|
| 1 | +--- |
| 2 | +title: Create an access review of an access package in Azure AD entitlement management |
| 3 | +description: Learn how to create an access review policy for entitlement management access packages in Azure Active Directory access reviews (Preview). |
| 4 | +services: active-directory |
| 5 | +documentationCenter: '' |
| 6 | +author: msaburnley |
| 7 | +manager: daveba |
| 8 | +editor: |
| 9 | +ms.service: active-directory |
| 10 | +ms.workload: identity |
| 11 | +ms.tgt_pltfrm: na |
| 12 | +ms.devlang: na |
| 13 | +ms.topic: conceptual |
| 14 | +ms.subservice: compliance |
| 15 | +ms.date: 11/01/2019 |
| 16 | +ms.author: ajburnle |
| 17 | +ms.reviewer: |
| 18 | +ms.collection: M365-identity-device-management |
| 19 | + |
| 20 | + |
| 21 | +#Customer intent: As an administrator, I want to create an access review policy for my access packages so I can review the active assignments of my users to ensure everyone has the appropriate access. |
| 22 | + |
| 23 | +--- |
| 24 | +# Create an access review of an access package in Azure AD entitlement management |
| 25 | + |
| 26 | +To reduce the risk of stale access, you should enable periodic reviews of users who have active assignments to an access package in Azure AD entitlement management. You can enable reviews when you create a new access package or edit an existing access package. This article describes how to enable access reviews of access packages. |
| 27 | + |
| 28 | +## Prerequisites |
| 29 | + |
| 30 | +To enable reviews of access packages, you must meet the prerequisites for creating an access package: |
| 31 | +- Azure AD Premium P2 |
| 32 | +- Global administrator, User administrator, Catalog owner, or Access package manager |
| 33 | + |
| 34 | +For more information, see [License requirements](entitlement-management-overview.md#license-requirements). |
| 35 | + |
| 36 | + |
| 37 | +## Create an access review of an access package |
| 38 | + |
| 39 | +You can enable access reviews when [creating a new access package](entitlement-management-access-package-create.md) or [editing an existing access package](entitlement-management-access-package-lifecycle-policy.md) policy. Follow these steps to enable access reviews of an access package: |
| 40 | + |
| 41 | +1. Open the **Lifecycle** tab for an access package and scroll down to **Access Reviews**. |
| 42 | + |
| 43 | +1. Move the **Require access reviews** toggle to **Yes**. |
| 44 | + |
| 45 | +  |
| 46 | + |
| 47 | +1. Specify the date the reviews will start next to **Starting on**. |
| 48 | + |
| 49 | +1. Next, set the **Review frequency** to **Annually**, **Bi-annually**, **Quarterly** or **Monthly**. |
| 50 | +This setting determines how often access reviews will occur. |
| 51 | + |
| 52 | +1. Set the **Duration** to define how many days each review of the recurring series will be open for input from reviewers. For example, you might schedule an annual review that starts on January 1st and is open for review for 30 days so that reviewers have until the end of the month to respond. |
| 53 | + |
| 54 | +1. Next to **Reviewers**, select **Self-review** if you want users to perform their own access review or select **Specific reviewer(s)** if you want to designate a reviewer. |
| 55 | + |
| 56 | +  |
| 57 | + |
| 58 | +1. If you selected **Specific reviewer(s)**, specify which users will do the access review: |
| 59 | + 1. Select **Add reviewers**. |
| 60 | + 1. In the **Select reviewers** pane, search for and select the user(s) you want to be a reviewer. |
| 61 | + 1. When you've selected your reviewer(s), click the **Select** button. |
| 62 | + |
| 63 | +  |
| 64 | + |
| 65 | +1. Click **Review + Create** if you are creating a new access package or **Update** if you are editing an access package, at the bottom of the page. |
| 66 | + |
| 67 | +## View the status of the access review |
| 68 | + |
| 69 | +After the start date, an access review will be listed in the **Access reviews** section. Follow these steps to view the status of an access review: |
| 70 | + |
| 71 | +1. In **Identity Governance**, click **Access packages** then select the access package with the access review status you'd like to check. |
| 72 | + |
| 73 | +1. Once you are on the access package overview, click **Access reviews** on the left menu. |
| 74 | + |
| 75 | +  |
| 76 | + |
| 77 | +1. A list will appear that contains all of the policies that have access reviews associated with them. Click the review to see its report. |
| 78 | + |
| 79 | +  |
| 80 | + |
| 81 | +1. When you view the report, it shows the number of users reviewed and the actions taken by the reviewer on them. |
| 82 | + |
| 83 | +  |
| 84 | + |
| 85 | + |
| 86 | +## Access reviews email notifications |
| 87 | +You can designate reviewers, or users can review their access themselves. By default, Azure AD will send an email to reviewers or self-reviewers shortly after the review starts. |
| 88 | + |
| 89 | +The email will include instructions on how to review access to access packages. If the review is for users to review their access, show them the instructions on how to perform a self-review of their access packages. |
| 90 | + |
| 91 | +If you've assigned guest users as reviewers, and they haven't accepted their Azure AD guest invitation, they won't receive emails from Azure AD access reviews. They must first accept the invite and create an account with Azure AD before they can receive the emails. |
| 92 | + |
| 93 | +## Next steps |
| 94 | + |
| 95 | +- [Review access of access packages](entitlement-management-access-reviews-review-access.md) |
| 96 | +- [Self-review of access packages](entitlement-management-access-reviews-self-review.md) |
0 commit comments