M365Clarity · Entra Governance

Microsoft Entra ID Governance — PIM, access reviews, and lifecycle workflows explained

M365Clarity · 24 June 2026

← All articles

What is Entra ID Governance?

Microsoft Entra ID Governance is a set of identity lifecycle and access governance features built on top of Microsoft Entra ID (formerly Azure Active Directory). It addresses one of the most persistent problems in enterprise IT — the accumulation of excessive, stale, and unreviewed access over time.

It is included in Microsoft Entra ID P2, which comes with Microsoft 365 E5 and is available as an add-on for E3. Despite being licensed by a significant proportion of Microsoft 365 customers, most of the governance features ship unconfigured and are never activated.

Privileged Identity Management (PIM)

PIM is the most critical Entra Governance feature for most organisations. It changes how privileged roles — Global Administrator, Privileged Role Administrator, Security Administrator, and others — are assigned. Instead of permanent role assignments that are active 24 hours a day, PIM makes roles eligible. Users activate their role when they need it, for a defined time window, and the access expires automatically.

The security benefit is significant. A permanently assigned Global Administrator account that is compromised gives an attacker immediate, unlimited access to your tenant. An eligible Global Administrator account that is compromised gives an attacker nothing until they can also complete PIM activation — which can require MFA, justification text, manager approval, and triggers immediate alerting.

Most common finding: Tenants with E5 licences that include PIM but have never configured it. All admin accounts remain permanently assigned. This is the highest-risk identity configuration possible.

Getting started with PIM involves three steps: navigate to Microsoft Entra admin centre → Identity Governance → Privileged Identity Management, convert Global Administrator assignments from permanent to eligible, and configure activation settings including MFA requirement and maximum duration.

Access reviews

Access reviews allow you to periodically certify that users should still have access to the groups, applications, and roles they have been assigned. Without access reviews, access accumulates — users who change roles or leave the organisation may retain access to systems they no longer need, indefinitely.

Microsoft recommends quarterly reviews for privileged roles and annual reviews for application access and group membership. Reviews can be self-attested (users confirm their own access) or reviewed by managers or resource owners.

Access reviews are configured in Microsoft Entra admin centre → Identity Governance → Access reviews. You define the scope (which groups, apps, or roles), the reviewers (managers, resource owners, or specific individuals), the frequency, and what happens when reviewers do not respond — auto-approve or auto-deny on no response.

Lifecycle workflows (Joiner, Mover, Leaver)

Lifecycle workflows automate identity management at the three key moments in an employee's tenure — when they join, when they change role, and when they leave. Without automation, these transitions depend entirely on manual processes that are frequently delayed, inconsistent, or incomplete.

The leaver workflow is the most impactful: Former employees with active accounts are one of the most common sources of unauthorised access. Automating account disablement on last day eliminates this risk entirely.

Entitlement management

Entitlement management lets you package access — a combination of groups, applications, and SharePoint sites — into access packages that users can request through a self-service portal. Requests go through an approval workflow and access is time-limited, expiring automatically unless renewed.

For organisations that manage multiple departments or partner organisations, entitlement management replaces ad-hoc access requests (email your manager, wait for IT to action it) with a structured, auditable self-service process.

What M365Clarity checks in the Entra Governance tab

The Entra Governance tab in M365Clarity runs 14 checks covering PIM configuration and eligible role assignments, access review status and cadence, lifecycle workflow coverage for joiner and leaver scenarios, dynamic group configuration, entitlement management packages, terms of use policies, enterprise app OAuth grant auditing, and application proxy configuration. Every finding includes plain-English explanation and remediation guidance.

Licence note: Entra ID Governance features require Microsoft Entra ID P2, included in Microsoft 365 E5 and Microsoft Entra ID Governance add-on. E3 tenants without the add-on will see most of these checks as unavailable.

See your Entra Governance posture in 30 seconds

M365Clarity scans 14 Entra Governance checks and shows you exactly which identity lifecycle and access governance features are configured in your tenant.

Free scan — no agents required →

Related articles