Identity and security

Identity Governance

Microsoft Entra ID Governance

Microsoft Entra ID Governance extends core identity management with the tooling needed to keep access aligned with actual, current business need, rather than letting it accumulate indefinitely as people change roles, projects end, and external collaborators come and go.

Why Identity Governance matters in a Microsoft estate

Identity Governance matters because identity, access, endpoint, and data controls shape how Microsoft environments are protected. Readers should understand the term and then be able to move into security assessment, conformity, or remediation guidance.

How Identity Governance shows up in practice

It addresses the specific problem that provisioning access is comparatively easy while removing it correctly, and on time, consistently is not. Entitlement management is its request-and-approval engine, letting administrators bundle related resources, group memberships, application roles, SharePoint sites, into access packages that users can request through a self-service catalogue, subject to configurable approval workflows and, critically, an expiration date. This means access granted for a defined project or a fixed-term contract does not silently persist as standing access once that need has ended. It is one of the most common and hardest-to-spot sources of unnecessary privilege in an estate that has been provisioning access manually and informally for years. Access reviews complement this by periodically requiring a designated reviewer, a manager, a resource owner, or the user themselves, to explicitly recertify that continued access is still needed, rather than assuming it is.

Reviews can be scheduled to run automatically on a recurring cycle against groups, applications, or privileged roles, with access automatically revoked from anyone who does not respond or is explicitly denied. This converts access certification from an annual manual spreadsheet exercise, if it happens at all, into a structured, auditable, and largely automated process. Lifecycle workflows automate the joiner-mover-leaver sequence directly, triggering predefined actions, account creation, licence and group assignment, welcome communications on joining, and account disablement, group removal, and access revocation on leaving, based on attributes already held in the HR source system.

This closes one of the most consequential gaps in identity management: the departed employee whose account remains active, sometimes for months, because deprovisioning depended on someone remembering to run a manual offboarding checklist. The connection to cost is direct and often underappreciated: every access package with no expiration, every access review that never actually runs, and every departed user whose licence assignment survives their departure represents ongoing, avoidable Microsoft 365 licence spend sitting on top of the security exposure of orphaned access. This is why identity governance and licence optimisation tend to be examined together rather than treated as separate initiatives, once an organisation actually audits who holds what and why. Entra ID Governance is licensed as Entra ID P2 or the dedicated Governance add-on, sitting above the baseline P1 tier that only covers Conditional Access and more limited access review functionality.

Related terms

Glossary