Set up Entra ID access reviews for groups, apps, and PIM roles
For developers and tenant admins who need Entra ID access reviews working without trial-and-error. This walks through creating repeatable reviews for group membership, application assignments, and privileged roles, plus the exact checks to confirm reviewers, schedules, and auto-remediation are actually in place.
TL;DR — You can set up Entra ID access reviews from the portal in three places: Identity Governance for groups/apps, and Privileged Identity Management for privileged roles. The most common failure is missing licensing or role permissions; if the "Access reviews" option is missing or creation fails, fix your admin role and verify Entra ID Governance / P2 licensing first. Reading time: ~5 min
Goal
When you finish, your tenant will have active Entra ID access reviews for at least one group, one enterprise application, and one privileged role, each with reviewers, recurrence, decision settings, and auto-apply behavior configured so access is removed or retained based on review outcomes.
Prerequisites
- Entra admin access with one of these roles:
Global Administrator,Identity Governance Administrator, or for role reviewsPrivileged Role Administrator— check in Entra admin center underIdentity → Roles & admins - Licensing that includes access reviews functionality for the users being reviewed; in practice this is typically Entra ID Governance / Entra ID P2-capable licensing in your tenant
- At least one target of each type already exists:
- a security or Microsoft 365 group with members
- an enterprise application with users or groups assigned
- a privileged role assignment managed in PIM
- Browser access to the Microsoft Entra admin center
- Optional for verification: Microsoft Graph Explorer or a shell with
curland a bearer token for Graph API calls - The exact reviewer identities you want to use:
Group owners,Selected users or groups,Members (self-review), orManagers - The review policy values you intend to set: recurrence, duration in days, on-no-response behavior, and whether to auto-apply results
Steps
Step 1: Confirm you can see the access review entry points
Use these exact menu paths in the Entra admin center:
- For groups and apps:
Identity Governance → Access reviews - For privileged roles:
Identity Governance → Privileged Identity Management → Microsoft Entra roles → Access reviews
What you should see when this succeeds: a + New access review or Create access review action is visible on the page.
Step 2: Create an access review for a group
In the Entra admin center, go to:
Identity Governance → Access reviews → + New access review
Set these literal values on the form:
| Field | Value |
|---|---|
| Select what to review | Teams + Groups |
| Review scope | Select Teams + Groups |
| Group | <your target group name> |
| Scope | Guest users only or All users |
| Reviewers | Group Owners |
| Upon completion settings | Auto apply results to resource = Yes |
| If reviewers don't respond | Remove access |
| Action to apply on denied guest users | Block user from signing in for 30 days, then remove user from the tenant if available; otherwise leave default |
| Recurrence | Monthly |
| Duration | 7 days |
| Start date | Today |
| End | Never |
| Name | Monthly review - <group name> |
Click Start or Create.
What you should see when this succeeds: the new review appears in the list with Status showing Starting or Active within a minute.
Step 3: Create an access review for an enterprise application
In the Entra admin center, go to:
Identity Governance → Access reviews → + New access review
Set these literal values:
| Field | Value |
|---|---|
| Select what to review | Applications |
| Review scope | Select applications |
| Application | <your enterprise app name> |
| Scope | Users assigned to application or Guest users assigned to application |
| Reviewers | Selected users or groups |
| Selected reviewers | <reviewer user or reviewer group> |
| Upon completion settings | Auto apply results to resource = Yes |
| If reviewers don't respond | No change for low-risk apps, or Remove access for strict environments |
| Recurrence | Quarterly |
| Duration | 14 days |
| Start date | Today |
| End | Never |
| Name | Quarterly app assignment review - <app name> |
Click Start or Create.
What you should see when this succeeds: the review opens to an overview page showing the application as the reviewed resource and the reviewer set you selected.
Step 4: Create an access review for privileged roles in PIM
Go to:
Identity Governance → Privileged Identity Management → Microsoft Entra roles → Access reviews → + New
Set these exact values:
| Field | Value |
|---|---|
| Scope | Select roles |
| Roles | <choose one role, for example User Administrator> |
| Assignment type | Eligible assignments first; repeat later for Active assignments if needed |
| Reviewers | Selected users or groups or Members (self) |
| Selected reviewers | <security reviewer group> |
| Recurrence | Monthly |
| Duration | 7 days |
| Start date | Today |
| End | Never |
| If reviewers don't respond | Remove access |
| Auto apply results | Enabled |
| Name | Monthly PIM role review - User Administrator eligible |
Click Create.
What you should see when this succeeds: the review is listed under PIM access reviews with the role name and assignment type.
Step 5: Turn on notification and recommendation options if your form exposes them
On each review, open the review and set these values if available:
Review settings → Mail notifications = Enabled
Review settings → Reminders = Enabled
Review settings → Justification required = Enabled
Review settings → Recommendations = Enabled
Save the review.
What you should see when this succeeds: the settings page shows the toggles enabled and the review summary reflects the updated policy.
Step 6: Verify the review instances were generated
Open each review and use this menu path:
<Review name> → Instances
You should see a current instance with a start date matching today and an end date matching the duration you set.
What you should see when this succeeds: at least one instance exists per review, with In progress, Starting, or equivalent active state.
Verify it works
Use the portal first:
Identity Governance → Access reviewsshould list your group and application reviews asActiveorStarting.Identity Governance → Privileged Identity Management → Microsoft Entra roles → Access reviewsshould list your role review.- Open each review and confirm:
- the reviewed resource is correct
- recurrence is correct
Auto apply resultsis enabled where you intended itIf reviewers don't respondmatches your policy
If you verify with Microsoft Graph, query definitions and instances. Use Graph Explorer or your own token with scope that can read identity governance objects.
curl -sS -H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
"https://graph.microsoft.com/v1.0/identityGovernance/accessReviews/definitions?$top=20" | jq '.value[] | {id,displayName,status,createdDateTime}'
Expected output shape:
{
"id": "3f1c2d4e-...",
"displayName": "Monthly review - Engineering-Prod-Admins",
"status": "InProgress",
"createdDateTime": "2026-10-01T09:12:44Z"
}
For PIM-backed role reviews, if your tenant exposes them through the same access review definitions endpoint, they appear there too; otherwise verify in the PIM UI. If your token is wrong, you will typically see:
{
"error": {
"code": "Authorization_RequestDenied",
"message": "Insufficient privileges to complete the operation.",
"innerError": {
"date": "2026-10-01T09:15:02Z",
"request-id": "...",
"client-request-id": "..."
}
}
}
Common pitfalls
Missing license or wrong admin role
Mistake: trying to create reviews with a role that cannot manage Identity Governance, or in a tenant without the required licensing.
Symptom: the Access reviews menu is missing, or creation fails with permission/licensing banners.
Fix: assign Identity Governance Administrator or Global Administrator, and verify the tenant has the required Entra ID Governance / P2-capable licensing for the reviewed population.
Reviewing a group or app with no assignments
Mistake: creating a review before the group has members or the enterprise app has assigned users/groups.
Symptom: the review creates successfully but shows 0 users in scope.
Fix: add at least one member to the group or one assignment to the enterprise app, then create a new instance or wait for the next recurrence.
Using the wrong reviewer type for the resource
Mistake: selecting Managers or Group Owners when those relationships are incomplete.
Symptom: no reviewer is resolved, or review emails never go out.
Fix: for predictable behavior, use Selected users or groups and point it at a dedicated reviewer group.
Auto-apply disabled when you expected removals
Mistake: setting If reviewers don't respond = Remove access but leaving Auto apply results off.
Symptom: decisions are recorded, but memberships or assignments do not change after the review closes.
Fix: edit the review and set Auto apply results to resource to Yes for groups/apps or Auto apply results to Enabled for PIM role reviews.
Reviewing only eligible PIM assignments and forgetting active ones
Mistake: creating a role review for Eligible assignments only.
Symptom: permanently active privileged assignments remain untouched.
Fix: create a second review with the same role set and Assignment type = Active assignments.
Expecting immediate email delivery as proof of success
Mistake: using email arrival as the only verification.
Symptom: you assume the review failed because no mail appears within a few minutes.
Fix: verify in Instances and the review overview first; mail flow can lag, but an active instance in the portal is the authoritative signal.
This article was written by an AI system and published pending human review. Verify anything you intend to act on.
Have a project in mind?
Get an instant AI price estimate for it, or talk directly to our team.
One email a month on what we learn building with AI