What's changed: Created SC-300 Chapter 5 (Domain 4: entitlement management (catalogs/access packages/policies/My Access/connected organizations/ToU/external lifecycle); access reviews (scope/reviewers/auto-apply/privileged-role reviews); PIM (eligible/active/activation/Entra roles/Azure resources/PIM for Groups/settings/audit history/break-glass); monitoring (sign-in/audit/provisioning logs/diagnostic settings Log Analytics-storage-Event Hubs/KQL/workbooks/Identity Secure Score)).
5.1Entitlement management
Understand Microsoft Entra entitlement management: catalogs and access packages, access requests/approval, terms of use (ToU), external-user lifecycle, and connected organizations.
Identity governance keeps "the right people have the right access for the right time" automatically. At its center is entitlement management, unifying access from request through approval, expiry, and removal.
5.1.1Catalogs and access packages
A catalog is a container grouping resources (groups, apps, SharePoint sites), managed by delegated owners. An access package defines "the bundle of access a role needs," with a policy for who can request, who approves, and for how long. Users self-request via the My Access portal; on approval, access to the needed groups/apps is auto-granted and auto-removed at expiry. For "deliver a role’s access as a self-service, time-bound bundle," use access packages.
5.1.2External-user lifecycle and ToU
Entitlement management also works for external users. Register trusted partner orgs as connected organizations and let their people request access packages. On approval, external guests are auto-created, and external-user lifecycle auto-removes guests when access expires. You can require consent to Terms of Use (ToU) as a condition of access, so users cannot access without accepting.
Cues: "deliver a role’s access self-service + approval + time-bound" = access packages (catalog + policy). "trust a partner org to let them request" = connected organizations. "require ToU acceptance before access" = Terms of Use. "auto-remove external guests at expiry" = external-user lifecycle.
Watch the mix-ups: (1) Entitlement management (request/approval/expiry lifecycle) and access reviews (periodic re-check of existing access, next section) are complementary but distinct. (2) Access packages "bundle and deliver"; groups are the "unit of grant"—different roles. (3) Auto-removal of external guests requires lifecycle settings.
5.1.3Section summary
- Access packages = self-service request + approval + expiry for a role’s access bundle (catalog + policy)
- Connected organizations let external parties request; gate with ToU; auto-remove external guests at expiry
- Entitlement management (request/expiry) and access reviews (periodic re-check) are complementary
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. You want project members to self-request a bundle of access to needed groups/apps/SharePoint, auto-granted on approval and auto-removed in 90 days. Which is best?
Q2. You want employees of a trusted partner org to request your access packages. Which is best?
Q3. You want to require users to accept terms before granting access. Which is best?
Q4. You want invited external guests auto-removed when their access package expires. Which is best?
Q5. Which correctly relates entitlement management and access reviews?
Keep track of your progress
The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.

