Microsoft Entra ID Governance Access Package Workflow
An Access Package is a feature of Entitlement Management within Microsoft Entra ID Governance. With an Access Package, users gain self-service access to groups, applications, or SharePoint sites. You can also configure an Access Package to require approval before access is granted.
The post is a follow-up to my blog post, Configure Microsoft Entra ID Governance Entitlement Management Access Packages, and shows you the workflow for an Access Package.
In this post, I will show each stage of an Access Package, including approvals and views from the user, approver, and admin perspectives.
Prerequisites
- An active Access Package.
If you haven’t set up an Access Package, my blog post Configure Microsoft Entra ID Governance Entitlement Management Access Packages details the entire setup process.
The Process
There are several stages of an Access Package.
- User Request
- First Approval
- Second Approval
- Alternate Approvers
- Approval Not Actioned
- Request Denied
- User Cancel Access Request
- Access Granted
- Access Extend
- Access Review
- Access Ended
- Manual Assignments
User Request
To start the workflow for an Access Package, a user requests access to the Access Package.
- The user goes to https://myaccess.microsoft.com/
- The user clicks My Access > Access packages.
- The user finds the Access Package they want and, under Actions, clicks Request.
- On the Request details tab, the user clicks Continue.
If the user clicks the Resources tab, they can see what resources they will gain access to.
- The user fills in the required details, then they click Submit request.
If the Access Package has an expiry configured and the user enters a longer period, they will receive an error when submitting the request.
If a user does not enter specific period dates, the expiry countdown begins once they have access to the Access Package.
Once a user requests access to an Access Package, they cannot request it again until the request is approved or denied.
From the admin side, go to the Access Package, click Requests, and select the user to view the request details.
First Approval
If the Access Package has approvals configured, the user’s request is sent for approval.
- The first approvers will get an email about the access request.
The email approvers see shows the access start and end times in UTC, and the user’s answers are not visible.
- The first approver clicks the link in the email or goes to https://myaccess.microsoft.com/
- The first approver clicks My Access > Approvals.
- The first approver locates the request and clicks Review.
- The first approver can see some basic information, such as when they are required to make a decision.



















































