Skip to content

Commit a86926c

Browse files
authored
Merge pull request #205845 from JamesJBarnett/perform-access-review
edit pass: perform-access-review
2 parents 9c52e20 + 5c8fc7d commit a86926c

File tree

1 file changed

+52
-49
lines changed

1 file changed

+52
-49
lines changed

articles/active-directory/governance/perform-access-review.md

Lines changed: 52 additions & 49 deletions
Original file line numberDiff line numberDiff line change
@@ -18,46 +18,46 @@ ms.collection: M365-identity-device-management
1818

1919
# Review access to groups and applications in Azure AD access reviews
2020

21-
Azure Active Directory (Azure AD) simplifies how enterprises manage access to groups and applications in Azure AD and other Microsoft Online Services with a feature called Azure AD access reviews. This article will go over how a designated reviewer performs an access review for members of a group or users with access to an application. If you would like to review access to an access package read [Review access of an access package in Azure AD entitlement management](entitlement-management-access-reviews-review-access.md)
21+
Azure Active Directory (Azure AD) simplifies how enterprises manage access to groups and applications in Azure AD and other Microsoft web services with a feature called Azure AD access reviews. This article will cover how a designated reviewer performs an access review for members of a group or users with access to an application. If you want to review access to an access package, read [Review access of an access package in Azure AD entitlement management](entitlement-management-access-reviews-review-access.md).
2222

23-
## Perform access review using My Access
24-
You can review access to groups and applications via My Access, an end-user friendly portal for granting, approving, and reviewing access needs.
23+
## Perform access review by using My Access
24+
You can review access to groups and applications via My Access. My Access is a user-friendly portal for granting, approving, and reviewing access needs.
2525

26-
### Use email to navigate to My Access
26+
### Use email to go to My Access
2727

2828
>[!IMPORTANT]
29-
> There could be delays in receiving email and it some cases it could take up to 24 hours. Add [email protected] to your safe recipients list to make sure that you are receiving all emails.
29+
> There could be delays in receiving email. In some cases, it could take up to 24 hours. Add [email protected] to your safe recipients list to make sure that you're receiving all emails.
3030
31-
1. Look for an email from Microsoft asking you to review access. You can see an example email message below:
31+
1. Look for an email from Microsoft asking you to review access. Here's an example email message:
3232

33-
![Example email from Microsoft to review access to a group](./media/perform-access-review/access-review-email-preview.png)
33+
![Screenshot of example email from Microsoft to review access to a group.](./media/perform-access-review/access-review-email-preview.png)
3434

35-
1. Click the **Start review** link to open the access review.git pu
35+
1. Select the **Start review** link to open the access review.
3636

37-
### Navigate directly to My Access
37+
### Go directly to My Access
3838

3939
You can also view your pending access reviews by using your browser to open My Access.
4040

41-
1. Sign in to the My Access at https://myaccess.microsoft.com/
41+
1. Sign in to My Access at https://myaccess.microsoft.com/.
4242

43-
2. Select **Access reviews** from the menu on the left side bar to see a list of pending access reviews assigned to you.
43+
2. Select **Access reviews** from the left menu to see a list of pending access reviews assigned to you.
4444

4545
## Review access for one or more users
4646

47-
After you open My Access under Groups and Apps you can see:
47+
After you open My Access under **Groups and Apps**, you can see:
4848

49-
- **Name** The name of the access review.
50-
- **Due** The due date for the review. After this date denied users could be removed from the group or app being reviewed.
51-
- **Resource** The name of the resource under review.
52-
- **Progress** The number of users reviewed over the total number of users part of this access review.
49+
- **Name**: The name of the access review.
50+
- **Due**: The due date for the review. After this date, denied users could be removed from the group or app being reviewed.
51+
- **Resource**: The name of the resource under review.
52+
- **Progress**: The number of users reviewed over the total number of users part of this access review.
5353

54-
Click on the name of an access review to get started.
54+
Select the name of an access review to get started.
5555

56-
![Pending access reviews list for apps and groups](./media/perform-access-review/access-reviews-list-preview.png)
56+
![Screenshot of pending access reviews list for apps and groups.](./media/perform-access-review/access-reviews-list-preview.png)
5757

58-
Once that it opens, you will see the list of users in scope for the access review.
58+
After it opens, you'll see the list of users in scope for the access review.
5959

60-
> [!NOTE]
60+
> [!NOTE]
6161
> If the request is to review your own access, the page will look different. For more information, see [Review access for yourself to groups or applications](review-your-access.md).
6262
6363
There are two ways that you can approve or deny access:
@@ -69,72 +69,75 @@ There are two ways that you can approve or deny access:
6969

7070
1. Review the list of users and decide whether to approve or deny their continued access.
7171

72-
1. Select one or more users by clicking the circle next to their names.
72+
1. Select one or more users by selecting the circle next to their names.
73+
74+
1. Select **Approve** or **Deny** on the bar.
75+
76+
If you're unsure if a user should continue to have access, you can select **Don't know**. The user gets to keep their access, and your choice is recorded in the audit logs. Keep in mind that any information you provide will be available to other reviewers. They can read your comments and take them into account when they review the request.
7377

74-
1. Select **Approve** or **Deny** on the bar above.
75-
- If you are unsure if a user should continue to have access or not, you can click **Don't know**. The user gets to keep their access and your choice is recorded in the audit logs. It is important that you keep in mind that any information you provide will be available to other reviewers. They can read your comments and take them into account when they review the request.
78+
![Screenshot of open access review listing the users who need review.](./media/perform-access-review/user-list-preview.png)
7679

77-
![Open access review listing the users who need review](./media/perform-access-review/user-list-preview.png)
80+
1. The administrator of the access review might require you to supply a reason for your decision in the **Reason** box, even when a reason is not required. You can still provide a reason for your decision. The information that you include will be available to other approvers for review.
7881

79-
1. The administrator of the access review may require that you supply a reason in the **Reason** box for your decision. Even when a reason is not required. You can still provide a reason for your decision and the information that you include will be available to other approvers for review.
82+
1. Select **Submit**.
8083

81-
1. Click **Submit**.
82-
- You can change your response at any time until the access review has ended. If you want to change your response, select the row and update the response. For example, you can approve a previously denied user or deny a previously approved user.
84+
You can change your response at any time until the access review has ended. If you want to change your response, select the row and update the response. For example, you can approve a previously denied user or deny a previously approved user.
8385

8486
> [!IMPORTANT]
85-
> - If a user is denied access, they aren't removed immediately. They are removed when the review period has ended or when an administrator stops the review.
86-
> - If there are multiple reviewers, the last submitted response is recorded. Consider an example where an administrator designates two reviewersAlice and Bob. Alice opens the access review first and approves a user's access request. Before the review period ends, Bob opens the access review and denies access on the same request previously approved by Alice. The last decision denying the access is the response that gets recorded.
87+
> - If a user is denied access, they aren't removed immediately. The user is removed when the review period has ended or when an administrator stops the review.
88+
> - If there are multiple reviewers, the last submitted response is recorded. Consider an example where an administrator designates two reviewers: Alice and Bob. Alice opens the access review first and approves a user's access request. Before the review period ends, Bob opens the access review and denies access on the same request previously approved by Alice. The last decision denying the access is the response that gets recorded.
8789
8890
### Review access based on recommendations
8991

90-
To make access reviews easier and faster for you, we also provide recommendations that you can accept with a single click. There are two ways recommendations are generated for the reviewer. One method the system uses to create recommendations is by the user's sign-in activity. If a user has been inactive for 30 days or more, the reviewer will be recommended to deny access. The other method is based on the access the user's peers have. If the user doesn't have the same access as their peers, the reviewer will be recommended to deny that user access.
92+
To make access reviews easier and faster for you, we also provide recommendations that you can accept with a single selection. There are two ways that the system generates recommendations for the reviewer. One method is by the user's sign-in activity. If a user has been inactive for 30 days or more, the system will recommend that the reviewer deny access.
9193

92-
If you have **No sign-in within 30 days** or **Peer outlier** enabled, follow the steps below to accept recommendations:
94+
The other method is based on the access that the user's peers have. If the user doesn't have the same access as their peers, the system will recommend that the reviewer deny that user access.
9395

94-
1. Select one or more users and then Click **Accept recommendations**.
96+
If you have **No sign-in within 30 days** or **Peer outlier** enabled, follow these steps to accept recommendations:
9597

96-
![Open access review listing showing the Accept recommendations button](./media/perform-access-review/accept-recommendations-preview.png)
98+
1. Select one or more users, and then select **Accept recommendations**.
9799

98-
1. Or to accept recommendations for all unreviewed users, make sure that no users are selected and click on the **Accept recommendations** button on the top bar.
100+
![Screenshot of open access review listing that shows the Accept recommendations button.](./media/perform-access-review/accept-recommendations-preview.png)
99101

100-
1. Click **Submit** to accept the recommendations.
102+
Or to accept recommendations for all unreviewed users, make sure that no users are selected and then select the **Accept recommendations** button on the top bar.
101103

104+
1. Select **Submit** to accept the recommendations.
102105

103106
> [!NOTE]
104-
> When you accept recommendations previous decisions will not be changed.
107+
> When you accept recommendations, previous decisions won't be changed.
105108
106109
### Review access for one or more users in a multi-stage access review (preview)
107110

108-
If multi-stage access reviews have been enabled by the administrator, there will be 2 or 3 total stages of review. Each stage of review will have a specified reviewer.
111+
If the administrator has enabled multi-stage access reviews, there will be two or three total stages of review. Each stage of review will have a specified reviewer.
109112

110-
You will review access either manually or accept the recommendations based on sign-in activity for the stage you are assigned as the reviewer.
113+
You will either review access manually or accept the recommendations based on sign-in activity for the stage you're assigned as the reviewer.
111114

112-
If you are the 2nd stage or 3rd stage reviewer, you will also see the decisions made by the reviewers in the prior stage(s) if the administrator enabled this setting when creating the access review. The decision made by a 2nd or 3rd stage reviewer will overwrite the previous stage. So, the decision the 2nd stage reviewer makes will overwrite the first stage, and the 3rd stage reviewer's decision will overwrite the second stage.
115+
If you're the second-stage or third-stage reviewer, you'll also see the decisions made by the reviewers in the prior stages, if the administrator enabled this setting when creating the access review. The decision made by a second-stage or third-stage reviewer will overwrite the previous stage. So, the decision that the second-stage reviewer makes will overwrite the first stage. And the third-stage reviewer's decision will overwrite the second stage.
113116

114-
![Select user to show the multi-stage access review results](./media/perform-access-review/multi-stage-access-review.png)
117+
![Screenshot showing selection of a user to show the multi-stage access review results.](./media/perform-access-review/multi-stage-access-review.png)
115118

116119
Approve or deny access as outlined in [Review access for one or more users](#review-access-for-one-or-more-users).
117120

118121
> [!NOTE]
119-
> The next stage of the review won't become active until the duration specified during the access review setup has passed. If the administrator believes a stage is done but the review duration for this stage has not expired yet, they can use the **Stop current stage** button in the overview of the access review in the Azure AD portal. This will close the active stage and start the next stage.
122+
> The next stage of the review won't become active until the duration specified during the access review setup has passed. If the administrator believes a stage is done but the review duration for this stage has not expired yet, they can use the **Stop current stage** button in the overview of the access review in the Azure AD portal. This action will close the active stage and start the next stage.
120123
121-
### Review access for B2B direct connect users in Teams Shared Channels and Microsoft 365 groups (preview)
124+
### Review access for B2B direct connect users in Teams shared channels and Microsoft 365 groups (preview)
122125

123126
To review access of B2B direct connect users, use the following instructions:
124127

125-
1. As the reviewer, you should receive an email that requests you to review access for the team or group. Click the link in the email, or navigate directly to https://myaccess.microsoft.com/.
128+
1. As the reviewer, you should receive an email that requests you to review access for the team or group. Select the link in the email, or go directly to https://myaccess.microsoft.com/.
126129

127-
1. Follow the instructions in [Review access for one or more users](#review-access-for-one-or-more-users) to make decisions to approve or deny the users access to the Teams.
130+
1. Follow the instructions in [Review access for one or more users](#review-access-for-one-or-more-users) to make decisions to approve or deny the users access to the teams.
128131

129132
> [!NOTE]
130-
> Unlike internal users and B2B Collaboration users, B2B direct connect users and Teams **don't** have recommendations based on last sign-in activity to make decisions when you perform the review.
133+
> Unlike internal users and B2B collaboration users, B2B direct connect users and teams _don't_ have recommendations based on last sign-in activity to make decisions when you perform the review.
131134
132-
If a Team you review has shared channels, all B2B direct connect users and teams that access those shared channels are part of the review. This includes B2B collaboration users and internal users. When a B2B direct connect user or team is denied access in an access review, the user will lose access to every shared channel in the Team. To learn more about B2B direct connect users, read [B2B direct connect](../external-identities/b2b-direct-connect-overview.md).
135+
If a team you review has shared channels, all B2B direct connect users and teams that access those shared channels are part of the review. This includes B2B collaboration users and internal users. When a B2B direct connect user or team is denied access in an access review, the user will lose access to every shared channel in the team. To learn more about B2B direct connect users, read [B2B direct connect](../external-identities/b2b-direct-connect-overview.md).
133136

134-
## If no action is taken on access review
135-
When the access review is setup, the administrator has the option to use advanced settings to determine what will happen in the event a reviewer doesn't respond to an access review request.
137+
## Set up what will happen if no action is taken on access review
138+
When the access review is set up, the administrator has the option to use advanced settings to determine what will happen if a reviewer doesn't respond to an access review request.
136139

137-
The administrator can set up the review so that if reviewers do not respond at the end of the review period, all unreviewed users can have an automatic decision made on their access. This includes the loss of access to the group or application under review.
140+
The administrator can set up the review so that if reviewers don't respond at the end of the review period, all unreviewed users can have an automatic decision made on their access. This includes the loss of access to the group or application under review.
138141

139142
## Next steps
140143

0 commit comments

Comments
 (0)