Description:
Access Reviews in Microsoft Entra ID Privileged Identity Management (PIM) ensure that external users (guests, partners, B2B users) who have privileged access are reviewed regularly. External identities often have elevated risk because they are outside the organization’s direct control. Enforcing recurring access reviews ensures that only users who still require privileged access retain it, reducing unnecessary exposure and preventing stale or unused accounts from maintaining administrative permissions.
Rationale:
External users with privileged access pose a significant security risk if their access is not monitored and validated regularly. Without access reviews, inactive or unauthorized external users may retain administrative roles indefinitely, creating opportunities for misuse, insider threats, or compromised accounts. Implementing periodic access reviews helps maintain least-privilege principles, supports compliance requirements, and strengthens identity governance.
Impact:
Ensures external users’ privileged access is continuously validated
Reduces excess permissions and privilege creep
Strengthens identity governance and compliance posture
Minimizes risks from compromised or inactive external accounts
Default Value:
By default, no Access Review is configured for external users in PIM.
Pre-Requisites:
Microsoft Entra ID P2 license (required for PIM access reviews)
Access to the Microsoft Entra admin center
Privileged Identity Management enabled
Required permissions: Identity Governance Administrator, Privileged Role Administrator, or Global Administrator.
Test Plan:
Sign in to the Azure Portal.
In the portal, search for Microsoft Entra ID(Azure Active Directory).
Under Manage section, click Identity Governance
Under the Access Review section, click on Access Reviews
Review existing access reviews
Verify that an access review is configured for external users with privileged roles
If access reviews for external privileged users are not configured, follow the implementation steps
Implementation Steps:
Sign in to the Azure Portal
Search for Microsoft Entra ID
Under the Manage section, click Identity Governance
Under the Access Review section, click on Access Reviews
Select Create access review and configure the review to target external users with privileged roles
Set the review schedule and recurrence
Configure reviewers and access decision settings
Enable and save the access review configuration
Backout Plan:
Sign in to the Azure Portal at https://portal.azure.com
Open Microsoft Entra ID
Under the Manage section, select Privileged Identity Management
Select Access reviews
Select the access review configured for external privileged users
Disable or delete the access review
Save the changes
Reference:

