Microsoft Entra ID Governance Access Package Workflow

Microsoft Entra ID Governance Access Package Workflow

An Access Package is a feature of Entitlement Management within Microsoft Entra ID Governance. With an Access Package, users gain self-service access to groups, applications, or SharePoint sites. You can also configure an Access Package to require approval before access is granted.

The post is a follow-up to my blog post, Configure Microsoft Entra ID Governance Entitlement Management Access Packages, and shows you the workflow for an Access Package.

In this post, I will show each stage of an Access Package, including approvals and views from the user, approver, and admin perspectives.

Prerequisites

If you haven’t set up an Access Package, my blog post Configure Microsoft Entra ID Governance Entitlement Management Access Packages details the entire setup process.

The Process

There are several stages of an Access Package.

User Request

To start the workflow for an Access Package, a user requests access to the Access Package.

If the user clicks the Resources tab, they can see what resources they will gain access to.

If the Access Package has an expiry configured and the user enters a longer period, they will receive an error when submitting the request.

If a user does not enter specific period dates, the expiry countdown begins once they have access to the Access Package.

Once a user requests access to an Access Package, they cannot request it again until the request is approved or denied.

From the admin side, go to the Access Package, click Requests, and select the user to view the request details.

First Approval

If the Access Package has approvals configured, the user’s request is sent for approval.

The email approvers see shows the access start and end times in UTC, and the user’s answers are not visible.

If any first approver denies the request, all first approvers are notified of the denial.

If any first approver approves the request, all first approvers are notified of the approval and that the request is moving to the next approver.

Second Approval

If the Access Package has a second approval configured, the request is routed for second approval.

The email the second approvers receive shows access start and end times in UTC. The user’s answers and the first approver’s approval reason are not visible.

From the admin side, go to the Access Package, click Requests, and select the user. We can see details about the current process and that the first approval stage is approved.

If any second approver denies the request, all second approvers are notified of the denial.

If a second approver approves the request, all second approvers are notified, and the user gains access to the Access Package.

From the admin side, go to the Access Package, click Requests, and select the user. We can see the user is now scheduled to receive access.

Alternate Approvers

If alternate approvers are configured and a request is not actioned in time, the alternate approvers receive an email notification and can approve or deny the request.

The email the alternate approvers see shows access start and end times in UTC, and the user’s answers are not visible.

Approval Not Actioned

If no approver acts on the Access Package request within the required timeframe, the request is denied and the user is notified.

The email the user sees shows the access start and end times in UTC.

The approvers are also notified that no one acted on the Access Package request in time.

From the admin side, go to the Access Package, click Requests, and select the user. We can see the request was denied due to the approval timeout.

Request Denied

The email the user sees shows the access start and end times in UTC.

User Cancel Access Request

The user can cancel their request at any point during the Access Package process.

From the admin side, go to the Access Package, click Requests, and select the user. We can see the access request was canceled.

Access Granted

If the user did not provide a start date for their Access Package request, they are notified they have access once everything is fully approved. Otherwise, they are informed when the start date is reached.

The email the user sees shows times in UTC.

Once the Access Package start date is reached, from the admin side go to the Access Package, click Requests, and select the user. We can see the access has been delivered to the user.

After the Access Package has been delivered, on the admin side click the Access Package, then click Assignments. We can see who currently has the Access Package and when their access will expire.

Access Extend

If the Access Package allows access extensions, users can extend access before it expires.

If approvals are configured for extensions, then the request is routed for approval.

Access Review

If an Access Package has an access review configured, the access reviewers will be required to review the users who currently have access.

During the review window, if one reviewer makes a decision, others can override it.

From the admin side, go to the Access Package, click Access reviews, then click the access review.

The overview page shows the current status of the access review.

Once a reviewer has made a decision, we can view more details by clicking Results.

When the review window closes, if reviewers deny a user or take no action, the user’s Access Package access is removed.

Once an Access Package access review is complete, on the admin side we can see the results by clicking Review history, then clicking on the review.

On the admin side, we can view when the next access review is scheduled to start by clicking Scheduled review.

Access Ended

The user is automatically removed from the resources when an Access Package end date is reached or if an access review denies their access.

Manual Assignments

Typically, users submit Access Package requests themselves. However, an admin can manually add a user to an Access Package.

In my example, I will select the policy Initial Policy.

In my example, I will select Identities in my directory.

If the Access Package policy includes questions, only one user can be added at a time.

In my example, I will select the user named User1.

In my example, I selected Yes to skip the approval process.

If the Access Package policy has an expiry date, the end date you enter must be less than the maximum number of days allowed by the policy.

If no end date is entered, the expiry countdown begins when the user is added and follows the Access Package expiry setting.

If the Access Package policy contains any required questions, they must be completed before the user can be manually added to the Access Package.

Summary

That is the complete workflow of the Access Package request feature of Entitlement Management within Microsoft Entra ID Governance.

If you want to read more about the Access Package request process, here is the Microsoft documentation.

Exit mobile version