You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory/governance/perform-access-review.md
+16-14Lines changed: 16 additions & 14 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -76,22 +76,24 @@ There are two ways that you can approve or deny access:
76
76
77
77

78
78
79
-
1. The administrator of the access review may require you to supply a reason for your decision in the **Reason** box, even when a reason is not required. You can still provide a reason for your decision, and the information that you include will be available to other approvers for review.
79
+
1. The administrator of the access review may require you to supply a reason for your decision in the **Reason** box, even when a reason is not required. You can still provide a reason for your decision. The information that you include will be available to other approvers for review.
80
80
81
81
1. Select **Submit**.
82
82
- You can change your response at any time until the access review has ended. If you want to change your response, select the row and update the response. For example, you can approve a previously denied user or deny a previously approved user.
83
83
84
84
> [!IMPORTANT]
85
-
> - If a user is denied access, they aren't removed immediately. They are removed when the review period has ended or when an administrator stops the review.
86
-
> - If there are multiple reviewers, the last submitted response is recorded. Consider an example where an administrator designates two reviewers – Alice and Bob. Alice opens the access review first and approves a user's access request. Before the review period ends, Bob opens the access review and denies access on the same request previously approved by Alice. The last decision denying the access is the response that gets recorded.
85
+
> - If a user is denied access, they aren't removed immediately. The user is removed when the review period has ended or when an administrator stops the review.
86
+
> - If there are multiple reviewers, the last submitted response is recorded. Consider an example where an administrator designates two reviewers: Alice and Bob. Alice opens the access review first and approves a user's access request. Before the review period ends, Bob opens the access review and denies access on the same request previously approved by Alice. The last decision denying the access is the response that gets recorded.
87
87
88
88
### Review access based on recommendations
89
89
90
-
To make access reviews easier and faster for you, we also provide recommendations that you can accept with a single selection. There are two ways recommendations are generated for the reviewer. One method the system uses to create recommendations is by the user's sign-in activity. If a user has been inactive for 30 days or more, it will be recommended that the reviewer to deny access. The other method is based on the access the user's peers have. If the user doesn't have the same access as their peers, it will be recommended that the reviewer deny that user access.
90
+
To make access reviews easier and faster for you, we also provide recommendations that you can accept with a single selection. There are two ways that recommendations are generated for the reviewer. One method that the system uses to create recommendations is by the user's sign-in activity. If a user has been inactive for 30 days or more, the system will recommend that the reviewer deny access.
91
+
92
+
The other method is based on the access that the user's peers have. If the user doesn't have the same access as their peers, the system will recommend that the reviewer deny that user access.
91
93
92
94
If you have **No sign-in within 30 days** or **Peer outlier** enabled, follow these steps to accept recommendations:
93
95
94
-
1. Select one or more users and then select**Accept recommendations**.
96
+
1. Select one or more users and then click**Accept recommendations**.
95
97
96
98

97
99
@@ -106,32 +108,32 @@ If you have **No sign-in within 30 days** or **Peer outlier** enabled, follow th
106
108
107
109
If multi-stage access reviews have been enabled by the administrator, there will be two or three total stages of review. Each stage of review will have a specified reviewer.
108
110
109
-
You will review access either manually or accept the recommendations based on sign-in activity for the stage you're assigned as the reviewer.
111
+
You will either review access manually or accept the recommendations based on sign-in activity for the stage you're assigned as the reviewer.
110
112
111
-
If you're the second- or third-stage reviewer, you will also see the decisions made by the reviewers in the prior stage(s), if the administrator enabled this setting when creating the access review. The decision made by a second- or third-stage reviewer will overwrite the previous stage. So, the decision the second-stage reviewer makes will overwrite the first stage, and the third-stage reviewer's decision will overwrite the second stage.
113
+
If you're the second-stage or third-stage reviewer, you will also see the decisions made by the reviewers in the prior stage(s), if the administrator enabled this setting when creating the access review. The decision made by a second-stage or third-stage reviewer will overwrite the previous stage. So, the decision that the second-stage reviewer makes will overwrite the first stage. And the third-stage reviewer's decision will overwrite the second stage.
112
114
113
115

114
116
115
117
Approve or deny access as outlined in [Review access for one or more users](#review-access-for-one-or-more-users).
116
118
117
119
> [!NOTE]
118
-
> The next stage of the review won't become active until the duration specified during the access review setup has passed. If the administrator believes a stage is done but the review duration for this stage has not expired yet, they can use the **Stop current stage** button in the overview of the access review in the Azure AD portal. This will close the active stage and start the next stage.
120
+
> The next stage of the review won't become active until the duration specified during the access review setup has passed. If the administrator believes a stage is done but the review duration for this stage has not expired yet, they can use the **Stop current stage** button in the overview of the access review in the Azure AD portal. This action will close the active stage and start the next stage.
119
121
120
-
### Review access for B2B direct connect users in Teams Shared Channels and Microsoft 365 groups (preview)
122
+
### Review access for B2B direct connect users in Teams shared channels and Microsoft 365 groups (preview)
121
123
122
124
To review access of B2B direct connect users, use the following instructions:
123
125
124
126
1. As the reviewer, you should receive an email that requests you to review access for the team or group. Select the link in the email, or go directly to https://myaccess.microsoft.com/.
125
127
126
-
1. Follow the instructions in [Review access for one or more users](#review-access-for-one-or-more-users) to make decisions to approve or deny the users access to Teams.
128
+
1. Follow the instructions in [Review access for one or more users](#review-access-for-one-or-more-users) to make decisions to approve or deny the users access to the teams.
127
129
128
130
> [!NOTE]
129
-
> Unlike internal users and B2B collaboration users, B2B direct connect users and Teams **don't** have recommendations based on last sign-in activity to make decisions when you perform the review.
131
+
> Unlike internal users and B2B collaboration users, B2B direct connect users and teams _don't_ have recommendations based on last sign-in activity to make decisions when you perform the review.
130
132
131
-
If a Team you review has shared channels, all B2B direct connect users and teams that access those shared channels are part of the review. This includes B2B collaboration users and internal users. When a B2B direct connect user or team is denied access in an access review, the user will lose access to every shared channel in the Team. To learn more about B2B direct connect users, read [B2B direct connect](../external-identities/b2b-direct-connect-overview.md).
133
+
If a team you review has shared channels, all B2B direct connect users and teams that access those shared channels are part of the review. This includes B2B collaboration users and internal users. When a B2B direct connect user or team is denied access in an access review, the user will lose access to every shared channel in the team. To learn more about B2B direct connect users, read [B2B direct connect](../external-identities/b2b-direct-connect-overview.md).
132
134
133
-
## If no action is taken on access review
134
-
When the access review is set up, the administrator has the option to use advanced settings to determine what will happen in the event a reviewer doesn't respond to an access review request.
135
+
## Set up what will happen if no action is taken on access review
136
+
When the access review is set up, the administrator has the option to use advanced settings to determine what will happen if a reviewer doesn't respond to an access review request.
135
137
136
138
The administrator can set up the review so that if reviewers don't respond at the end of the review period, all unreviewed users can have an automatic decision made on their access. This includes the loss of access to the group or application under review.
0 commit comments