What's changed: Created SC-300 Chapter 5 (Domain 4: entitlement management (catalogs/access packages/policies/My Access/connected organizations/ToU/external lifecycle); access reviews (scope/reviewers/auto-apply/privileged-role reviews); PIM (eligible/active/activation/Entra roles/Azure resources/PIM for Groups/settings/audit history/break-glass); monitoring (sign-in/audit/provisioning logs/diagnostic settings Log Analytics-storage-Event Hubs/KQL/workbooks/Identity Secure Score)).
5.2Access reviews
Understand periodically re-certifying existing access to groups/apps/roles with Microsoft Entra access reviews, and planning/creating/monitoring reviews and responding to results.
Access accumulates over time, creating "rights that remain though no longer needed (permission creep)." Access reviews periodically re-check existing access ("still needed?") and remove what is not.
5.2.1Creating reviews and reviewers
In an access review, set the target (group members, app assignments, privileged roles, guests) and frequency (one-time/recurring), and designate reviewers (resource owners, the user themselves = self-review, managers). Enabling auto-apply removes denied access automatically (manual apply is also possible). Design the default for no-response (remove/keep/follow recommendations). Periodic guest reviews and privileged-role reviews are especially important.
5.2.2Monitoring and privileged-role governance
Admins monitor review progress/results and respond manually as needed. Privileged-role access reviews integrated with PIM periodically inventory holders of high privilege (e.g., Global Administrator) and reduce excessive privilege. Access reviews are the "continuous inventory" counterpart to entitlement management (entry-point control), maintaining Zero Trust least privilege over time.
Cues: "periodically re-check existing access and remove what is not needed" = access reviews. "auto-remove denied access" = auto-apply. "periodically inventory high-privilege holders" = privileged-role access reviews (PIM-integrated). The entry-point control of request/approval/expiry is entitlement management (previous section).
Watch the mix-ups: (1) Access reviews (periodic re-check of existing access) vs entitlement management (request/grant/expiry). (2) Without auto-apply, denials are not actually removed until manually applied. (3) Without designing the no-response default, access may be unintentionally kept/removed.
5.2.3Section summary
- Access reviews = periodically re-check existing access (groups/apps/roles/guests); auto-apply removes denials
- Privileged-role reviews (PIM-integrated) inventory high privilege; design the no-response default
- Entitlement management (entry) + access reviews (continuous inventory) maintain least privilege over time
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. A department group’s membership has bloated over time. You want owners to review quarterly and auto-remove unneeded members. Which is best?
Q2. You want to periodically inventory holders of high-privilege roles like Global Administrator and reduce excessive privilege. Which is best?
Q3. You want denied results in an access review to be automatically reflected as actual access removal. What setting is needed?
Q4. Which correctly splits roles between access reviews and entitlement management?
Q5. When periodically reviewing external guest access, which is NOT a valid reviewer option?
Keep track of your progress
The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.

