Bundle in entitlement management that groups apps, groups and sites together with request policies and an expiry. Access to the resources is withdrawn once an assignment expires.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Access package in context, with comparison tables and the common traps.
Terms in this definition
- Entitlement management
Entra ID Governance capability built around access packages, which can require approval, expire automatically and include connected organisations.
Related terms
- Automatic assignment policy
Works much like a dynamic group: a membership rule based on user attributes decides who gets an access package and removes assignments when people stop matching. It is an ID Governance entitlement management feature, and neither catalog owners nor access package managers are allowed to set one up.
- Catalog owner
Within its own catalog this entitlement management role controls what resources are present and which access packages exist, and may appoint additional owners or access package managers.
- External user lifecycle
Entitlement management option that, once a guest's final access package assignment ends, blocks them and later deletes them from the directory (30 days by default).
- Incompatible access packages
Lets you say that people who already have certain other access packages, or who belong to certain groups, can't ask for this one. It is configured on the access package in entitlement management.
- Separation of duties
Stops conflicting access in entitlement management: anyone already holding an incompatible group membership or access package is prevented from requesting a given package.