You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
You can use entitlement management as a way of onboarding external users. This feature allows external users to request access to a set of resources and where you can set up approvals before they gain access to your directory. For external users onboarded through entitlement, you can manage their lifecycle through access packages. When their last access package expires, they'll be removed from your directory.
23
23
24
-
In this tutorial, you work for WoodGrove Bank as an IT administrator. You’ve been asked to create an access package to onboard partners from an outside organization that your business group is working with. They will need access to a Teams group called **External collaboration**.
24
+
In this tutorial, you work for WoodGrove Bank as an IT administrator. You’ve been asked to create an access package to onboard partners from an outside organization that your business group is working with. They'll need access to a Teams group called **External collaboration**.
25
25
Approval is needed by an internal sponsor for collaborating organizations. Also, you've been informed that the partner's access needs to expire after 60 days.
26
26
To use entitlement management, you must have one of the following licenses:
27
27
@@ -34,35 +34,35 @@ For more information, see [License requirements](entitlement-management-overview
34
34
35
35
**Prerequisite role:** Global administrator, Identity Governance administrator, User administrator, Catalog owner, or Access package manager
36
36
37
-
1. In the Azure portal, in the left navigation, click**Azure Active Directory**.
37
+
1. In the Azure portal, in the left navigation, select**Azure Active Directory**.
38
38
39
-
2. In the left menu, click**Identity Governance**.
39
+
2. In the left menu, select**Identity Governance**.
40
40
41
-
3. In the left menu, click**Access packages**. If you see Access denied, ensure that an Azure AD Premium P2 license is present in your directory.
41
+
3. In the left menu, select**Access packages**. If you see Access denied, ensure that an Azure AD Premium P2 license is present in your directory.
42
42
43
-
4.Click**New access package**.
43
+
4.Select**New access package**.
44
44
45
45
5. On the **Basics** tab, enter the name **External user package** and description **Access for external users pending approval**.
46
46
47
47
6. You can leave the **Catalog** drop-down list set to **General**.
48
48
49
49
## Step 2: Configure resources
50
50
51
-
1.Click**Next** to open the **Resource roles** tab.
51
+
1.Select**Next** to open the **Resource roles** tab.
52
52
53
53
On this tab, you select the resources and the resource role to include in the access package.
54
54
55
-
2.Click on **Groups and Teams** and search for your group **External collaboration**.
55
+
2.Select on **Groups and Teams** and search for your group **External collaboration**.
56
56
57
57
## Step 3: Configure requests
58
58
59
-
1.Click**Next** to open the **Requests** tab.
59
+
1.Select**Next** to open the **Requests** tab.
60
60
61
61
On this tab, you create a request policy. A *policy* defines the rules or guardrails to access an access package. You create a policy that allows a specific user in the resource directory to request this access package.
62
62
63
-
2. In the **Users who can request access** section, click**For users not in your directory** and then click**All users (All connected organizations + any new external users)**.
63
+
2. In the **Users who can request access** section, select**For users not in your directory** and then select**All users (All connected organizations + any new external users)**.
64
64
65
-
3. Because any user who is not yet in your directory can view and submit a request for this access package, **Yes** is mandatory for the **Require approval** setting.
65
+
3. Because any user who isn't yet in your directory can view and submit a request for this access package, **Yes** is mandatory for the **Require approval** setting.
66
66
67
67
4. The following settings allow you to configure how your approvals work for your external users:
68
68
@@ -80,13 +80,13 @@ For more information, see [License requirements](entitlement-management-overview
80
80
81
81
## Step 4: Configure requestor information
82
82
83
-
1.Click**Next** to open the **Requestor information** tab
83
+
1.Select**Next** to open the **Requestor information** tab
84
84
85
85
2. On this screen, you can ask additional questions to collect more information from your requestor. These questions are shown on their request form and can be set to required or optional. For now you can leave these as empty.
86
86
87
87
## Step 5: Configure lifecycle
88
88
89
-
1.Click**Next** to open the **Lifecycle** tab
89
+
1.Select**Next** to open the **Lifecycle** tab
90
90
91
91
2. In the **Expiration** section, set **Access package assignment expire** to **Number of days**.
92
92
@@ -96,11 +96,11 @@ For more information, see [License requirements](entitlement-management-overview
96
96
97
97
## Step 6: Review and create your access package
98
98
99
-
1.Click**Next** to open the **Review + Create** tab.
99
+
1.Select**Next** to open the **Review + Create** tab.
100
100
101
101
2. On this screen, you can review the configuration for your access package before creating. If there are any issues, you can use the tabs to navigate to a specific point in the create experience to make edits.
102
102
103
-
3. When you're happy with your selections, click on **Create**. After a few moments, you should see a notification that the access package was successfully created.
103
+
3. When you're happy with your selections, select on **Create**. After a few moments, you should see a notification that the access package was successfully created.
104
104
105
105
4. Once created, you’ll be brought to the **Overview** page for your access package. You can find the **My Access portal link** and copy the value here. Share this link with your external users and they can go to request this package to start collaborating.
106
106
@@ -110,15 +110,15 @@ In this step, you can delete the **External user package** access package.
110
110
111
111
**Prerequisite role:** Global administrator, Identity Governance administrator or Access package manager
112
112
113
-
1. In the **Azure portal**, in the left navigation, click**Azure Active Directory**.
113
+
1. In the **Azure portal**, in the left navigation, select**Azure Active Directory**.
114
114
115
-
2. In the left menu, click**Identity Governance**.
115
+
2. In the left menu, select**Identity Governance**.
116
116
117
-
3. In the left menu, click**Access Packages**.
117
+
3. In the left menu, select**Access Packages**.
118
118
119
119
4. Open the **External user package** access package.
120
120
121
-
5.Click**Resource Roles**.
121
+
5.Select**Resource Roles**.
122
122
123
123
6. Select the **External collaboration** group you added to this access package, and in the **Details** pane, select **Remove resource role**. In the message that appears, select **Yes**.
0 commit comments