Skip to content

Commit dfbf64b

Browse files
authored
Merge pull request #109409 from barclayn/access-package-warning
adding a warning about the inability to assign the member role to dyn…
2 parents d5eb2d4 + be34139 commit dfbf64b

File tree

2 files changed

+29
-25
lines changed

2 files changed

+29
-25
lines changed

articles/active-directory/governance/entitlement-management-access-package-first.md

Lines changed: 29 additions & 25 deletions
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@ ms.tgt_pltfrm: na
1212
ms.devlang: na
1313
ms.topic: tutorial
1414
ms.subservice: compliance
15-
ms.date: 10/22/2019
15+
ms.date: 03/30/2020
1616
ms.author: ajburnle
1717
ms.reviewer: markwahl-msft
1818
ms.collection: M365-identity-device-management
@@ -82,79 +82,83 @@ An *access package* is a bundle of resources that a team or project needs and is
8282

8383
1. In the Azure portal, in the left navigation, click **Azure Active Directory**.
8484

85-
1. In the left menu, click **Identity Governance**
85+
2. In the left menu, click **Identity Governance**
8686

87-
1. In the left menu, click **Access packages**. If you see **Access denied**, ensure that an Azure AD Premium P2 license is present in your directory.
87+
3. In the left menu, click **Access packages**. If you see **Access denied**, ensure that an Azure AD Premium P2 license is present in your directory.
8888

89-
1. Click **New access package**.
89+
4. Click **New access package**.
9090

9191
![Entitlement management in the Azure portal](./media/entitlement-management-shared/access-packages-list.png)
9292

93-
1. On the **Basics** tab, type the name **Marketing Campaign** access package and description **Access to resources for the campaign**.
93+
5. On the **Basics** tab, type the name **Marketing Campaign** access package and description **Access to resources for the campaign**.
9494

95-
1. Leave the **Catalog** drop-down list set to **General**.
95+
6. Leave the **Catalog** drop-down list set to **General**.
9696

9797
![New access package - Basics tab](./media/entitlement-management-access-package-first/basics.png)
9898

99-
1. Click **Next** to open the **Resource roles** tab.
99+
7. Click **Next** to open the **Resource roles** tab.
100100

101101
On this tab, you select the resources and the resource role to include in the access package.
102102

103-
1. Click **Groups and Teams**.
103+
8. Click **Groups and Teams**.
104104

105-
1. In the Select groups pane, find and select the **Marketing resources** group you created earlier.
105+
9. In the Select groups pane, find and select the **Marketing resources** group you created earlier.
106106

107107
By default, you see groups inside and outside the **General** catalog. When you select a group outside of the **General** catalog, it will be added to the **General** catalog.
108108

109109
![New access package - Resource roles tab](./media/entitlement-management-access-package-first/resource-roles-select-groups.png)
110110

111-
1. Click **Select** to add the group to the list.
111+
10. Click **Select** to add the group to the list.
112112

113-
1. In the **Role** drop-down list, select **Member**.
113+
11. In the **Role** drop-down list, select **Member**.
114114

115115
![New access package - Resource roles tab](./media/entitlement-management-access-package-first/resource-roles.png)
116116

117-
1. Click **Next** to open the **Requests** tab.
117+
>[!NOTE]
118+
> When using [dynamic groups](../users-groups-roles/groups-create-rule.md) you will not see any other roles available besides owner. This is by design.
119+
> ![Scenario overview](./media/entitlement-management-access-package-first/dynamic-group-warning.png)
120+
121+
12. Click **Next** to open the **Requests** tab.
118122

119123
On this tab, you create a request policy. A *policy* defines the rules or guardrails to access an access package. You create a policy that allows a specific user in the resource directory to request this access package.
120124

121-
1. In the **Users who can request access** section, click **For users in your directory** and then click **Specific users and groups**.
125+
13. In the **Users who can request access** section, click **For users in your directory** and then click **Specific users and groups**.
122126

123127
![New access package - Requests tab](./media/entitlement-management-access-package-first/requests.png)
124128

125-
1. Click **Add users and groups**.
129+
14. Click **Add users and groups**.
126130

127-
1. In the Select users and groups pane, select the **Requestor1** user you created earlier.
131+
15. In the Select users and groups pane, select the **Requestor1** user you created earlier.
128132

129133
![New access package - Requests tab - Select users and groups](./media/entitlement-management-access-package-first/requests-select-users-groups.png)
130134

131-
1. Click **Select**.
135+
16. Click **Select**.
132136

133-
1. Scroll down to the **Approval** and **Enable requests** sections.
137+
17. Scroll down to the **Approval** and **Enable requests** sections.
134138

135-
1. Leave **Require approval** set to **No**.
139+
18. Leave **Require approval** set to **No**.
136140

137-
1. For **Enable requests**, click **Yes** to enable this access package to be requested as soon as it is created.
141+
19. For **Enable requests**, click **Yes** to enable this access package to be requested as soon as it is created.
138142

139143
![New access package - Requests tab - Approval and Enable requests](./media/entitlement-management-access-package-first/requests-approval-enable.png)
140144

141-
1. Click **Next** to open the **Lifecycle** tab.
145+
20. Click **Next** to open the **Lifecycle** tab.
142146

143-
1. In the **Expiration** section, set **Access package assignments expire** to **Number of days**.
147+
21. In the **Expiration** section, set **Access package assignments expire** to **Number of days**.
144148

145-
1. Set **Assignments expire after** to **30** days.
149+
22. Set **Assignments expire after** to **30** days.
146150

147151
![New access package - Lifecycle tab](./media/entitlement-management-access-package-first/lifecycle.png)
148152

149-
1. Click **Next** to open the **Review + Create** tab.
153+
23. Click **Next** to open the **Review + Create** tab.
150154

151155
![New access package - Review + Create tab](./media/entitlement-management-access-package-first/review-create.png)
152156

153157
After a few moments, you should see a notification that the access package was successfully created.
154158

155-
1. In left menu of the Marketing Campaign access package, click **Overview**.
159+
24. In left menu of the Marketing Campaign access package, click **Overview**.
156160

157-
1. Copy the **My Access portal link**.
161+
25. Copy the **My Access portal link**.
158162

159163
You'll use this link for the next step.
160164

18.9 KB
Loading

0 commit comments

Comments
 (0)