Microsoft Entra ID Governance capability that periodically asks reviewers or users themselves to confirm membership for guests, app users or groups, removing anyone who does not respond. PIM, by contrast, handles privileged roles.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-305AZ-104SC-500AZ-900SC-900AB-900SC-300
Each book explains Access reviews in context, with comparison tables and the common traps.
Terms in this definition
- Microsoft Entra ID Governance
Set of features, and the licence for them, covering lifecycle workflows, entitlement management and access reviews.
- Capability
Something that a person, organisation or system is able to do.
- App protection policy
A set of Intune rules on managed apps that safeguards organisational data, for example by demanding a PIN or preventing copy-paste and save-as into personal apps. It works whether or not the device is enrolled.
- Privileged Identity Management
Capability in Microsoft Entra ID P2 that activates privileged roles just in time and for limited periods, with approval, justification and an audit trail.
Related terms
- Defender for Identity
Microsoft Defender service that detects attacks on identities, using sensors on on-premises Active Directory servers plus signals from Microsoft Entra ID and other identity providers; it does no access reviews or identity governance.
- Entra ID P2
Entra licence tier that adds Privileged Identity Management, access reviews and Identity Protection.
- Entra Permissions Management
Microsoft's multicloud CIEM (cloud infrastructure entitlement management) product, retired 1 October 2025; it was never meant for access reviews.
- Identity Governance Administrator
Can configure access reviews, access packages, catalogs and policies in Microsoft Entra ID Governance. It is a privileged Microsoft Entra role.
- SharePoint Advanced Management
An add-on for SharePoint governance, bundled with Microsoft 365 Copilot, that helps detect and cut oversharing via site access reviews, restricted content discovery, restricted access control and data access governance reports.