What's changed: Created SC-300 Chapter 5 (Domain 4: entitlement management (catalogs/access packages/policies/My Access/connected organizations/ToU/external lifecycle); access reviews (scope/reviewers/auto-apply/privileged-role reviews); PIM (eligible/active/activation/Entra roles/Azure resources/PIM for Groups/settings/audit history/break-glass); monitoring (sign-in/audit/provisioning logs/diagnostic settings Log Analytics-storage-Event Hubs/KQL/workbooks/Identity Secure Score)).
5.1Entitlement management
Understand Microsoft Entra entitlement management: catalogs and access packages, access requests/approval, terms of use (ToU), external-user lifecycle, and connected organizations.
Identity governance keeps "the right people have the right access for the right time" automatically. At its center is entitlement management, unifying access from request through approval, expiry, and removal.
5.1.1Catalogs and access packages
A catalog is a container grouping resources (groups, apps, SharePoint sites), managed by delegated owners. An access package defines "the bundle of access a role needs," with a policy for who can request, who approves, and for how long. Users self-request via the My Access portal; on approval, access to the needed groups/apps is auto-granted and auto-removed at expiry. For "deliver a role’s access as a self-service, time-bound bundle," use access packages.
Continue reading — free sign-up
You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.

