Configure Microsoft Entra ID Governance Entitlement Management Access Packages

Configure Microsoft Entra ID Governance Entitlement Management Access Packages

Microsoft Entra ID Governance has many cool features, one of them is Entitlement Management. Within Entitlement Management is the Access Packages feature.

Access Packages allow you to configure user self-service access to groups, applications, or SharePoint sites. You can set an Access Package to use a specific approver or a dynamic one, such as the user’s manager. You can also configure access reviews to help address users having access to things they no longer need.

An example use case for an Access Package is configuring it so a user can request Visio and have their manager approve the request. Once approved, the Access Package adds the user to the Visio licensing group, which allocates them a license. If Intune is configured, the user can then install Visio themselves via Company Portal.

You can delegate the setup of Access Packages for a department to someone in that department, allowing them to self-manage how their department members get the access they need for the projects or tasks they are working on.

In this post, I will show you step by step how to create an Access Package.

Prerequisites

To use the basics of Entitlement Management, including Access Packages, you need the following license.

If you want to unlock all the advanced features of Entitlement Management and Identity Governance, you need to have one of the following licenses.

The Process

The rest of the process is divided into the following sections.

Catalogs

Before creating an Access Package, we need to create a Catalog. A Catalog is a collection of resources that Access Packages can use. Catalogs help organize resources and can enable delegated management without excessive permissions.

In my example, I will enter the name as Project Neo and the description as Access to project Neo.

In my example, I will select Yes.

In my example, I will select No.

In my example, I will click on the Project Neo catalog I just created.

In my example, I will add the cloud security group named SG-Project-Neo.

Access Packages

Once we have created the Catalog, we can create the Access Package within the Catalog so users can request access to the resources in it.

Access Package – Basics

The name and description of the Access Package will be visible to users.

In my example, I will enter the name as Project Neo and the description as 3 month access to project Neo.

Access Package – Resource roles

Now we can add the resources from the Catalog to the Access Package so users can request access to them.

In my example, I will select the security group named SG-Project-Neo.

In my example, I will select the role member.

Access Package – Requests

Now we need to configure how Access Package requests are handled.

In my example, I will select For users, service principals, and agent identities in your directory.

In my example, I will select All members (excluding guests).

In my example, I will select Self.

In my example, I will set Require requestor justification to No.

Users will always see the Business justification box when requesting access to an Access Package regardless of the require requestor justification setting. The setting only controls if input is required.

When an Access Package requires approval, you can have the user’s manager approve it, or you can set a static approver.

In my example, I will set Require approval to Yes.

In my example, I want to require two approvals. I will set Require approval to Yes and set the approval stages to 2.

In my example, I will set the First Approver to the Manager.

When setting a manager or sponsor as an approver, you need to set a Fallback approver in case the Manager or Sponsor information is not populated. Specific approvers don’t need a fallback approver.

In my example, I will select the group named First Approver Manager Fallback.

In my example, I will set this to 4 days.

In my example, I will set this to Yes.

The default setting is to show the approver details.

In my example, I will leave this set to default.

In my example, I will set this to Yes.

In my example, I will set this to Second level manager as alternate approver.

When setting second level manager as an approver, you need to set a Fallback approver in case the Manager information is not populated. Specific approvers do not need a fallback.

In my example, I will select the group named Second Level Manager Approver Fallback.

The number of days must be less than the maximum number of days of the initial first approval.

In my example, I will set this to 2 days.

Below is an image of my first approver settings.

In my example, I will select specific approvers.

In my example, I will select the group named Second Approvers.

In my example, I will set this to 7 days.

In my example, I will set this to No.

In my example, I will set this to No.

In my example, I will set this to No.

In my example, I will set this to No to keep everyone involved informed.

In my example, I will skip that section as I don’t have the license for it.

Access Package – Requestor information

Now we can configure the Requestor information to gather data from the user when they request access to an Access Package. The information can be in the form of questions or attributes.

Requestor information is optional.

In my example, I will request information from the user through questions.

In my example, I will add a question to ask the user if they know the internal project codename.

If you support multiple languages, click on add localization to add different wording for the question in other languages.

In my example, I will select Short text.

In my example, I will leave this blank.

In my example, I will select Required.

In my example, I will add another question asking the user to explain why they need access, set the answer format to Long text, and mark it as Required.

In my example, I will enter Yes.

In my example, I will select English (United States).

In my example, I will enter Yes.

In my example, I will add another option for No.

Access Package – Lifecycle

Now we can configure the Lifecycle of the Access Package, including how long a user can have access, if they can extend it, and access reviews.

In my example, I will select number of days.

In my example, I will enter 90 days.

In my example, I will set this to Yes.

If the Users can request specific timeline option is set to Yes, when a user requests access to the Access Package, they can enable a toggle to request access for a specific period of time.

Currently, there is no option to make this a required field or clearly inform the user of the maximum period they can enter. If the user enters a period longer than the expiry period, they will get an error.

If a user does not enter specific period dates, the expiry date countdown begins once the user has access to the Access Package.

If you have emails enabled for the Access Package, this will send the user an email 14 days before their Access Package access expires and 1 day before their Access Package access ends.

In my example, I will set this to Yes.

In my example, I will set this to No.

We also have the option to configure Access Reviews.

In my example, I will select Require access reviews.

In my example, I will set this to October 1, 2026.

In my example, I will select Monthly.

In my example, I will set the duration to 14 days.

In my example, I will select Manager.

When setting manager as the reviewer, you need to set a Fallback approver in case the Manager information is not populated. If you set the reviewer to self-review or to specific reviewers, you don’t need to configure a fallback reviewer.

In my example, I will select the group named Reviewer Manager Fallback.

In my example, I will set this to remove access. If a reviewer does not complete the review within 14 days, the user’s access to the Access Package will be removed.

In my example, I will set this to Yes.

In my example, I will set this to Yes.

In my example, I will select reminders.

Access Package – Custom extensions

If you have a Microsoft Entra ID Governance or Microsoft Entra Suite license, you can configure custom extensions.

Custom extensions are optional.

Access Package – Review and Create

User Access Request

Once an Access Package is created, users can request access by going to https://myaccess.microsoft.com/

That’s all it takes to configure a Microsoft Entra ID Governance Entitlement Management Access Package.

If you want to read more about Access Packages, here is the Microsoft documentation.

Exit mobile version