Instiq
Chapter 5 · Identity governance and monitoring·v1.0.0·Updated 6/29/2026·~14 min

What's changed: Created SC-300 Chapter 5 (Domain 4: entitlement management (catalogs/access packages/policies/My Access/connected organizations/ToU/external lifecycle); access reviews (scope/reviewers/auto-apply/privileged-role reviews); PIM (eligible/active/activation/Entra roles/Azure resources/PIM for Groups/settings/audit history/break-glass); monitoring (sign-in/audit/provisioning logs/diagnostic settings Log Analytics-storage-Event Hubs/KQL/workbooks/Identity Secure Score)).

5.1Entitlement management

Key points

Understand Microsoft Entra entitlement management: catalogs and access packages, access requests/approval, terms of use (ToU), external-user lifecycle, and connected organizations.

Identity governance keeps "the right people have the right access for the right time" automatically. At its center is entitlement management, unifying access from request through approval, expiry, and removal.

5.1.1Catalogs and access packages

A catalog is a container grouping resources (groups, apps, SharePoint sites), managed by delegated owners. An access package defines "the bundle of access a role needs," with a policy for who can request, who approves, and for how long. Users self-request via the My Access portal; on approval, access to the needed groups/apps is auto-granted and auto-removed at expiry. For "deliver a role’s access as a self-service, time-bound bundle," use access packages.

5.1.2External-user lifecycle and ToU

Entitlement management also works for external users. Register trusted partner orgs as connected organizations and let their people request access packages. On approval, external guests are auto-created, and external-user lifecycle auto-removes guests when access expires. You can require consent to Terms of Use (ToU) as a condition of access, so users cannot access without accepting.

Exam point

Cues: "deliver a role’s access self-service + approval + time-bound" = access packages (catalog + policy). "trust a partner org to let them request" = connected organizations. "require ToU acceptance before access" = Terms of Use. "auto-remove external guests at expiry" = external-user lifecycle.

Warning

Watch the mix-ups: (1) Entitlement management (request/approval/expiry lifecycle) and access reviews (periodic re-check of existing access, next section) are complementary but distinct. (2) Access packages "bundle and deliver"; groups are the "unit of grant"—different roles. (3) Auto-removal of external guests requires lifecycle settings.

Diagram of access packages (catalog + policy for request/approval/expiry), My Access self-service, connected organizations (external requests), Terms of Use, and external-user lifecycle (auto-remove at expiry).
Automate the entry

5.1.3Section summary

  • Access packages = self-service request + approval + expiry for a role’s access bundle (catalog + policy)
  • Connected organizations let external parties request; gate with ToU; auto-remove external guests at expiry
  • Entitlement management (request/expiry) and access reviews (periodic re-check) are complementary

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. You want project members to self-request a bundle of access to needed groups/apps/SharePoint, auto-granted on approval and auto-removed in 90 days. Which is best?

Q2. You want employees of a trusted partner org to request your access packages. Which is best?

Q3. You want to require users to accept terms before granting access. Which is best?

Q4. You want invited external guests auto-removed when their access package expires. Which is best?

Q5. Which correctly relates entitlement management and access reviews?

Check your understandingPractice questions for Chapter 5: Identity governance and monitoring

Keep track of your progress

The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.