Instiq
Chapter 5 · Identity governance and monitoring·v1.0.0·Updated 6/28/2026·~12 min

What's changed: Created SC-300 Chapter 5 (Domain 4: entitlement management (catalogs/access packages/policies/My Access/connected organizations/ToU/external lifecycle); access reviews (scope/reviewers/auto-apply/privileged-role reviews); PIM (eligible/active/activation/Entra roles/Azure resources/PIM for Groups/settings/audit history/break-glass); monitoring (sign-in/audit/provisioning logs/diagnostic settings Log Analytics-storage-Event Hubs/KQL/workbooks/Identity Secure Score)).

5.2Access reviews

Key points

Understand periodically re-certifying existing access to groups/apps/roles with Microsoft Entra access reviews, and planning/creating/monitoring reviews and responding to results.

Access accumulates over time, creating "rights that remain though no longer needed (permission creep)." Access reviews periodically re-check existing access ("still needed?") and remove what is not.

5.2.1Creating reviews and reviewers

In an access review, set the target (group members, app assignments, privileged roles, guests) and frequency (one-time/recurring), and designate reviewers (resource owners, the user themselves = self-review, managers). Enabling auto-apply removes denied access automatically (manual apply is also possible). Design the default for no-response (remove/keep/follow recommendations). Periodic guest reviews and privileged-role reviews are especially important.

Continue reading — free sign-up

You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.