You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory/governance/entitlement-management-access-package-approval-policy.md
+28-28Lines changed: 28 additions & 28 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -3,7 +3,7 @@ title: Change approval settings for an access package in Azure AD entitlement ma
3
3
description: Learn how to change approval and requestor information settings for an access package in Azure Active Directory entitlement management.
4
4
services: active-directory
5
5
documentationCenter: ''
6
-
author: owinfreyatl
6
+
author: owinfreyATL
7
7
manager: karenhoran
8
8
editor:
9
9
ms.service: active-directory
@@ -32,7 +32,7 @@ In the Approval section, you specify whether an approval is required when users
32
32
33
33
- Only one of the selected approvers or fallback approvers needs to approve a request for single-stage approval.
34
34
- Only one of the selected approvers from each stage needs to approve a request for multi-stage approval for the request to progress to the next stage.
35
-
- If one of the selected approved in a stage denies a request before another approver in that stage approves it, or if no one approves, the request terminates and the user does not receive access.
35
+
- If one of the selected approved in a stage denies a request before another approver in that stage approves it, or if no one approves, the request terminates and the user doesn't receive access.
36
36
- The approver can be a specified user or member of a group, the requestor's Manager, Internal sponsor, or External sponsor depending on who the policy is governing access.
37
37
38
38
For a demonstration of how to add approvers to a request policy, watch the following video:
@@ -50,13 +50,13 @@ Follow these steps to specify the approval settings for requests for the access
50
50
51
51
**Prerequisite role:** Global administrator, Identity Governance administrator, User administrator, Catalog owner, or Access package manager
52
52
53
-
1. In the Azure portal, click**Azure Active Directory** and then click**Identity Governance**.
53
+
1. In the Azure portal, select**Azure Active Directory** and then select**Identity Governance**.
54
54
55
-
1. In the left menu, click**Access packages** and then open the access package.
55
+
1. In the left menu, select**Access packages** and then open the access package.
56
56
57
57
1. Either select a policy to edit or add a new policy to the access package
58
-
1.Click**Policies** and then **Add policy** if you want to create a new policy.
59
-
1.Click the policy you wish to edit and then click**edit**.
58
+
1.Select**Policies** and then **Add policy** if you want to create a new policy.
59
+
1.Select the policy you wish to edit and then select**edit**.
60
60
61
61
1. Go to the **Request** tab.
62
62
@@ -75,19 +75,19 @@ Use the following steps to add approvers after selecting how many stages you req
75
75
76
76
1. Add the **First Approver**:
77
77
78
-
If the policy is set to govern access for users in your directory, you can select **Manager as approver**. Or, add a specific user by clicking**Add approvers** after selecting Choose specific approvers from the dropdown menu.
78
+
If the policy is set to govern access for users in your directory, you can select **Manager as approver**. Or, add a specific user by selecting**Add approvers** after selecting **Choose specific approvers** from the dropdown menu.
79
79
80
80

81
81
82
82
If this policy is set to govern access for users not in your directory, you can select **External sponsor** or **Internal sponsor**. Or, add a specific user by clicking **Add approvers** or groups under Choose specific approvers.
83
83
84
84

85
85
86
-
1. If you selected **Manager** as the first approver, click**Add fallback** to select one or more users or groups in your directory to be a fallback approver. Fallback approvers receive the request if entitlement management can't find the manager for the user requesting access.
86
+
1. If you selected **Manager** as the first approver, select**Add fallback** to select one or more users or groups in your directory to be a fallback approver. Fallback approvers receive the request if entitlement management can't find the manager for the user requesting access.
87
87
88
88
The manager is found by entitlement management using the **Manager** attribute. The attribute is in the user's profile in Azure AD. For more information, see [Add or update a user's profile information using Azure Active Directory](../fundamentals/active-directory-users-profile-azure-portal.md).
89
89
90
-
1. If you selected **Choose specific approvers**, click**Add approvers** to select one or more users or groups in your directory to be approvers.
90
+
1. If you selected **Choose specific approvers**, select**Add approvers** to choose one or more users or groups in your directory to be approvers.
91
91
92
92
1. In the box under **Decision must be made in how many days?**, specify the number of days that an approver has to review a request for this access package.
93
93
@@ -99,11 +99,11 @@ Use the following steps to add approvers after selecting how many stages you req
99
99
100
100
### Multi-stage approval
101
101
102
-
If you selected a multi-stage approval, you'll need to add an approver for each additional stage.
102
+
If you selected a multi-stage approval, you'll need to add an approver for each extra stage.
103
103
104
104
1. Add the **Second Approver**:
105
105
106
-
If the users are in your directory, add a specific user as the second approver by clicking**Add approvers** under Choose specific approvers.
106
+
If the users are in your directory, add a specific user as the second approver by selecting**Add approvers** under Choose specific approvers.
107
107
108
108

109
109
@@ -115,7 +115,7 @@ If you selected a multi-stage approval, you'll need to add an approver for each
115
115
116
116
1. Set the Require approver justification toggle to **Yes** or **No**.
117
117
118
-
You also have the option to add an additional stage for a three-stage approval process. For example, you might want an employee’s manager to be the first stage approver for an access package. But, one of the resources in the access package contains confidential information. In this case, you could designate the resource owner as a second approver and a security reviewer as the third approver. That allows a security team to have oversight into the process and the ability to, for example, reject a request based on risk criteria not known to the resource owner.
118
+
You also have the option to add an extra stage for a three-stage approval process. For example, you might want an employee’s manager to be the first stage approver for an access package. But, one of the resources in the access package contains confidential information. In this case, you could designate the resource owner as a second approver and a security reviewer as the third approver. That allows a security team to have oversight into the process and the ability to, for example, reject a request based on risk criteria not known to the resource owner.
119
119
120
120
1. Add the **Third Approver**:
121
121
@@ -134,28 +134,28 @@ If you selected a multi-stage approval, you'll need to add an approver for each
134
134
135
135
You can specify alternate approvers, similar to specifying the primary approvers who can approve requests on each stage. Having alternate approvers will help ensure that the requests are approved or denied before they expire (timeout). You can list alternate approvers alongside the primary approver on each stage.
136
136
137
-
By specifying alternate approvers on a stage, in the event that the primary approvers were unable to approve or deny the request, the pending request gets forwarded to the alternate approvers, per the forwarding schedule you specified during policy setup. They receive an email to approve or deny the pending request.
137
+
By specifying alternate approvers on a stage, if the primary approvers were unable to approve or deny the request, the pending request gets forwarded to the alternate approvers, per the forwarding schedule you specified during policy setup. They receive an email to approve or deny the pending request.
138
138
139
139
After the request is forwarded to the alternate approvers, the primary approvers can still approve or deny the request. Alternate approvers use the same My Access site to approve or deny the pending request.
140
140
141
-
You can list people or groups of people to be approvers and alternate approvers. Please ensure that you list different sets of people to be the first, second, and alternate approvers.
141
+
You can list people or groups of people to be approvers and alternate approvers. Ensure that you list different sets of people to be the first, second, and alternate approvers.
142
142
For example, if you listed Alice and Bob as the first stage approver(s), list Carol and Dave as the alternate approvers. Use the following steps to add alternate approvers to an access package:
143
143
144
-
1. Under the approver on a stage, click**Show advanced request settings**.
144
+
1. Under the approver on a stage, select**Show advanced request settings**.
If you select Manager as approver for the First Approver, you will have an additional option, **Second level manager as alternate approver**, available to choose in the alternate approver field. If you select this option, you need to add a fallback approver to forward the request to in case the system can't find the second level manager.
154
+
If you select Manager as approver for the First Approver, you'll have an extra option, **Second level manager as alternate approver**, available to choose in the alternate approver field. If you select this option, you need to add a fallback approver to forward the request to in case the system can't find the second level manager.
155
155
156
156
1. In the **Forward to alternate approver(s) after how many days** box, put in the number of days the approvers have to approve or deny a request. If no approvers have approved or denied the request before the request duration, the request expires (timeout), and the user will have to submit another request for the access package.
157
157
158
-
Requests can only be forwarded to alternate approvers a day after the request duration reaches half-life, and the decision of the main approver(s) has to time-out after at least 4 days. If the request time-out is less or equal than 3, there is not enough time to forward the request to alternate approver(s). In this example, the duration of the request is 14 days. So, the request duration reaches half-life at day 7. So the request can't be forwarded earlier than day 8. Also, requests can't be forwarded on the last day of the request duration. So in the example, the latest the request can be forwarded is day 13.
158
+
Requests can only be forwarded to alternate approvers a day after the request duration reaches half-life, and the decision of the main approver(s) has to time-out after at least four days. If the request time-out is less or equal than three, there isn't enough time to forward the request to alternate approver(s). In this example, the duration of the request is 14 days. So, the request duration reaches half-life at day 7. So the request can't be forwarded earlier than day 8. Also, requests can't be forwarded on the last day of the request duration. So in the example, the latest the request can be forwarded is day 13.
159
159
160
160
## Enable requests
161
161
@@ -167,42 +167,42 @@ For example, if you listed Alice and Bob as the first stage approver(s), list Ca
## Collect additional requestor information for approval
173
173
174
-
In order to make sure users are getting access to the right access packages, you can require requestors to answer custom text field or multiple choice questions at the time of request. There is a limit of 20 questions per policy and a limit of 25 answers for multiple choice questions. The questions will then be shown to approvers to help them make a decision.
174
+
In order to make sure users are getting access to the right access packages, you can require requestors to answer custom text field or multiple choice questions at the time of request. There's a limit of 20 questions per policy and a limit of 25 answers for multiple choice questions. The questions will then be shown to approvers to help them make a decision.
175
175
176
-
1. Go to the **Requestor information** tab and click the **Questions** sub tab.
176
+
1. Go to the **Requestor information** tab and select the **Questions** sub tab.
177
177
178
178
1. Type in what you want to ask the requestor, also known as the display string, for the question in the **Question** box.
179
179
180
180

181
181
182
-
1. If the community of users who will need access to the access package don't all have a common preferred language, then you can improve the experience for users requesting access on myaccess.microsoft.com. To improve the experience, you can provide alternative display strings for different languages. For example, if a user's web browser is set to Spanish, and you have Spanish display strings configured, then those strings will be displayed to the requesting user. To configure localization for requests, click**add localization**.
183
-
1. Once in the **Add localizations for question** pane, select the **language code** for the language in which you are localizing the question.
182
+
1. If the community of users who will need access to the access package don't all have a common preferred language, then you can improve the experience for users requesting access on myaccess.microsoft.com. To improve the experience, you can provide alternative display strings for different languages. For example, if a user's web browser is set to Spanish, and you have Spanish display strings configured, then those strings will be displayed to the requesting user. To configure localization for requests, select**add localization**.
183
+
1. Once in the **Add localizations for question** pane, select the **language code** for the language in which you're localizing the question.
184
184
1. In the language you configured, type the question in the **Localized Text** box.
185
-
1. Once you have added all the localizations needed, click**Save**.
185
+
1. Once you've added all the localizations needed, select**Save**.
1. Select the **Answer format** in which you would like requestors to answer. Answer formats include: *short text*, *multiple choice*, and *long text*.
1. If selecting multiple choice, click on the **Edit and localize** button to configure the answer options.
193
+
1. If selecting multiple choice, select on the **Edit and localize** button to configure the answer options.
194
194
1. After selecting Edit and localize the **View/edit question** pane will open.
195
195
1. Type in the response options you wish to give the requestor when answering the question in the **Answer values** boxes.
196
196
1. Type in as many responses as you need.
197
197
1. If you would like to add your own localization for the multiple choice options, select the **Optional language code** for the language in which you want to localize a specific option.
198
198
1. In the language you configured, type the option in the Localized text box.
199
-
1. Once you have added all of the localizations needed for each multiple choice option, click**Save**.
199
+
1. Once you've added all of the localizations needed for each multiple choice option, select**Save**.
200
200
201
201

202
202
203
-
1. To require requestors to answer this question when requesting access to an access package, click the check box under **Required**.
203
+
1. To require requestors to answer this question when requesting access to an access package, select the check box under **Required**.
204
204
205
-
1. Fill out the remaining tabs (e.g., Lifecycle) based on your needs.
205
+
1. Fill out the remaining tabs (for example, Lifecycle) based on your needs.
206
206
207
207
After you have configured requestor information in your access package's policy, can view the requestor's responses to the questions. For guidance on seeing requestor information, see [View requestor's answers to questions](entitlement-management-request-approve.md#view-requestors-answers-to-questions).
0 commit comments