Skip to Content
SecurityPrivileged AccessAccess Reviews

Access Reviews

Periodically review and certify user access to groups, applications, and roles. Ensure least-privilege access and remove unnecessary permissions.

Review Types

TypeScopeFrequency
Group membershipReview members of security/M365 groupsQuarterly
Application accessReview users assigned to appsSemi-annual
Role assignmentsReview Azure AD role membersMonthly
Guest accessReview external user accessQuarterly

Review Workflow

  1. Create review — Define scope, reviewers, and schedule
  2. Notify reviewers — Email sent to designated reviewers
  3. Review period — Reviewers approve or deny access
  4. Auto-apply — Denied access automatically removed
  5. Report — Audit trail of decisions

Settings

  • Auto-apply results — Automatically remove denied access
  • If reviewer doesn’t respond — Remove access, approve, or no change
  • Recurrence — One-time, weekly, monthly, quarterly, annual

API Reference

  • GET /api/security/access-reviews — List access reviews
  • POST /api/security/access-reviews — Create review
Last updated on