Entra ID Governance capability built around access packages, which can require approval, expire automatically and include connected organisations.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Entitlement management in context, with comparison tables and the common traps.
Terms in this definition
- Microsoft Entra ID
Cloud identity service from Microsoft, previously named Azure AD, which provides the tenant behind Microsoft 365 and Azure.
- Governance
Keeping cloud deployments in line with an organisation's rules on technology, security and compliance, helped by Azure Policy, tags and resource locks.
- Capability
Something that a person, organisation or system is able to do.
Related terms
- Access package
Bundle in entitlement management that groups apps, groups and sites together with request policies and an expiry. Access to the resources is withdrawn once an assignment expires.
- Access package assignment manager
An entitlement management role, scoped to a catalog, whose holders can add users to or remove them from access packages that already exist. They cannot create or change the packages themselves or the policies attached to them.
- Access package manager
Holders of this catalog-level entitlement management role design new access packages, alter existing ones and set their policies, drawing only on resources that are already in that catalog; bringing extra resources in is beyond them.
- Automatic assignment policy
Works much like a dynamic group: a membership rule based on user attributes decides who gets an access package and removes assignments when people stop matching. It is an ID Governance entitlement management feature, and neither catalog owners nor access package managers are allowed to set one up.
- Catalog creator
Anyone holding this tenant-level entitlement management role may set up new catalogs and becomes the first owner of each, yet catalogs owned by others stay invisible and out of reach.
- Catalog owner
Within its own catalog this entitlement management role controls what resources are present and which access packages exist, and may appoint additional owners or access package managers.
- Catalog reader
A role in entitlement management, limited to one catalog, whose holders may look at the access packages in it but change nothing.
- Connected organization
In entitlement management, an outside partner's directory that you register so access-package policies are able to include its users.