of-duties risk.
Leavers
Leaver processes remove access when employment, contracts or partnerships end.
Lifecycle workflows
Lifecycle workflows automate repeatable joiner, mover and leaver tasks based on identity attributes and organisational events.
Automation reduces delay and inconsistency, but workflows must be tested and monitored to ensure that critical access is not missed or retained.
Sources of identity truth
Human resources systems, contractor databases and other authoritative sources can drive identity lifecycle decisions.
Incorrect or delayed source data can create incorrect access, so ownership and data quality remain essential.
What is entitlement management?
Entitlement management helps organisations manage access to groups, applications and SharePoint sites through structured access packages.
It is especially useful when users require a collection of resources for a project, department, partner relationship or temporary assignment.
Access packages
An access package bundles multiple resources into one governed request.
Instead of asking separate administrators for each permission, the requester follows a defined policy with approvals, duration and review controls.
Catalogues
Catalogues organise resources and access packages for a business area, project or external collaboration scenario.
Catalogue owners control which resources are available for governance and who can manage them.
Access package request flow
Internal users
Employees can request access based on department, role, location, group membership or other eligibility rules.
Policies should prevent users from requesting access that conflicts with their responsibilities.
External users
Entitlement management can govern partner, supplier and guest access.
External identities should have clear sponsors, expiry dates and review cycles because their organisational relationship may change without internal administrators being notified.
Access reviews
Access reviews require reviewers to confirm whether users still need access to groups, applications, roles or access packages.
| Review target | Typical reviewer | Question |
|---|---|---|
| Group membership | Group owner or manager | Does this user still require membership? |
| Application access | Application owner | Does this user still need the application? |
| Guest access | Sponsor or resource owner | Does the external relationship still exist? |
| Privileged roles | Role owner or security team | Does this user still need privileged eligibility? |
| Access package assignment | Manager or package owner | Is the original business purpose still valid? |
Recurring reviews
Reviews can run monthly, quarterly, six-monthly or on another schedule appropriate to the risk.
High-impact, privileged and external access generally requires more frequent review.
Review decisions
Reviewers can approve, deny or defer decisions depending on the configuration.
Automatic recommendations can help, but reviewers remain responsible for validating the business need.
Terms of use
Terms of use can require users to acknowledge organisational conditions before accessing protected resources.
They may support acceptable-use, privacy, confidentiality or external collaboration requirements, but acceptance does not replace technical security controls.
Separation of duties
Separation of duties prevents one person from holding conflicting permissions that could enable fraud, unauthorised approval or unmonitored changes.
Governance policies should detect or prevent incompatible access combinations.
Access ownership
Every governed resource should have an accountable owner who understands who needs access and why.
Security teams can provide oversight, but business owners are often best positioned to validate ongoing need.
Governance investigation workflow
Do not ask only who has access. Ask why they have it, who approved it, when it expires and whether anyone has reviewed it.
Real-world scenario: the contractor left six months ago
Investigate access use
Stale access becomes more serious when it has recently been used.
Review sign-in logs, application activity, SharePoint access, mailbox activity and Defender XDR telemetry to understand what occurred.
Investigate the approval path
Determine whether the request was approved by the correct person and whether the approver understood the resources being granted.
Weak approval paths can turn governance into a rubber-stamping exercise.
Common mistakes
| Mistake | Why it creates risk | Better practice |
|---|---|---|
| Access packages without expiration | Temporary access becomes permanent. | Use appropriate assignment durations and renewal controls. |
| No named resource owner | Nobody is accountable for validating access. | Assign owners and maintain ownership when staff change. |
| Reviews that are never completed | Access remains even when business need has ended. | Use reminders, escalation and automatic removal where suitable. |
| Managers approving unfamiliar access | The reviewer may not understand the resource or risk. | Include application and resource owners in the approval process. |
| Ignoring mover events | Users accumulate permissions across roles. | Remove obsolete access whenever responsibilities change. |
| Unmanaged guest accounts | External access may outlive the business relationship. | Require sponsors, expiry and recurring guest reviews. |
Key takeaways
- Identity governance controls who receives access, why it is granted and how long it remains.
- Joiner, mover and leaver processes must remove obsolete permissions as well as grant new ones.
- Entitlement management uses access packages to bundle governed access.
- Access reviews provide recurring confirmation that permissions are still required.
- External and privileged access should have strong ownership, expiration and review controls.
- Governance investigations connect approvals, assignments, reviews, audit logs and actual resource use.
Related Agent Foskett resources
Continue learning
Microsoft Entra Identity Governance Fundamentals
Microsoft Entra ID Governance helps organisations manage identity lifecycle, access packages, entitlement management, access reviews, guest access and ongoing access certification.
Microsoft Entra Academy Lesson 8 — Identity Governance Fundamentals
This Agent Foskett lesson explains joiner, mover and leaver processes, lifecycle workflows, access packages, access reviews, ownership, expiration and identity governance investigations.
