You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
# Review access to groups and applications in Azure AD access reviews
20
20
21
-
Azure Active Directory (Azure AD) simplifies how enterprises manage access to groups and applications in Azure AD and other Microsoft Online Services with a feature called Azure AD access reviews. This article will go over how a designated reviewer performs an access review for members of a group or users with access to an application. If you would like to review access to an access package read [Review access of an access package in Azure AD entitlement management](entitlement-management-access-reviews-review-access.md)
21
+
Azure Active Directory (Azure AD) simplifies how enterprises manage access to groups and applications in Azure AD and other Microsoft web services with a feature called Azure AD access reviews. This article will cover how a designated reviewer performs an access review for members of a group or users with access to an application. If you want to review access to an access package, read [Review access of an access package in Azure AD entitlement management](entitlement-management-access-reviews-review-access.md).
22
22
23
-
## Perform access review using My Access
24
-
You can review access to groups and applications via My Access, an end-user friendly portal for granting, approving, and reviewing access needs.
23
+
## Perform access review by using My Access
24
+
You can review access to groups and applications via My Access. My Access is a user-friendly portal for granting, approving, and reviewing access needs.
25
25
26
-
### Use email to navigate to My Access
26
+
### Use email to go to My Access
27
27
28
28
>[!IMPORTANT]
29
-
> There could be delays in receiving email and it some cases it could take up to 24 hours. Add [email protected] to your safe recipients list to make sure that you are receiving all emails.
29
+
> There could be delays in receiving email. In some cases, it could take up to 24 hours. Add [email protected] to your safe recipients list to make sure that you're receiving all emails.
30
30
31
-
1. Look for an email from Microsoft asking you to review access. You can see an example email message below:
31
+
1. Look for an email from Microsoft asking you to review access. Here's an example email message:
32
32
33
-

33
+

34
34
35
-
1.Click the **Start review** link to open the access review.git pu
35
+
1.Select the **Start review** link to open the access review.
36
36
37
-
### Navigate directly to My Access
37
+
### Go directly to My Access
38
38
39
39
You can also view your pending access reviews by using your browser to open My Access.
40
40
41
-
1. Sign in to the My Access at https://myaccess.microsoft.com/
41
+
1. Sign in to My Access at https://myaccess.microsoft.com/.
42
42
43
-
2. Select **Access reviews** from the menu on the left side bar to see a list of pending access reviews assigned to you.
43
+
2. Select **Access reviews** from the left menu to see a list of pending access reviews assigned to you.
44
44
45
45
## Review access for one or more users
46
46
47
-
After you open My Access under Groups and Apps you can see:
47
+
After you open My Access under **Groups and Apps**, you can see:
48
48
49
-
-**Name** The name of the access review.
50
-
-**Due** The due date for the review. After this date denied users could be removed from the group or app being reviewed.
51
-
-**Resource** The name of the resource under review.
52
-
-**Progress** The number of users reviewed over the total number of users part of this access review.
49
+
-**Name**: The name of the access review.
50
+
-**Due**: The due date for the review. After this date, denied users could be removed from the group or app being reviewed.
51
+
-**Resource**: The name of the resource under review.
52
+
-**Progress**: The number of users reviewed over the total number of users part of this access review.
53
53
54
-
Click on the name of an access review to get started.
54
+
Select the name of an access review to get started.
55
55
56
-

56
+

57
57
58
-
Once that it opens, you will see the list of users in scope for the access review.
58
+
After it opens, you'll see the list of users in scope for the access review.
59
59
60
-
> [!NOTE]
60
+
> [!NOTE]
61
61
> If the request is to review your own access, the page will look different. For more information, see [Review access for yourself to groups or applications](review-your-access.md).
62
62
63
63
There are two ways that you can approve or deny access:
@@ -69,72 +69,75 @@ There are two ways that you can approve or deny access:
69
69
70
70
1. Review the list of users and decide whether to approve or deny their continued access.
71
71
72
-
1. Select one or more users by clicking the circle next to their names.
72
+
1. Select one or more users by selecting the circle next to their names.
73
+
74
+
1. Select **Approve** or **Deny** on the bar.
75
+
76
+
If you're unsure if a user should continue to have access, you can select **Don't know**. The user gets to keep their access, and your choice is recorded in the audit logs. Keep in mind that any information you provide will be available to other reviewers. They can read your comments and take them into account when they review the request.
73
77
74
-
1. Select **Approve** or **Deny** on the bar above.
75
-
- If you are unsure if a user should continue to have access or not, you can click **Don't know**. The user gets to keep their access and your choice is recorded in the audit logs. It is important that you keep in mind that any information you provide will be available to other reviewers. They can read your comments and take them into account when they review the request.
78
+

76
79
77
-

80
+
1. The administrator of the access review might require you to supply a reason for your decision in the **Reason** box, even when a reason is not required. You can still provide a reason for your decision. The information that you include will be available to other approvers for review.
78
81
79
-
1.The administrator of the access review may require that you supply a reason in the **Reason** box for your decision. Even when a reason is not required. You can still provide a reason for your decision and the information that you include will be available to other approvers for review.
82
+
1.Select **Submit**.
80
83
81
-
1. Click **Submit**.
82
-
- You can change your response at any time until the access review has ended. If you want to change your response, select the row and update the response. For example, you can approve a previously denied user or deny a previously approved user.
84
+
You can change your response at any time until the access review has ended. If you want to change your response, select the row and update the response. For example, you can approve a previously denied user or deny a previously approved user.
83
85
84
86
> [!IMPORTANT]
85
-
> - If a user is denied access, they aren't removed immediately. They are removed when the review period has ended or when an administrator stops the review.
86
-
> - If there are multiple reviewers, the last submitted response is recorded. Consider an example where an administrator designates two reviewers – Alice and Bob. Alice opens the access review first and approves a user's access request. Before the review period ends, Bob opens the access review and denies access on the same request previously approved by Alice. The last decision denying the access is the response that gets recorded.
87
+
> - If a user is denied access, they aren't removed immediately. The user is removed when the review period has ended or when an administrator stops the review.
88
+
> - If there are multiple reviewers, the last submitted response is recorded. Consider an example where an administrator designates two reviewers: Alice and Bob. Alice opens the access review first and approves a user's access request. Before the review period ends, Bob opens the access review and denies access on the same request previously approved by Alice. The last decision denying the access is the response that gets recorded.
87
89
88
90
### Review access based on recommendations
89
91
90
-
To make access reviews easier and faster for you, we also provide recommendations that you can accept with a single click. There are two ways recommendations are generated for the reviewer. One method the system uses to create recommendations is by the user's sign-in activity. If a user has been inactive for 30 days or more, the reviewer will be recommended to deny access. The other method is based on the access the user's peers have. If the user doesn't have the same access as their peers, the reviewer will be recommended to deny that user access.
92
+
To make access reviews easier and faster for you, we also provide recommendations that you can accept with a single selection. There are two ways that the system generates recommendations for the reviewer. One method is by the user's sign-in activity. If a user has been inactive for 30 days or more, the system will recommend that the reviewer deny access.
91
93
92
-
If you have**No sign-in within 30 days** or **Peer outlier** enabled, follow the steps below to accept recommendations:
94
+
The other method is based on the access that the user's peers have. If the user doesn't have the same access as their peers, the system will recommend that the reviewer deny that user access.
93
95
94
-
1. Select one or more users and then Click**Accept recommendations**.
96
+
If you have **No sign-in within 30 days** or**Peer outlier** enabled, follow these steps to accept recommendations:
95
97
96
-

98
+
1. Select one or more users, and then select **Accept recommendations**.
97
99
98
-
1. Or to accept recommendations for all unreviewed users, make sure that no users are selected and click on the **Accept recommendations** button on the top bar.
100
+

99
101
100
-
1. Click **Submit**to accept the recommendations.
102
+
Or to accept recommendations for all unreviewed users, make sure that no users are selected and then select the **Accept recommendations**button on the top bar.
101
103
104
+
1. Select **Submit** to accept the recommendations.
102
105
103
106
> [!NOTE]
104
-
> When you accept recommendations previous decisions will not be changed.
107
+
> When you accept recommendations, previous decisions won't be changed.
105
108
106
109
### Review access for one or more users in a multi-stage access review (preview)
107
110
108
-
If multi-stage access reviews have been enabled by the administrator, there will be 2 or 3 total stages of review. Each stage of review will have a specified reviewer.
111
+
If the administrator has enabled multi-stage access reviews, there will be two or three total stages of review. Each stage of review will have a specified reviewer.
109
112
110
-
You will review access either manually or accept the recommendations based on sign-in activity for the stage you are assigned as the reviewer.
113
+
You will either review access manually or accept the recommendations based on sign-in activity for the stage you're assigned as the reviewer.
111
114
112
-
If you are the 2nd stage or 3rd stage reviewer, you will also see the decisions made by the reviewers in the prior stage(s) if the administrator enabled this setting when creating the access review. The decision made by a 2nd or 3rd stage reviewer will overwrite the previous stage. So, the decision the 2nd stage reviewer makes will overwrite the first stage, and the 3rd stage reviewer's decision will overwrite the second stage.
115
+
If you're the second-stage or third-stage reviewer, you'll also see the decisions made by the reviewers in the prior stages, if the administrator enabled this setting when creating the access review. The decision made by a second-stage or third-stage reviewer will overwrite the previous stage. So, the decision that the second-stage reviewer makes will overwrite the first stage. And the third-stage reviewer's decision will overwrite the second stage.
113
116
114
-

117
+

115
118
116
119
Approve or deny access as outlined in [Review access for one or more users](#review-access-for-one-or-more-users).
117
120
118
121
> [!NOTE]
119
-
> The next stage of the review won't become active until the duration specified during the access review setup has passed. If the administrator believes a stage is done but the review duration for this stage has not expired yet, they can use the **Stop current stage** button in the overview of the access review in the Azure AD portal. This will close the active stage and start the next stage.
122
+
> The next stage of the review won't become active until the duration specified during the access review setup has passed. If the administrator believes a stage is done but the review duration for this stage has not expired yet, they can use the **Stop current stage** button in the overview of the access review in the Azure AD portal. This action will close the active stage and start the next stage.
120
123
121
-
### Review access for B2B direct connect users in Teams Shared Channels and Microsoft 365 groups (preview)
124
+
### Review access for B2B direct connect users in Teams shared channels and Microsoft 365 groups (preview)
122
125
123
126
To review access of B2B direct connect users, use the following instructions:
124
127
125
-
1. As the reviewer, you should receive an email that requests you to review access for the team or group. Click the link in the email, or navigate directly to https://myaccess.microsoft.com/.
128
+
1. As the reviewer, you should receive an email that requests you to review access for the team or group. Select the link in the email, or go directly to https://myaccess.microsoft.com/.
126
129
127
-
1. Follow the instructions in [Review access for one or more users](#review-access-for-one-or-more-users) to make decisions to approve or deny the users access to the Teams.
130
+
1. Follow the instructions in [Review access for one or more users](#review-access-for-one-or-more-users) to make decisions to approve or deny the users access to the teams.
128
131
129
132
> [!NOTE]
130
-
> Unlike internal users and B2B Collaboration users, B2B direct connect users and Teams **don't** have recommendations based on last sign-in activity to make decisions when you perform the review.
133
+
> Unlike internal users and B2B collaboration users, B2B direct connect users and teams _don't_ have recommendations based on last sign-in activity to make decisions when you perform the review.
131
134
132
-
If a Team you review has shared channels, all B2B direct connect users and teams that access those shared channels are part of the review. This includes B2B collaboration users and internal users. When a B2B direct connect user or team is denied access in an access review, the user will lose access to every shared channel in the Team. To learn more about B2B direct connect users, read [B2B direct connect](../external-identities/b2b-direct-connect-overview.md).
135
+
If a team you review has shared channels, all B2B direct connect users and teams that access those shared channels are part of the review. This includes B2B collaboration users and internal users. When a B2B direct connect user or team is denied access in an access review, the user will lose access to every shared channel in the team. To learn more about B2B direct connect users, read [B2B direct connect](../external-identities/b2b-direct-connect-overview.md).
133
136
134
-
## If no action is taken on access review
135
-
When the access review is setup, the administrator has the option to use advanced settings to determine what will happen in the event a reviewer doesn't respond to an access review request.
137
+
## Set up what will happen if no action is taken on access review
138
+
When the access review is set up, the administrator has the option to use advanced settings to determine what will happen if a reviewer doesn't respond to an access review request.
136
139
137
-
The administrator can set up the review so that if reviewers do not respond at the end of the review period, all unreviewed users can have an automatic decision made on their access. This includes the loss of access to the group or application under review.
140
+
The administrator can set up the review so that if reviewers don't respond at the end of the review period, all unreviewed users can have an automatic decision made on their access. This includes the loss of access to the group or application under review.
0 commit comments