Introduction to Microsoft Entitlement Management

Need help understanding how Microsoft Entra Entitlement Management allows organizations to manage identity and access lifecycle at scale? Watch this Pluralsight course clip.

FULL SC-900 Pluralsight Path

Video Summary

Here are the key points from the video:

  • Entitlement Management Overview: Helps manage identity and access lifecycle at scale, automating access and offloading management to business stakeholders.
  • Creating Access Packages: Admins or delegated users can create access packages, which are collections of permissions across Microsoft 365 and external apps, including groups, teams, and SharePoint sites.
  • Request and Approval Process: Users can request access to these packages, which can be configured to require approval. Approvers review and approve requests to ensure users get the necessary permissions.
  • Catalogs and Delegation: Access packages are grouped into catalogs, and administrators can delegate catalog management to business users, reducing the burden on IT.
  • Practical Example: Demonstrates creating an access package named “Project Alpha,” assigning permissions, and showing the request and approval process from both the end-user and approver perspectives.

For more information, read the transcript blog below, or watch the video above!

Video Transcript

Next up on our list of awesome tools is Entra ID Entitlement Management. Entitlement management is an identity governance feature that enables organizations to manage identity and access lifecycle at scale. It makes it easy to implement access automation and offload access management to business stakeholders, taking the burden off the IT department. Entitlement management is built to solve two main problems. When a user starts working on a project or a new team, they don’t know all the accesses they need. Even once they find out, each resource might have different owners, taking different times to give the user their permissions. While users fight to get their permissions, their productivity goes down.

So, how does entitlement management help? Users, who can either be admins or delegated business users, can create access packages. An access package is basically a collection of permissions across Microsoft 365 and external apps. It can include groups, teams, SharePoint sites, or even apps connected with Entra ID, such as Salesforce, Box, custom line-of-business applications, and more. In addition to that, you can also configure who can request access, whether it is automatically granted or needs to go through an approval process, and whether the access automatically expires after a certain amount of time or at a certain date. Finally, you can also integrate periodic access reviews that we learned about earlier into the contents of the access package.

From an end-user perspective, you can go to a single location and see all the different packages you are allowed to request and what they include. From this interface, you can then request them, or if you are an approver, you can approve the requests. Another functionality is catalogs, as access packages are grouped together into catalogs. In one tenant, you can have multiple catalogs, and each one of them can have multiple access packages. As an administrator, you can then delegate access to catalogs, taking some responsibility off IT and empowering trained business users to do more. You can assign other users to be catalog owners, catalog readers, access package managers, or access package assignment managers.

Now that we know the theory, let’s head over to the lab environment and check out what Entra ID entitlement management can do for us. We’re now in the live environment. Let me open up the browser here, where I’m inside the Microsoft Entra admin center. Let me go under identity governance and then to entitlement management. Let’s go under access packages and create our access package. First, it will ask us for the name, so I will call it Project Alpha. Then a description: “Request this access package if you need to work on Project Alpha.” I can select what catalog it’s in. Right now, we only have one catalog, which is the general one, but remember, you can create multiple.

Next, let’s go to the roles. What actual permissions will this access package give us? Let’s start with some groups and teams here. Then, let’s see all of them. What you will do then is search for all the different teams and groups that you want to add this member to. As you see, I have Project Alpha Europe and Project Alpha Canada. They’re both either a Microsoft 365 group or they have a team attached to it. Then I need to select the role. Will the user be an owner or a member? Let’s select a member here for both. Let me also add the SharePoint site here. I can see all of them if I want to. It will show me all the ones in my organization. Let’s again search Project Alpha. We need to be careful because, of course, it can give access to only the SharePoint site part of the group, but you know what? I want this other one, the investor relation news. Then I can select what SharePoint group I want to add the member in. I want to add the member as an owner. Perfect.

Then let’s click on next here, and we can decide who can request it. Only users in my directory? Only users not in my directory? Do I want to make this purposely built for external users that need to request access to my tenant? Imagine that instead of manually provisioning and inviting the user, you have an external-facing directory. If your vendor needs somebody new on the project, you just give them a link, they request access from there even if they’re not in your tenant yet, and then you approve them before they join. But what I want to do is make this one for users in my directory, and I want everybody, including guests, to be able to request it. Do I want to require an approval? Yes or no? I do. Yes, I need a justification, and I only need one stage of approval. I want to select specific approvers here, so let me select Vlad as an approver. Yes, perfect. How many days does Vlad have to approve or deny the request? Let’s put it at three days. Great.

Now, do I want to enable new requests for this access package? Yes, I do. If you have Entra ID governance, you can actually enforce verified IDs. Next, I can ask additional questions to the user. For example, why do you need access to this? This will be a short text. Here, I want to say, what is your department cost center code? This will also be a short text. I want to make both of them required. Great. Then I can have the lifecycle settings. When does the access package assignment expire? Of course, you can have it at never, but you can also have it, for example, at 180 days. Users can request a specific timeline, and users are able to extend their access if they still need to be on the project afterwards, but I want them to still require an approval. We are then able to integrate access reviews to it if we want. We’ve already seen access reviews, so I’m not going to do it here.

Next up, again, if you have Entra ID governance, you can add extra rules at different stages. Finally, we can review everything and create it. Let’s create it over here. It will take a few seconds, and after that, I can copy the direct link to this My Access portal request. This is it for creating it. Now, let’s go to Vanessa. So, Vanessa here, I’m in Microsoft Teams, but you know what? I don’t have access to the Project Alpha things. I need to request them. I pasted in the link in a new tab. Let me just close it here. You see, as a user, I can always go to myaccess.microsoft.com and see all the different access packages I can request. Right now, we only have one in our tenant. I can see the name, the description, and the resources I have access to. Let’s go and request it. Let’s go here, click on request, click on continue. Why do you need access to this? I am the new PM on the project. What is your department cost center code? It’s 1112. Do I want to request for a specific period? I can have a start date and an end date if I want to add that there, but I don’t want to for this one. For the business justification, I can add that I’m the new PM on the project. Now, let’s submit the request.

Great. Now, let me go over to Vlad because, remember, access is not automatically granted. I have to go to My Access here. Let’s go to approvals. It might take a few seconds until we see it here. Let’s do a refresh and see if it appeared. Okay, so refresh. There it is. You see, I have one approval pending as Vlad. Vanessa Lee requested package Project Alpha on this date, and I have until this date to approve it. I will, of course, approve. I can view the request details, for example, and everything. I will say verified, and Vanessa is the new PM. Now, I clicked on submit. Of course, it will take anywhere from a few seconds to a few minutes, but what will happen if I go to Vanessa here? We will just give it a few minutes before we refresh, but Vanessa will be added to all the different resources that we have in the access package. There we go. Project Alpha Europe and Canada just got added automatically, so my access package worked.

This is it for entitlement management, a way to automate permissions and also offload a lot of this permission granting to the business users that are closer to the actual resources, rather than having it all centralized in IT. Now, let’s head back to the slides and learn about our next identity governance tool.