Configure Microsoft Entra ID Governance Entitlement Management Access Packages - 夜莺博客

Configure Microsoft Entra ID Governance Entitlement Management Access Packages

原文:Configure Microsoft Entra ID Governance Entitlement Management Access Packages — theDXT (Daniel Keer)

Microsoft Entra ID Governance has many cool features, one of them is Entitlement Management. Within Entitlement Management is the Access Packages feature.

Access Packages allow you to configure user self-service access to groups, applications, or SharePoint sites. You can set an Access Package to use a specific approver or a dynamic one, such as the user’s manager. You can also configure access reviews to help address users having access to things they no longer need.

An example use case for an Access Package is configuring it so a user can request Visio and have their manager approve the request. Once approved, the Access Package adds the user to the Visio licensing group, which allocates them a license. If Intune is configured, the user can then install Visio themselves via Company Portal.

You can delegate the setup of Access Packages for a department to someone in that department, allowing them to self-manage how their department members get the access they need for the projects or tasks they are working on.

In this post, I will show you step by step how to create an Access Package.

Prerequisites

To use the basics of Entitlement Management, including Access Packages, you need the following license.

  • Microsoft Entra ID P2

If you want to unlock all the advanced features of Entitlement Management and Identity Governance, you need to have one of the following licenses.

  • Microsoft Entra ID Governance
  • Microsoft Entra Suite

The Process

  • Login to the Microsoft Entra admin center.
  • Click on ID Governance > Entitlement management.

Image 1

The rest of the process is divided into the following sections.

Catalogs

Before creating an Access Package, we need to create a Catalog. A Catalog is a collection of resources that Access Packages can use. Catalogs help organize resources and can enable delegated management without excessive permissions.

  • Click on Catalogs.

Image 2

  • Click on New catalog.

Image 3

  • Enter a name and description for the catalog.

Image 4

In my example, I will enter the name as Project Neo and the description as Access to project Neo.

  • For Enabled for users to request, decide if users can request access to the Access Packages within the Catalog.

Image 5

In my example, I will select Yes.

  • For Enabled for external users to request, decide if external users can request access to Access Packages within the Catalog.

Image 6

In my example, I will select No.

  • Click Create.

Image 7

  • Click on the Catalog you just created.

Image 8

In my example, I will click on the Project Neo catalog I just created.

  • In the Managesection, click on Resources.

Image 9

  • Click on Add resources.

Image 10

  • Click on the type of resource you want to add to the Catalog. A resource can be in more than one catalog.

    • Groups and Teams

      • The groups need to be cloud groups and can be 365 Groups or Security Groups.
    • Applications

      • These are Entra Enterprise apps.
    • SharePoint sites.

    • Azure Resources.

      • Microsoft Entra ID Governance or Microsoft Entra Suite license required.
    • Microsoft Entra role.

      • Microsoft Entra ID Governance or Microsoft Entra Suite license required.
    • Custom Data Provided Resource.

      • Microsoft Entra ID Governance or Microsoft Entra Suite license required.

Image 11

In my example, I will add the cloud security group named SG-Project-Neo.

  • When you’ve selected all the resources you want in the Catalog click Add.

Image 12

Access Packages

Once we have created the Catalog, we can create the Access Package within the Catalog so users can request access to the resources in it.

  • In the Manage section, click on Access packages.

Image 13

  • Click on New access package.

Image 14

Access Package – Basics

  • Enter a name and description for the Access Package. When ready, click Next: Resource roles.

The name and description of the Access Package will be visible to users.

Image 15

In my example, I will enter the name as Project Neo and the description as 3 month access to project Neo.

Access Package – Resource roles

Now we can add the resources from the Catalog to the Access Package so users can request access to them.

  • Add the resources that this Access Package should grant access to.

Image 16

In my example, I will select the security group named SG-Project-Neo.

  • Select what role the user should get for the resource you added.

Image 17

In my example, I will select the role member.

  • When ready, click Next: Requests.

Image 18

Access Package – Requests

Now we need to configure how Access Package requests are handled.

Image 19

  • For Who can get access, decide whether users or external users can request access or if only administrators can grant access.

Image 20

In my example, I will select For users, service principals, and agent identities in your directory.

  • For Select specific scope, decide who can see and request access to the Access Package.

Image 21

In my example, I will select All members (excluding guests).

  • For Who can request access, decide which types of people can request access: Self, Admin, Manager, or Users in your directory.

Image 22

In my example, I will select Self.

  • For Require requestor justification, decide whether you want your users to provide a reason for requesting access to the Access Package.

Image 23

In my example, I will set Require requestor justification to No.

Users will always see the Business justification box when requesting access to an Access Package regardless of the require requestor justification setting. The setting only controls if input is required.

Image 24

  • For Require approval, decide if you want someone to approve the Access Package request before the user is granted access.

When an Access Package requires approval, you can have the user’s manager approve it, or you can set a static approver.

Image 25

In my example, I will set Require approval to Yes.

  • For How many stages, select the number of approvals required before a user is granted access to the Access Package.

Image 26

In my example, I want to require two approvals. I will set Require approval to Yes and set the approval stages to 2.

  • For the First Approver, select who should approve the initial Access Package request: Manager as approver, specific approvers, or Sponsors as approvers.

Image 27

In my example, I will set the First Approver to the Manager.

When setting a manager or sponsor as an approver, you need to set a Fallback approver in case the Manager or Sponsor information is not populated. Specific approvers don’t need a fallback approver.

  • For Fallback, select specific users, a security group, or a 365 Group.
    • If you select a 365 Group, the email notifications are sent directly to all group members, not to the group mailbox.

Image 28

In my example, I will select the group named First Approver Manager Fallback.

  • For Decision must be made in how many days, enter how long an Access Package request waits for approval before it is automatically rejected.

Image 29

In my example, I will set this to 4 days.

  • For Require approver justification, decide if you want the approver to be required to enter a reason why they approved or rejected the request.

Image 30

In my example, I will set this to Yes.

  • Click on Show advanced request settings.

Image 31

  • For Show approvers details to requestors, decide whether you want to show who the first approvers are to the user requesting the Access Package.

The default setting is to show the approver details.

Image 32

In my example, I will leave this set to default.

  • For If no action taken, forward to alternate approvers, decide whether you want the first approval to route to someone else if the first approvers don’t action the request fast enough.

Image 33

In my example, I will set this to Yes.

  • For Alternate Approver, decide whether you want to use Second level manager as an alternate approver or Choose specific alternate approvers.

Image 34

In my example, I will set this to Second level manager as alternate approver.

When setting second level manager as an approver, you need to set a Fallback approver in case the Manager information is not populated. Specific approvers do not need a fallback.

  • For Fallback, select specific users, a security group, or a 365 Group.
    • If you select a 365 Group, the email notifications are sent directly to all group members, not to the group mailbox.

Image 35

In my example, I will select the group named Second Level Manager Approver Fallback.

  • For Forward to alternate approver(s) after how many days, enter how many days before the request is sent to the alternate approvers.

The number of days must be less than the maximum number of days of the initial first approval.

Image 36

In my example, I will set this to 2 days.

  • We have completed setting up the first approver.

Below is an image of my first approver settings.

Image 37

  • For the Second Approver, select Choose specific approvers or Sponsors as approvers.

Image 38

In my example, I will select specific approvers.

  • For Select approvers, click Add approvers, then select the users or groups to use as the second approvers.
    • If you select a 365 Group, the email notifications are sent directly to all group members, not to the group mailbox.

Image 39

In my example, I will select the group named Second Approvers.

  • For Decision must be made in how many days, enter how many days a request waits for a second approval before it is automatically rejected.

Image 40

In my example, I will set this to 7 days.

  • For Require approver justification, decide if you want the second approver to be required to enter a reason why they approved or rejected the request.

Image 41

In my example, I will set this to No.

  • Click on Show advanced request settings.

Image 42

  • For Show approvers details to requestors, decide whether you want to show who the second approvers are to the first approvers or the user requesting the Access Package.

Image 43

In my example, I will set this to No.

  • For If no action taken, forward to alternate approvers, decide whether you want the second approval to route to someone else if the second approvers don’t action the request fast enough.

Image 44

In my example, I will set this to No.

  • For Disable assignment emails, decide if email notifications should be sent when an Access Package is approved, denied, or expires.

Image 45

In my example, I will set this to No to keep everyone involved informed.

  • Depending on your Entra license, you can configure Required Verified IDs.

Image 46

In my example, I will skip that section as I don’t have the license for it.

  • Once you’ve configured all the approval settings, click Next: Requestor Information.

Image 47

Access Package – Requestor information

Now we can configure the Requestor information to gather data from the user when they request access to an Access Package. The information can be in the form of questions or attributes.

Requestor information is optional.

Image 48

In my example, I will request information from the user through questions.

  • In the Question box, enter the question you want to ask the user.

Image 49

In my example, I will add a question to ask the user if they know the internal project codename.

If you support multiple languages, click on add localization to add different wording for the question in other languages.

  • For Answer format, select Short text, Multiple choice, or Long text.

Image 50

In my example, I will select Short text.

  • For Regex pattern, enter any regex you want to use to validate the user input.

Image 51

In my example, I will leave this blank.

  • For Required, select the box to require a response before the user can submit their Access Package request.

Image 52

In my example, I will select Required.

  • Add any additional questions you want to ask the user.

Image 53

In my example, I will add another question asking the user to explain why they need access, set the answer format to Long text, and mark it as Required.

  • If the answer format is Multiple choice, click Edit and localize to add options.

Image 54

  • On the View/edit question screen, enter the multiple choice option in the Answer values field.

Image 55

In my example, I will enter Yes.

  • For Language, select the language for the localized text.

Image 56

In my example, I will select English (United States).

  • For Localized Text, enter the text that will be presented to the user in the selected language.

Image 57

In my example, I will enter Yes.

  • Add any additional multiple choice options. When ready, click Save.

Image 58

In my example, I will add another option for No.

  • Once you have completed adding all the questions, click Next: Lifecycle.

Image 59

Access Package – Lifecycle

Now we can configure the Lifecycle of the Access Package, including how long a user can have access, if they can extend it, and access reviews.

Image 60

  • For Access package assignments expire, decide whether access should expire on a specific date, after a number of days, hours, or never.

Image 61

In my example, I will select number of days.

  • For Assignments expire after, enter the date, number of days, or number of hours after which access to the Access Package should expire.

Image 62

In my example, I will enter 90 days.

  • For Users can request specific timeline, this shows a date selector allowing users to specify when their access starts and how long they need it.

Image 63

In my example, I will set this to Yes.

If the Users can request specific timeline option is set to Yes, when a user requests access to the Access Package, they can enable a toggle to request access for a specific period of time.

Image 64

Currently, there is no option to make this a required field or clearly inform the user of the maximum period they can enter. If the user enters a period longer than the expiry period, they will get an error.

Image 65

If a user does not enter specific period dates, the expiry date countdown begins once the user has access to the Access Package.

  • For Allow users to extend access, decide whether you want users to be able to extend their access.

If you have emails enabled for the Access Package, this will send the user an email 14 days before their Access Package access expires and 1 day before their Access Package access ends.

Image 66

In my example, I will set this to Yes.

  • For Require approval to grant extension, decide whether you want the user to go through the approval process again to extend their access.

Image 67

In my example, I will set this to No.

We also have the option to configure Access Reviews.

Image 68

  • Select the box for Require access reviews to enable access reviews on the Access Package.

Image 69

In my example, I will select Require access reviews.

  • For Starting on, select the current or future date when you want the Access Reviews to begin.

Once you’ve created the Access Package, you cannot change the starting on date.

Image 70

In my example, I will set this to October 1, 2026.

  • For Review frequency, set how often you want access reviews performed: Annually, Bi-annually, Quarterly, Monthly, or Weekly.

Image 71

In my example, I will select Monthly.

  • For Duration (in days), enter how many days reviewers have to complete the review.

Image 72

In my example, I will set the duration to 14 days.

  • For Reviewers, decide who performs the review and select self-review, specific reviewers, or manager.

Image 73

In my example, I will select Manager.

When setting manager as the reviewer, you need to set a Fallback approver in case the Manager information is not populated. If you set the reviewer to self-review or to specific reviewers, you don’t need to configure a fallback reviewer.

  • For Select fallback reviewers, select specific users, a security group, or a 365 Group.
    • If you select a 365 Group, the email notifications are sent directly to all group members, not to the group mailbox.

Image 74

In my example, I will select the group named Reviewer Manager Fallback.

  • Click on Show advanced access review settings.

Image 75

  • For If reviewers don’t respond, select No change, Remove access, or Take recommendations.

Image 76

In my example, I will set this to remove access. If a reviewer does not complete the review within 14 days, the user’s access to the Access Package will be removed.

  • For Show reviewer decision helpers, decide whether you want to provide the reviewers with additional information about the user, such as whether the user has logged in recently.

Image 77

In my example, I will set this to Yes.

  • For Require reviewer justification, decide whether you want to require the reviewers to provide a reason for removing or retaining the user’s access.

Image 78

In my example, I will set this to Yes.

  • For Reminders, select the box to send review email reminders to the reviewers.

Image 79

In my example, I will select reminders.

  • Once you have completed configuring the Lifecycle options, click Next: Rules.

Image 80

Access Package – Custom extensions

If you have a Microsoft Entra ID Governance or Microsoft Entra Suite license, you can configure custom extensions.

Custom extensions are optional.

  • Configure any custom extensions. When ready, click Next: Review + create.

Image 81

Access Package – Review and Create

  • Review everything you’ve just configured. If everything looks good, click Create.

Image 82

  • Once the Access Package is created, all the settings we configured are saved as the Initial Policy.

Image 83

  • If needed, create any additional policies.

If you go to the Overview page of the Access Package, you can get a direct link to the Access Package from the My Access portal link.

Image 84

User Access Request

Once an Access Package is created, users can request access by using the Access Package’s My Access portal link or going to https://myaccess.microsoft.com/

  • The user clicks onMy Access > Access packages.

Image 85

  • The user finds the Access Package they want. In the Actions column, they click Request.

Image 86

  • UnderRequest details, the user clicksContinue.

Image 87

  • The user fills in the required details, then clicksSubmit request.

Image 88

  • The user’s access request now follows the rules of the Initial Policy of the Access Package.

That’s all it takes to configure a Microsoft Entra ID Governance Entitlement Management Access Package.

If you want to read more about Access Packages, here is the Microsoft documentation.

If you want to see the entire workflow of the Access Package, my blog post, Microsoft Entra ID Governance Access Package Workflow, shows the process from the user, approver, and admin perspectives.