Microsoft Entra ID Governance Access Package Workflow - 夜莺博客

Microsoft Entra ID Governance Access Package Workflow

原文:Microsoft Entra ID Governance Access Package Workflow — theDXT (Daniel Keer)

An Access Package is a feature of Entitlement Management within Microsoft Entra ID Governance. With an Access Package, users gain self-service access to groups, applications, or SharePoint sites. You can also configure an Access Package to require approval before access is granted.

The post is a follow-up to my blog post, Configure Microsoft Entra ID Governance Entitlement Management Access Packages, and shows you the workflow for an Access Package.

In this post, I will show each stage of an Access Package, including approvals and views from the user, approver, and admin perspectives.

Prerequisites

  • An active Access Package.

If you haven’t set up an Access Package, my blog post Configure Microsoft Entra ID Governance Entitlement Management Access Packages details the entire setup process.

The Process

There are several stages of an Access Package.

User Request

To start the workflow for an Access Package, a user requests access to the Access Package.

Image 1

  • The user finds the Access Package they want and, under Actions, clicks Request.

Image 2

  • On the Request details tab, the user clicks Continue.

Image 3

If the user clicks the Resources tab, they can see what resources they will gain access to.

Image 4

  • The user fills in the required details, then they click Submit request.

Image 5

If the Access Package has an expiry configured and the user enters a longer period, they will receive an error when submitting the request.

Image 6

If a user does not enter specific period dates, the expiry countdown begins once they have access to the Access Package.

Once a user requests access to an Access Package, they cannot request it again until the request is approved or denied.

Image 7

From the admin side, go to the Access Package, click Requests, and select the user to view the request details.

Image 8

First Approval

If the Access Package has approvals configured, the user’s request is sent for approval.

  • The first approvers will get an email about the access request.

Image 9

The email approvers see shows the access start and end times in UTC, and the user’s answers are not visible.

Image 10

  • The first approver locates the request and clicks Review.

Image 11

  • The first approver can see some basic information, such as when they are required to make a decision.

Image 12

  • The first approver can click Request details to view all the information the user provided.

Image 13

  • The first approver selects Approve or Deny, provides a reason for their decision, and clicks Submit.

Image 14

If any first approver denies the request, all first approvers are notified of the denial.

Image 15

If any first approver approves the request, all first approvers are notified of the approval and that the request is moving to the next approver.

Image 16

Second Approval

If the Access Package has a second approval configured, the request is routed for second approval.

  • The second approvers receive an email notifying them of the access request after the first approver has approved the user’s request.

Image 17

The email the second approvers receive shows access start and end times in UTC. The user’s answers and the first approver’s approval reason are not visible.

From the admin side, go to the Access Package, click Requests, and select the user. We can see details about the current process and that the first approval stage is approved.

Image 18

Image 19

  • The second approver locates the request and clicks Review.

Image 20

  • The second approver can see some basic information, such as when they are required to make a decision.

Image 21

  • The second approver clicks Approval History and clicks More to see the reason the first approver approved the request.

Image 22

  • The second approver selects Approveor Denyand clicks Submit.

Image 23

If any second approver denies the request, all second approvers are notified of the denial.

Image 24

If a second approver approves the request, all second approvers are notified, and the user gains access to the Access Package.

Image 25

From the admin side, go to the Access Package, click Requests, and select the user. We can see the user is now scheduled to receive access.

Image 26

Alternate Approvers

If alternate approvers are configured and a request is not actioned in time, the alternate approvers receive an email notification and can approve or deny the request.

Image 27

The email the alternate approvers see shows access start and end times in UTC, and the user’s answers are not visible.

Approval Not Actioned

If no approver acts on the Access Package request within the required timeframe, the request is denied and the user is notified.

Image 28

The email the user sees shows the access start and end times in UTC.

The approvers are also notified that no one acted on the Access Package request in time.

Image 29

From the admin side, go to the Access Package, click Requests, and select the user. We can see the request was denied due to the approval timeout.

Image 30

Request Denied

  • If the user’s Access Package request is denied at any point, the user receives an email notification.

Image 31

The email the user sees shows the access start and end times in UTC.

  • The user can view denial details by clicking the link in the email or going to https://myaccess.microsoft.com/
  • The user clicks My Access > Request history.

Image 32

  • The user selects the Denied access request and clicks View.

Image 33

  • In the Request history section, the user clicks Details for the denial.

Image 34

  • If the approver who denied the request provided a reason, the user can see why.

Image 35

User Cancel Access Request

The user can cancel their request at any point during the Access Package process.

Image 36

  • The user locates the access request that is Pending approval and clicks View.

Image 37

  • The user clicks Cancel request to cancel the Access Package request.

Image 38

  • The user will see their request status change from Pending approval to Canceled.

Image 39

From the admin side, go to the Access Package, click Requests, and select the user. We can see the access request was canceled.

Image 40

Access Granted

If the user did not provide a start date for their Access Package request, they are notified they have access once everything is fully approved. Otherwise, they are informed when the start date is reached.

  • When the Access Package start date is reached, the user receives an email notifying them that they now have access to the Access Package.

Image 41

The email the user sees shows times in UTC.

Once the Access Package start date is reached, from the admin side go to the Access Package, click Requests, and select the user. We can see the access has been delivered to the user.

Image 42

After the Access Package has been delivered, on the admin side click the Access Package, then click Assignments. We can see who currently has the Access Package and when their access will expire.

Image 43

Access Extend

If the Access Package allows access extensions, users can extend access before it expires.

  • The user receives emails 14 days and 1 day before their Access Package access expires.

Image 44

Image 45

  • The user clicks the Active tab.

Image 46

  • The user locates the Access Package to extend, then underActions, clicks Extend.

Image 47

  • The user fills out the required information and clicks Submit.

Image 48

If approvals are configured for extensions, then the request is routed for approval.

Access Review

If an Access Package has an access review configured, the access reviewers will be required to review the users who currently have access.

  • When it is time for the access review, reviewers receive an email notification.

Image 49

Image 50

  • The access reviewer clicks the Access package assignment tab.

Image 51

  • The access reviewer clicks the Access package they want to review.

Image 52

  • The access reviewer clicks Details next to the user.

Image 53

  • The access reviewer decides whether to Approve or Deny the user’s access, provides a reason, and clicks Submit.

Image 54

During the review window, if one reviewer makes a decision, others can override it.

Image 55

From the admin side, go to the Access Package, click Access reviews, then click the access review.

Image 56

The overview page shows the current status of the access review.

Image 57

Once a reviewer has made a decision, we can view more details by clicking Results.

Image 58

When the review window closes, if reviewers deny a user or take no action, the user’s Access Package access is removed.

Once an Access Package access review is complete, on the admin side we can see the results by clicking Review history, then clicking on the review.

Image 59

On the admin side, we can view when the next access review is scheduled to start by clicking Scheduled review.

Image 60

Access Ended

The user is automatically removed from the resources when an Access Package end date is reached or if an access review denies their access.

  • The user receives an email notifying them that their access has been removed.

Image 61

Manual Assignments

Typically, users submit Access Package requests themselves. However, an admin can manually add a user to an Access Package.

  • From the admin side, go to the Access Package, click Assignments, then clickNew assignment.

Image 62

  • Now we need to fill in the details for the manual Access Package assignment.

Image 63

  • For Select policy, pick the policy you want the user to follow.

Image 64

In my example, I will select the policy Initial Policy.

  • Select whether the user you want to add is an Identities in my directory or an External user.

Image 65

In my example, I will select Identities in my directory.

  • For Select identities, click Add identitiesand select the user you want to add.

If the Access Package policy includes questions, only one user can be added at a time.

Image 66

In my example, I will select the user named User1.

  • For Bypass approval, decide if the manual assignment should follow the policy’s approval process.

Image 67

In my example, I selected Yes to skip the approval process.

  • For Assignment starts on and Assignment ends on, enter when the user should have access to the Access Package and when it should expire.

If the Access Package policy has an expiry date, the end date you enter must be less than the maximum number of days allowed by the policy.

If no end date is entered, the expiry countdown begins when the user is added and follows the Access Package expiry setting.

Image 68

If the Access Package policy contains any required questions, they must be completed before the user can be manually added to the Access Package.

  • Click View and edit user information.

Image 69

  • On the User information panel, fill out the required questions, then click Save.

Image 70

  • Once the info is populated, click Add.

Image 71

  • The manually added user will be added to the Access Package on the specified start date.

Summary

That is the complete workflow of the Access Package request feature of Entitlement Management within Microsoft Entra ID Governance.

If you want to read more about the Access Package request process, here is the Microsoft documentation.