You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
# Review access to groups and applications in Azure AD access reviews
20
20
21
-
Azure Active Directory (Azure AD) simplifies how enterprises manage access to groups and applications in Azure AD and other Microsoft web services with a feature called Azure AD access reviews. This article will cover how a designated reviewer performs an access review for members of a group or users with access to an application. If you'd like to review access to an access package, read [Review access of an access package in Azure AD entitlement management](entitlement-management-access-reviews-review-access.md).
21
+
Azure Active Directory (Azure AD) simplifies how enterprises manage access to groups and applications in Azure AD and other Microsoft web services with a feature called Azure AD access reviews. This article will cover how a designated reviewer performs an access review for members of a group or users with access to an application. If you want to review access to an access package, read [Review access of an access package in Azure AD entitlement management](entitlement-management-access-reviews-review-access.md).
22
22
23
23
## Perform access review by using My Access
24
-
You can review access to groups and applications via My Access. My Access is an userfriendly portal for granting, approving, and reviewing access needs.
24
+
You can review access to groups and applications via My Access. My Access is a user-friendly portal for granting, approving, and reviewing access needs.
25
25
26
26
### Use email to go to My Access
27
27
28
28
>[!IMPORTANT]
29
-
> There could be delays in receiving email and in some cases it could take up to 24 hours. Add [email protected] to your safe recipients list to make sure that you're receiving all emails.
29
+
> There could be delays in receiving email. In some cases, it could take up to 24 hours. Add [email protected] to your safe recipients list to make sure that you're receiving all emails.
30
30
31
-
1. Look for an email from Microsoft asking you to review access. Here is an example email message:
31
+
1. Look for an email from Microsoft asking you to review access. Here's an example email message:
32
32
33
33

34
34
35
-
1.Click the **Start review** link to open the access review.
35
+
1.Select the **Start review** link to open the access review.
36
36
37
37
### Go directly to My Access
38
38
39
39
You can also view your pending access reviews by using your browser to open My Access.
40
40
41
41
1. Sign in to My Access at https://myaccess.microsoft.com/.
42
42
43
-
2. Select **Access reviews** from the menu on the left side bar to see a list of pending access reviews assigned to you.
43
+
2. Select **Access reviews** from the left menu to see a list of pending access reviews assigned to you.
44
44
45
45
## Review access for one or more users
46
46
47
-
After you open My Access under **Groups and Apps** you can see:
47
+
After you open My Access under **Groups and Apps**, you can see:
48
48
49
49
-**Name**: The name of the access review.
50
50
-**Due**: The due date for the review. After this date, denied users could be removed from the group or app being reviewed.
@@ -55,7 +55,7 @@ Select the name of an access review to get started.
55
55
56
56

57
57
58
-
After it opens, you will see the list of users in scope for the access review.
58
+
After it opens, you'll see the list of users in scope for the access review.
59
59
60
60
> [!NOTE]
61
61
> If the request is to review your own access, the page will look different. For more information, see [Review access for yourself to groups or applications](review-your-access.md).
@@ -77,29 +77,29 @@ There are two ways that you can approve or deny access:
77
77
78
78

79
79
80
-
1. The administrator of the access review may require you to supply a reason for your decision in the **Reason** box, even when a reason is not required. You can still provide a reason for your decision. The information that you include will be available to other approvers for review.
80
+
1. The administrator of the access review might require you to supply a reason for your decision in the **Reason** box, even when a reason is not required. You can still provide a reason for your decision. The information that you include will be available to other approvers for review.
81
81
82
82
1. Select **Submit**.
83
83
84
84
You can change your response at any time until the access review has ended. If you want to change your response, select the row and update the response. For example, you can approve a previously denied user or deny a previously approved user.
85
85
86
86
> [!IMPORTANT]
87
87
> - If a user is denied access, they aren't removed immediately. The user is removed when the review period has ended or when an administrator stops the review.
88
-
> - If there are multiple reviewers, the last submitted response is recorded. Consider an example where an administrator designates two reviewers: Alice and Bob. Alice opens the access review first and approves a user's access request. Before the review period ends, Bob opens the access review and denies access on the same request previously approved by Alice. The last decision denying the access is the response that gets recorded.
88
+
> - If there are multiple reviewers, the last submitted response is recorded. Consider an example where an administrator designates two reviewers: Alice and Bob. Alice opens the access review first and approves a user's access request. Before the review period ends, Bob opens the access review and denies access on the same request previously approved by Alice. The last decision denying the access is the response that gets recorded.
89
89
90
90
### Review access based on recommendations
91
91
92
-
To make access reviews easier and faster for you, we also provide recommendations that you can accept with a single selection. There are two ways that recommendations are generated for the reviewer. One method that the system uses to create recommendations is by the user's sign-in activity. If a user has been inactive for 30 days or more, the system will recommend that the reviewer deny access.
92
+
To make access reviews easier and faster for you, we also provide recommendations that you can accept with a single selection. There are two ways that the system generates recommendations for the reviewer. One method is by the user's sign-in activity. If a user has been inactive for 30 days or more, the system will recommend that the reviewer deny access.
93
93
94
94
The other method is based on the access that the user's peers have. If the user doesn't have the same access as their peers, the system will recommend that the reviewer deny that user access.
95
95
96
96
If you have **No sign-in within 30 days** or **Peer outlier** enabled, follow these steps to accept recommendations:
97
97
98
-
1. Select one or more users and then click**Accept recommendations**.
98
+
1. Select one or more users, and then select**Accept recommendations**.
99
99
100
-

100
+

101
101
102
-
Or to accept recommendations for all unreviewed users, make sure that no users are selected and click the **Accept recommendations** button on the top bar.
102
+
Or to accept recommendations for all unreviewed users, make sure that no users are selected and then select the **Accept recommendations** button on the top bar.
103
103
104
104
1. Select **Submit** to accept the recommendations.
105
105
@@ -108,11 +108,11 @@ If you have **No sign-in within 30 days** or **Peer outlier** enabled, follow th
108
108
109
109
### Review access for one or more users in a multi-stage access review (preview)
110
110
111
-
If multi-stage access reviews have been enabled by the administrator, there will be two or three total stages of review. Each stage of review will have a specified reviewer.
111
+
If the administrator has enabled multi-stage access reviews, there will be two or three total stages of review. Each stage of review will have a specified reviewer.
112
112
113
113
You will either review access manually or accept the recommendations based on sign-in activity for the stage you're assigned as the reviewer.
114
114
115
-
If you're the second-stage or third-stage reviewer, you will also see the decisions made by the reviewers in the prior stage(s), if the administrator enabled this setting when creating the access review. The decision made by a second-stage or third-stage reviewer will overwrite the previous stage. So, the decision that the second-stage reviewer makes will overwrite the first stage. And the third-stage reviewer's decision will overwrite the second stage.
115
+
If you're the second-stage or third-stage reviewer, you'll also see the decisions made by the reviewers in the prior stages, if the administrator enabled this setting when creating the access review. The decision made by a second-stage or third-stage reviewer will overwrite the previous stage. So, the decision that the second-stage reviewer makes will overwrite the first stage. And the third-stage reviewer's decision will overwrite the second stage.
116
116
117
117

0 commit comments