Access accumulates. Reviews are the only mechanism that ever takes any of it back.
Entra access reviews recertify group membership, application assignments and role assignments on a schedule, with the resource owner deciding rather than IT guessing. Microsoft is explicit that excessive access rights lead both to compromises and to audit findings, because they indicate a lack of control.

- Weekly to annuallyRecurring review frequencies
- Owner or selfReviewers can be either, or named
- Groups, apps, rolesPlus access packages and Azure roles
- Governance licenceSome capabilities work with P2
Six review types, created in four different places.
Security group and Microsoft 365 group membership
Created in access reviews or in Microsoft Entra groups. Reviewers can be specified individuals, the group owners, or the members themselves through self-review. The reviewer experience is the Access panel. This is the highest volume review type in most organisations and the one where delegating to group owners rather than IT changes the outcome most, because the owner actually knows who should be there.
Enterprise application assignments
Created in access reviews or in Microsoft Entra enterprise apps, with specified reviewers or self-review, again through the Access panel. Microsoft points to business critical applications specifically, noting that compliance processes might require people to regularly reconfirm and give a justification for why they need continued access. That justification is what an auditor asks for.
Microsoft Entra role assignments
Created in Privileged Identity Management rather than in access reviews, with the reviewer working in the Microsoft Entra admin center. Microsoft frames the trigger plainly: check how many users have administrative access, how many are Global Administrators, and whether any invited guests or partners were never removed after an administrative task.
Azure resource role assignments
Also created in Privileged Identity Management, also reviewed in the Microsoft Entra admin center, with User Access Administrator given as the example role. Azure resource roles are the ones that accumulate quietly during a project and stay assigned for years, because nobody owns the cleanup and the project team has moved on.
Access package assignments
Created in entitlement management, with reviewers who can be specified individuals, group members or the assignee through self-review, in the Access panel. Where entitlement management is already in use, this is the natural recertification point because the access package already carries the business framing that makes a review answerable.
Access rights from custom data resources, in preview
Reviewed by managers, created in access reviews, through the Access panel. Microsoft lists this as a preview capability. Manager-based review is a different model from owner-based review and suits organisations whose access decisions genuinely sit with line management rather than with resource owners.
Recurrence, which is what makes it a control
Microsoft describes setting up recurring reviews at frequencies such as weekly, monthly, quarterly or annually, with reviewers notified at the start of each review, approving or denying with the help of smart recommendations. A one-off review is a cleanup project. A recurring review is a control, and only the second one survives an audit question about how you know access is still appropriate.
Guest access, which nothing else cleans up
Microsoft is direct about the gap: employee access might be automated through lifecycle workflows based on HR data, but invited guests are not. If a group gives guests access to business sensitive content, Microsoft says it is the group owner responsibility to confirm the guests still have a legitimate business need. In practice guest review is where the first cycle finds the most.
Entra ID P2 covers some of this. It does not cover all of it.
Microsoft states the feature requires Microsoft Entra ID Governance or Microsoft Entra Suite subscriptions, and that some capabilities within it may operate with a Microsoft Entra ID P2 subscription.
- The published note is specific about what P2 does not reach: creating a review on inactive users, creating a review with user-to-group affiliation recommendations, and an access review of multiple resources together, which is in preview, all require a Microsoft Entra ID Governance licence.
- Those three are precisely the capabilities that make reviews efficient at scale. Inactive user review is the highest-yield first campaign in almost every organisation, and affiliation recommendations are what stop reviewers rubber-stamping.
- A plan built assuming P2 covers everything therefore delivers the least useful version of the feature, and the gap only becomes visible once someone tries to configure the review that would actually have found something.
- We establish which licence your tenant actually holds, and which of the reviews you want fall inside it, before any design work. That is a fifteen minute check that regularly changes the shape of the programme.
Four things that stop reviews becoming a rubber stamp.
We fix group ownership before we schedule anything
Delegating a review to the group owner is the single highest-impact design choice, and it fails immediately in estates where half the groups have no owner or an owner who left. Establishing real ownership is unglamorous work that has to happen first, because a review sent to nobody gets approved by default or expires unanswered.
We start where the risk is, not where the volume is
Microsoft names too many users in privileged roles as the first trigger, and it is the right one. Global Administrator counts, leftover partner and guest accounts from an administrative task, and Azure User Access Administrator assignments are a short list with a high yield. Starting with three hundred distribution groups trains everyone to click approve.
We treat guest review as its own campaign
Microsoft is explicit that lifecycle workflows based on HR data automate employee access but not invited guests, and that confirming a guest still has a legitimate business need is the group owner responsibility. Guests are almost always the highest-yield first cycle, and they are also the finding an auditor is most likely to raise.
We design what happens after the review, first
A denial that does not remove access is theatre. A non-response that silently approves is worse, because it produces evidence that says the access was reviewed. We decide the apply behaviour, the non-responder behaviour and the appeal route before the first campaign, since those three decisions determine whether anything actually changes.
Six UAE situations where reviews earn their place immediately.
A regulated financial firm facing a user access review finding
User access review is a standing item in almost every regulatory examination and internal audit programme. Recurring Entra reviews produce the evidence as a by-product rather than as a project, with a record of who reviewed what and when. That is a materially better answer than a spreadsheet with a signature at the bottom.
A group that grew by acquisition
Every acquisition brings groups whose purpose nobody documented and applications whose assignment lists nobody has looked at. Recurring reviews delegated to the owners in each acquired business surface that far faster than a central team trying to work it out, and they keep working after the integration project closes.
A professional services firm working with external partners
Guests join for a project and stay forever, because nothing removes them. Microsoft points specifically at group owners confirming that guests still have a legitimate business need for access to business sensitive content. In a firm where client work is organised by group and Team, that single review type usually removes more standing access than everything else combined.
An operator with contractors and seasonal staff
Access granted for a shutdown, a commissioning window or a seasonal peak is rarely revoked on schedule, because the people who granted it are focused on the next thing. Recurring reviews at monthly or quarterly frequency, aimed at the specific groups that carry that access, close the loop without needing anyone to remember.
A healthcare organisation with clinical system access
Clinical applications are exactly what Microsoft means by business critical applications where compliance processes might require people to reconfirm and justify continued access. Requiring a written justification, rather than a yes or no, changes the quality of the answer and gives an auditor something to read.
An education institution with high annual turnover
Students, researchers, visiting staff and short contracts produce more access churn in one year than a corporate estate produces in five. Recurring reviews aligned to the academic calendar, with self-review where appropriate and owner review where the resource is sensitive, keep the estate honest without a permanent cleanup team.
How UAE organisations recertify access today.
| Feature | Recurring Entra reviews | Annual spreadsheet exercise | No recertification |
|---|---|---|---|
Group membership recertified | Yes | Partly | No |
Application assignments recertified | Yes | Rarely | No |
Privileged roles recertified | Yes | Sometimes | No |
Reviewed by the person who knows | Yes | No | Not applicable |
Denials actually remove access | Yes | Sometimes | Not applicable |
Guests reviewed separately | Yes | No | No |
Recurs without anyone starting it | Yes | No | No |
Evidence produced automatically | Yes | Manually | No |
Recommendations assist the reviewer | Yes | No | No |
Effort per cycle | Low | High | None |
What you are reviewing decides where you create it.
| Access being reviewed | Created in | Who can review | Practical consequence | |
|---|---|---|---|---|
| Security group members | Access reviews, or Microsoft Entra groups | Specified reviewers, group owners, or self-review | Delegating to owners is the single change that improves review quality most | |
| Microsoft 365 group members | Access reviews, or Microsoft Entra groups | Specified reviewers, group owners, or self-review | Also governs the Team, the SharePoint site and anything else attached to the group | |
| Assigned to a connected app | Access reviews, or Microsoft Entra enterprise apps | Specified reviewers, or self-review | The place to require a written justification for business critical applications | |
| Microsoft Entra role | Privileged Identity Management | Specified reviewers, or self-review | Reviewer works in the admin center, not the Access panel, so brief them differently | |
| Azure resource role | Privileged Identity Management | Specified reviewers, or self-review | Where leftover project access hides, User Access Administrator especially | |
| Access package assignments | Entitlement management | Specified reviewers, group members, or self-review | The package already carries business framing, which makes the review answerable | |
| Custom data resources, in preview | Access reviews | Managers | A manager-based model rather than an owner-based one |
Five steps, and the first cycle is the one that teaches you everything.
- 1
Confirm entitlement and scope
Which licence the tenant holds, since Microsoft states the feature requires Entra ID Governance or Entra Suite while some capabilities may operate with Entra ID P2, and reviews on inactive users, affiliation recommendations and multi-resource reviews require Governance specifically. Then which groups, applications and roles are in scope, and in what order.
- 2
Fix ownership and reviewer assignment
Every in-scope group gets a real owner or a named reviewer, with a documented fallback for when that person leaves. Where self-review is used, we agree what makes it defensible. This is the step that determines whether the reviews get answered at all.
- 3
Design the review types in the right places
Group and application reviews in access reviews or the respective blade, Entra role and Azure resource role reviews in Privileged Identity Management, access package reviews in entitlement management. Reviewers are briefed on which experience they will see, since role reviews happen in the admin center rather than the Access panel.
- 4
Run the first cycle deliberately smaller than you want
Privileged roles and guests first, because that is where the yield is and where a bad process shows up quickly. We watch response rates, appeals and the number of denials, then adjust the scope, the wording and the frequency before widening.
- 5
Make it recurring and hand it over
Frequencies set per scope across the weekly to annual range Microsoft supports, notifications going to reviewers at the start of each cycle, evidence collected as a by-product, and a named owner for the programme itself. Without that last part the recurrence survives and the attention does not.
What organisations ask about Entra access reviews.
Fifteen decisions that determine whether reviews work.
Scope
- Which groups genuinely need reviewing?Reviewing everything trains reviewers to click approve.
- Which applications are business critical?Those are the ones worth a justification field.
- Are privileged roles in the first wave?Microsoft names this trigger first.
- Do you have Azure resource roles to review?They are created in PIM, not access reviews.
- Are guests scoped separately?Lifecycle workflows do not cover them.
Reviewers
- Group owner or named reviewer?Owners know more, named reviewers respond faster.
- Is self-review appropriate anywhere?It works where the user can be held to the answer.
- Do your groups have real owners?Many do not, and that has to be fixed first.
- Who reviews when the owner has left?Decide the fallback before the first cycle.
- Are reviewers trained on which portal?Role reviews use the admin center.
Afterwards
- What happens on a denial?Automatic removal or a manual queue.
- What happens when nobody responds?Configure it deliberately, do not inherit it.
- Who handles the appeals?There will be appeals in cycle one.
- Where is the evidence kept?This is what the auditor asks for.
- What frequency for each scope?Weekly through annually is supported.
The pages around this one.
Start with privileged roles and guests. Both take a week and both find things.
Every organisation we have run this for has been surprised by at least one of the two. The point is not the surprise, it is that the same review runs again next quarter without anyone starting it.
Related Services
Explore more solutions that work great with this service
Intune RBAC and Scope Tags
Least privilege for device administration
Entra ID Governance
Joiner mover leaver, access packages and guests that expire on their own
Privileged Identity Management
Just-in-time admin access, approval, and audit history you can download
Access Rights Review
Certification that removes access, not one that gets approved
Entra Conditional Access
The control that decides who reaches your data
Entra ID P1 vs P2
What P2 genuinely adds, and what quietly moved
Microsoft Security Dubai
Entra, Defender, Purview, Sentinel, and what you already own
Active Directory Audit
Privilege paths, service accounts and local admin passwords