Skip to content

Commit e1e435e

Browse files
Merge pull request #53068 from R-C-Stewart/update-access-reviews
update access review
2 parents 1634230 + 67cb8fd commit e1e435e

11 files changed

Lines changed: 150 additions & 63 deletions
Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
### YamlMime:ModuleUnit
2+
uid: learn.wwl.plan-implement-manage-access-review.access-review-agent
3+
title: Explore the Access Review Agent in Microsoft Entra
4+
metadata:
5+
title: Explore the Access Review Agent in Microsoft Entra
6+
description: "Explore Access Review Agent in Microsoft Entra"
7+
ms.date: 01/8/2026
8+
author: wwlpublish
9+
ms.author: roberts
10+
ms.topic: unit
11+
ms.custom:
12+
- N/A
13+
durationInMinutes: 5
14+
content: |
15+
[!include[](includes/7a-access-review-agent.md)]

learn-pr/wwl-sci/plan-implement-manage-access-review/includes/1-introduction.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
1-
Once identity is deployed, you'll learn that proper governance is required. Using access reviews is necessary for a secure solution. Explore how you plan for and implement access reviews.
1+
Once identity is deployed, you learn that proper governance is required. Using access reviews is necessary for a secure solution. Explore how you plan for and implement access reviews.
22

3-
In this module, you will learn all about access reviews. Knowledge covered includes why access reviews are important to the security of your organization, and how to prepare for and perform them. Additionally you explore how to configure access reviews to occur on a recurring basis.
3+
In this module, you learn all about access reviews. Knowledge covered includes why access reviews are important to the security of your organization, and how to prepare for and perform them. Additionally you explore how to configure access reviews to occur on a recurring basis.
44

55
## Learning objectives
66

learn-pr/wwl-sci/plan-implement-manage-access-review/includes/2-plan-for-access-reviews.md

Lines changed: 30 additions & 30 deletions
Large diffs are not rendered by default.

learn-pr/wwl-sci/plan-implement-manage-access-review/includes/3-create-access-reviews-for-groups-apps.md

Lines changed: 16 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -21,13 +21,13 @@ Access to groups and applications for employees and guests changes over time. To
2121

2222
:::image type="content" source="../media/select-what-review.png" alt-text="Screenshot of the Create an access review - Review name and description dialog.":::
2323

24-
5. If you selected **Teams + Groups** in Step 1, you've two options in Step 2:
24+
5. If you selected **Teams + Groups** in Step 1, you have two options in Step 2:
2525

2626

2727
- **All Microsoft 365 groups with guest users**. Select this option if you would like to create recurring reviews on all your guest users across all your Microsoft Teams and Microsoft 365 groups in your organization. You can choose to exclude certain groups by selecting "Select group(s) to exclude."
28-
- **Select teams + groups**. Select this option if you would like to specify a finite set of teams and/or groups to review. After selecting on this option, you'll see a list of groups to the right to pick from.
28+
- **Select teams + groups**. Select this option if you would like to specify a finite set of teams and/or groups to review. After selecting this option, you'll see a list of groups to the right to pick from.
2929

30-
:::image type="content" source="../media/teams-groups.png" alt-text="Screenshot of the Teams and groups settings. Pick your groups to exclude.":::
30+
:::image type="content" source="../media/teams-groups.png" alt-text="Screenshot of the Teams and groups settings. Pick your groups to exclude.":::
3131

3232
:::image type="content" source="../media/teams-groups-detailed.png" alt-text="Screenshot of the Teams and groups chosen in the user interface. Selected items are excluded.":::
3333

@@ -43,15 +43,15 @@ Access to groups and applications for employees and guests changes over time. To
4343

4444
> [!NOTE]
4545
> If you selected All Microsoft 365 groups with guest users in Step 2, then your only option is to review Guest users in Step 3.
46-
8. Select on Next: Reviews
46+
8. Select **Next: Reviews**
4747
9. In the **Select reviewers** section, select one or more people to perform the access reviews. You can choose from:
4848

4949

5050
- **Group owner(s)** (Only available when performing a review on a team or group)
5151
- **Selected user(s) or groups(s)**
5252
- **Users review own access**
53-
- **(Preview) Managers of users**. If you choose either **Managers of users** or **Group owners,** you also have the option to specify a fallback reviewer. Fallback reviewers are asked to do a review when the user has no manager specified in the directory or the group doesn't have an owner.
54-
10. In the **Specify recurrence of review** section, you can specify a frequency such as **Weekly, Monthly, Quarterly, Semi-annually, Annually**. You then specify a **Duration**, which defines how long a review will be open for input from reviewers. For example, the maximum duration that you can set for a monthly review is 27 days to avoid overlapping reviews. You might want to shorten the duration to ensure that your reviewers input is applied earlier. Next, you can select a **Start date** and **End date**.
53+
- **(Preview) Managers of users**. If you choose either **Managers of users** or **Group owners,** you can also specify a fallback reviewer. Fallback reviewers are asked to do a review when the user has no manager specified in the directory or the group doesn't have an owner.
54+
10. In the **Specify recurrence of review** section, you can specify a frequency such as **Weekly, Monthly, Quarterly, Semi-annually, Annually**. You then specify a **Duration**, which defines how long a review is open for input from reviewers. For example, the maximum duration that you can set for a monthly review is 27 days to avoid overlapping reviews. You might want to shorten the duration to ensure that your reviewers input is applied earlier. Next, you can select a **Start date** and **End date**.
5555

5656
:::image type="content" source="../media/frequency.png" alt-text="Screenshot of the Choose how often the review should happen. Admins should set a reasonable timeline.":::
5757

@@ -61,7 +61,7 @@ Access to groups and applications for employees and guests changes over time. To
6161
:::image type="content" source="../media/upon-completion-settings-new.png" alt-text="Screenshot of the Create an access review - upon completion settings.":::
6262

6363

64-
If you want to automatically remove access for denied users, set **Auto apply results to resource** to **Enable**. If you want to manually apply the results when the review completes, set the switch to **Disable**. Use the **If reviewers don't respond** list to specify what happens for users that aren't reviewed by the reviewer within the review period. This setting doesn't impact users who have been reviewed by the reviewers manually. If the final reviewer's decision is Deny, then the user's access will be removed.
64+
If you want to automatically remove access for denied users, set **Auto apply results to resource** to **Enable**. If you want to manually apply the results when the review completes, set the switch to **Disable**. Use the **If reviewers don't respond** list to specify what happens for users that aren't reviewed by the reviewer within the review period. This setting doesn't change users who were reviewed manually. If the final reviewers' decision is Deny, then the user's access is removed.
6565

6666

6767
- No change - Leave user's access unchanged
@@ -72,37 +72,37 @@ Access to groups and applications for employees and guests changes over time. To
7272
Use the Action to apply on denied **guest** users to specify what happens to guest users if they're denied.
7373

7474

75-
- **Remove user’s membership from the resource** will remove denied user’s access to the group or application being reviewed, they'll still be able to sign-in to the tenant.
76-
- **Block user from signing in for 30 days, then remove user from the tenant** will block the denied users from signing in to the tenant, regardless if they have access to other resources. If there was a mistake or if an admin decides to re-enable one’s access, they can do so within 30 days after the user has been disabled. If there's no action taken on the disabled users, they'll be deleted from the tenant.
75+
- **Remove user’s membership from the resource** removes denied user’s access to the group or application being reviewed, they'll still be able to sign-in to the tenant.
76+
- **Block user from signing in for 30 days, then remove user from the tenant** blocks the denied users from signing in to the tenant, regardless if they have access to other resources. If there was a mistake or if an admin decides to re-enable one’s access, they can do so within 30 days after the user is disabled. If there's no action taken on the disabled users, they are deleted from the tenant.
7777
- Action to apply on denied guest users isn't configurable on reviews scoped to more than guest users. It's also not configurable for reviews of all Microsoft 365 groups with guest users. When not configurable, the default option of removing user's membership from the resource is used on denied users.
7878
13. In **Enable review decision helpers** choose whether you would like your reviewer to receive recommendations during the review process.
7979

80-
:::image type="content" source="../media/helpers.png" alt-text="Screenshot of the Enable decision helpers options. Offer recommendations to the reviewers.":::
80+
:::image type="content" source="../media/helpers.png" alt-text="Screenshot of the Enable decision helpers options. Offer recommendations to the reviewers.":::
8181

8282
14. In the **Advanced settings** section, you can choose the following
8383

8484

8585
- Set **Justification required** to **Enable** to require the reviewer to supply a reason for approval.
8686
- Set **email notifications** to **Enable** to have Microsoft Entra ID send email notifications to reviewers when an access review starts, and to administrators when a review completes.
87-
- Set **Reminders** to **Enable** to have Microsoft Entra ID send reminders of access reviews in progress to reviewers who haven't completed their review. These reminders will be half-way through the duration of the review.
88-
- The content of the email sent to reviewers is autogenerated based on the review details, such as review name, resource name, due date, etc. If you need a way to communicate additional information, such as additional instructions or contact information, you can specify these details in the **Additional content for reviewer email** section. The information that you enter is included in the invitation and reminder emails sent to assigned reviewers. The section highlighted in the image below shows where this information is displayed.
87+
- Set **Reminders** to **Enable** to have Microsoft Entra ID send reminders of access reviews in progress to reviewers who haven't completed their review. These reminders are half-way through the duration of the review.
88+
- The content of the email sent to reviewers is autogenerated based on the review details, such as review name, resource name, due date, etc. If you need a way to communicate additional information, such as extra instructions or contact information, you can specify these details in the **Additional content for reviewer email** section. The information that you enter is included in the invitation and reminder emails sent to assigned reviewers. The section highlighted in the image below shows where this information is displayed.
8989
15. Select **Next: Review + Create** to move to the next page.
9090
16. Name the access review. Optionally, give the review a description. The name and description are shown to the reviewers.
9191
17. Review the information and select **Create**.
9292

93-
:::image type="content" source="../media/create-review.png" alt-text="Screenshot of the create review screen. Overview of the access review that has just finished creation.":::
93+
:::image type="content" source="../media/create-review.png" alt-text="Screenshot of the create review screen. Overview of the access review that finished creation.":::
9494

9595

9696
## Start the access review
9797

98-
Once you've specified the settings for an access review, select **Start**. The access review will appear in your list with an indicator of its status.
98+
Once you've specified the settings for an access review, select **Start**. The access review appears in your list with an indicator of its status.
9999

100100
:::image type="content" source="../media/access-reviews-list.png" alt-text="Screenshot of the List of access reviews and their status. Review the status of each item.":::
101101

102102

103103
By default, Microsoft Entra ID sends an email to reviewers shortly after the review starts. If you choose not to have Microsoft Entra ID send the email, be sure to inform the reviewers that an access review is waiting for them to complete. You can show them the instructions for how to review access to groups or applications. If your review is for guests to review their own access, show them the instructions for how to review access for yourself to groups or applications.
104104

105-
If you've assigned guests as reviewers and they haven't accepted the invite, they'll not receive an email from access reviews because they must first accept the invitation prior to reviewing.
105+
If you've assigned guests as reviewers and they haven't accepted the invite, they don't receive an email from access reviews because they must first accept the invitation.
106106

107107
## Access review status table
108108

@@ -117,7 +117,7 @@ If you've assigned guests as reviewers and they haven't accepted the invite, the
117117
| Auto-Reviewed | Decisions have been recorded by the system for all users who weren't reviewed. Review is ready to proceed to **Applying** if Auto-Apply is enabled. |
118118
| Applying | There will be no change in access for users who were approved. |
119119
| Applied | Denied users, if any, have been removed from the resource or directory. |
120-
| Failed | Review could not progress. This error could be related to the deletion of the tenant, a change in licenses, or other internal tenant changes. |
120+
| Failed | Review couldn't progress. This error could be related to the deletion of the tenant, a change in licenses, or other internal tenant changes. |
121121

122122
## Create reviews via APIs
123123

learn-pr/wwl-sci/plan-implement-manage-access-review/includes/4-create-configure-access-review-programs.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -6,9 +6,9 @@ You can also create an access review in PowerShell with the `New-MgIdentityGover
66

77
The access reviews API in Microsoft Graph enables organizations to audit and attest to the access that identities are assigned to resources in the organization. For example, access to a SharePoint site that contains customer contact information. And by using the access reviews API, organizations can check and attest to access to such groups and by extension, resources.
88

9-
## Access Review API for a security groups
9+
## Access Review API for security groups
1010

11-
This learning module doesn't recreate the step by step method to use the API, to get that information see the article - [Review access to security groups using access reviews APIs.](/graph/tutorial-accessreviews-securitygroup) Here are the high level steps that need to be performed.
11+
This learning module doesn't recreate the step-by-step method to use the API, to get that information see the article - [Review access to security groups using access reviews APIs.](/graph/tutorial-accessreviews-securitygroup) Here are the high-level steps that need to be performed.
1212

1313
1. Create an access review for the security group
1414
2. List instances of the access review

learn-pr/wwl-sci/plan-implement-manage-access-review/includes/5-monitor-findings.md

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -20,11 +20,11 @@ You can start the Access Review process from the notification email or by going
2020
> If the Access reviews tile isn't visible, there are no access reviews to perform for that organization and no action is needed at this time.
2121
4. Select the **Begin review** link for the access review you want to perform.
2222

23-
Once you have opened the access review, you see the names of users who need to have their access reviewed.
23+
Once you open the access review, you see the names of users who need to have their access reviewed.
2424

2525
There are two ways that you can approve or deny access:
2626

27-
- You can approve or deny access for one or more users 'manually' by choosing the appropriate action for each user request.
27+
- You can approve or deny access for one or more users manually by choosing the appropriate action for each user request.
2828
- You can accept the system recommendations.
2929

3030
### Approve or deny access for one or more users
@@ -37,20 +37,20 @@ There are two ways that you can approve or deny access:
3737
2. Select **Approve** or **Deny**.
3838

3939
> [!NOTE]
40-
> If you are unsure, you can select "Don't know" and the user gets to keep their access and your choice is recorded in the audit logs.
40+
> If you're unsure, you can select "Don't know" and the user gets to keep their access and your choice is recorded in the audit logs.
4141
3. The administrator of the access review can require that you supply a reason in the **Reason** box for your decision.
4242

4343

44-
- Even when a reason is not required. You can still provide a reason for your decision and the information that you include will be available to other reviewers.
45-
4. Once you have specified the action to take, select **Save**.
44+
- Even when a reason isn't required, you can still provide a reason for your decision and the information that you include is available to other reviewers.
45+
4. Once you specify the action to take, select **Save**.
4646

4747

48-
- If a user is denied access, they aren't removed immediately. They are removed when the review period has ended. Or when an administrator stops the review if [Auto apply](/azure/active-directory/governance/complete-access-review) is enabled.
48+
- If a user is denied access, they aren't removed immediately. They're removed when the review period ends or when an administrator stops the review if [Auto apply](/azure/active-directory/governance/complete-access-review) is enabled.
4949
- If there are multiple reviewers, the last submitted response is recorded. Consider an example where an administrator designates two reviewers – Alice and Bob. Alice opens the access review first and approves a user's access request. Before the review period ends, Bob opens the access review and denies access on the same request previously approved by Alice. The last decision denying the access is the response that gets recorded.
5050

5151
### Approve or deny access based on recommendations
5252

5353
To make access reviews easier and faster for you, we also provide recommendations that you can accept with a single acceptance. The recommendations are generated based on the user's sign-in activity.
5454

5555
1. In the blue bar at the bottom of the page, select **Accept recommendations**. You see a summary of the recommended actions.
56-
2. Select **Ok** to accept the recommendations.
56+
2. Select **OK** to accept the recommendations.

0 commit comments

Comments
 (0)