Identity Governance and Privileged Access
Identity Governance and Privileged Access
Giving someone access is only part of identity management.
Organizations also need to answer questions such as:
Does this person still need access?
Should this administrator have powerful privileges permanently?
What happens when an employee changes roles or leaves?
How should temporary or external access be controlled?
Microsoft Entra identity governance capabilities help organizations manage access throughout its lifecycle, while privileged-access capabilities help reduce the risks associated with powerful administrative permissions.
What You’ll Learn
By the end of this lesson, you should be able to:
- Explain the purpose of identity governance
- Understand entitlement management at a foundational level
- Explain the purpose of access reviews
- Understand Privileged Identity Management
- Distinguish eligible and active privileged assignments
- Recognize the importance of time-limited privileged access
- Apply least privilege and lifecycle principles to access decisions
What Is Identity Governance?
Identity governance helps organizations manage identities and access throughout their lifecycle.
Creating an account and granting access may be straightforward.
The more difficult question is:
Should that person still have the same access six months later?
Employees change roles. Contractors finish projects. External collaborators leave. Administrative responsibilities change.
Without governance, access can accumulate over time.
Identity governance helps organizations manage this problem by supporting processes for requesting, assigning, reviewing, and removing access.
The Access Lifecycle
Remember the lifecycle introduced earlier:
Joiner → Mover → Leaver
Joiner
A person joins the organization and receives appropriate access.
Mover
The person changes roles or responsibilities.
Access should be reassessed so that new permissions can be provided while unnecessary old permissions are removed.
Leaver
The person leaves the organization.
Organizational access should be removed according to established processes.
Governance helps organizations make access lifecycle management more systematic.
Entitlement Management
Entitlement management helps organizations manage access to groups, applications, and other supported resources.
One important concept within entitlement management is an access package.
An access package can bundle resources that users need for a particular purpose.
For example, suppose Contoso regularly brings external consultants into a project.
Those consultants might need:
- Membership in a project group
- Access to a collaboration environment
- Access to a specific enterprise application
Instead of handling every resource independently each time, the organization can design an access package around the business requirement.
Access Packages
An access package represents a collection of resources and associated access that can be governed together.
Organizations can define policies controlling aspects such as:
- Who can request access
- Who approves requests
- How long access lasts
- Whether access requires review
- What happens when access expires
The important concept is:
Access packages help turn access into a governed lifecycle rather than a collection of unrelated manual assignments.
This can be particularly useful for projects, external collaboration, and other scenarios where access should not necessarily remain permanent.
Access Reviews
Even correctly granted access can become unnecessary later.
Access reviews help organizations periodically evaluate whether users should continue to have particular access.
For example, Contoso might review membership in a sensitive finance group every few months.
Reviewers can evaluate whether each person still requires membership.
This addresses a common security problem:
Access that was once legitimate may no longer be necessary.
Without periodic review, unnecessary access can remain unnoticed.
Practical Access Review Scenario
Suppose 40 employees have access to a sensitive application.
Over the next year:
- Several employees transfer departments
- Two leave the organization
- Some no longer perform work requiring the application
If nobody reviews the access, old permissions may remain.
An access review provides a structured opportunity to ask:
“Does this identity still require this access?”
That is a core identity-governance question.
Privileged Access
Some identities have significantly more power than ordinary users.
Administrative roles may allow users to change configurations, manage identities, modify security settings, or perform other sensitive operations.
Permanent administrative access increases exposure.
If a permanently privileged account is compromised, the attacker may immediately gain access to powerful capabilities.
A more controlled approach is to limit privileged access according to actual need.
Privileged Identity Management
Microsoft Entra Privileged Identity Management (PIM) helps organizations manage, control, and monitor access to important privileged roles and resources.
Rather than giving every administrator permanent active privileges, organizations can use PIM capabilities to provide more controlled privileged access.
Depending on configuration, privileged access processes can include controls such as:
- Time-limited activation
- Approval
- Multifactor authentication requirements
- Justification
- Notifications
- Access reviews
The goal is to reduce unnecessary standing privilege.
Eligible vs. Active Assignments
A useful PIM distinction is between eligible and active assignments.
Eligible Assignment
A user is permitted to activate a role when needed, subject to configured requirements.
The privilege does not necessarily remain continuously active.
Active Assignment
The user currently has the role active for the applicable assignment period.
A simple way to remember the difference:
Eligible = can activate the role when required
Active = currently has the role privileges
This distinction supports a more controlled approach to administrative access.
Just-In-Time Privileged Access
A related security concept is just-in-time access.
Instead of keeping powerful privileges permanently active, an administrator activates the required role when the task needs to be performed.
After the allowed period ends, the elevated access is no longer active.
Conceptually:
Normal access → Privilege required → Activate → Perform task → Privilege expires
This can reduce the amount of time highly privileged access remains available.
Practical PIM Scenario
Suppose Alex works on Contoso’s identity administration team.
Alex occasionally needs a highly privileged role to perform specific administrative work.
Giving Alex permanent active access means the privilege remains available even when it is not being used.
Instead, Contoso makes Alex eligible for the appropriate role.
When the privilege is required, Alex follows the configured activation process.
The organization might require additional verification, justification, approval, or other controls before activation.
After the activation period ends, the role is no longer active.
This better aligns administrative privilege with actual need.
Least Privilege and Zero Trust
Several concepts you’ve encountered throughout this course come together here.
Least privilege means identities should receive only the access required to perform their tasks.
A broader Zero Trust approach emphasizes explicitly verifying access rather than assuming trust based simply on location or previous access.
Identity governance and privileged-access management support these principles by helping organizations:
- Control who receives access
- Limit unnecessary privilege
- Review existing access
- Remove access that is no longer required
- Provide elevated access when necessary rather than automatically making it permanent
Governance vs. Privileged Access
These concepts are related but solve different problems.
Identity governance focuses broadly on managing access throughout its lifecycle.
Examples include:
- Access packages
- Entitlement management
- Access reviews
Privileged access management focuses particularly on controlling powerful administrative access.
A major Microsoft Entra capability in this area is:
Privileged Identity Management (PIM)
When reading a scenario, identify which problem needs to be solved.
SC-300 Exam Focus
Certain scenario clues can point toward particular governance capabilities.
If the requirement says:
“Users need a governed bundle of resources for a project.”
Think about entitlement management and access packages.
If it says:
“Managers must periodically confirm whether users still need access.”
Think access reviews.
If it says:
“Administrators should activate a privileged role only when needed.”
Think PIM and eligible role assignments.
If it says:
“Reduce permanent privileged access.”
Think about just-in-time privileged access and least privilege.
Focus on the problem being solved rather than simply memorizing product names.
Quick Review
Before completing this lesson, make sure you understand:
- Identity governance manages access throughout its lifecycle.
- Joiner, mover, and leaver processes help keep access aligned with business needs.
- Entitlement management can help govern access to resources.
- Access packages can bundle resources and policies around a business requirement.
- Access reviews help determine whether existing access is still necessary.
- Privileged accounts create greater security exposure.
- PIM helps control and monitor privileged access.
- Eligible assignments allow users to activate privileges when required.
- Active assignments provide currently active role privileges.
- Time-limited privileged access can reduce standing privilege.
- Least privilege applies throughout identity governance and privileged access management.
Continue to Lesson 8
You’ve now covered the foundational identity concepts in this course—from Microsoft Entra ID and authentication to Conditional Access, workload identities, governance, and privileged access.
In the final lesson, we’ll bring these concepts together, review the learning path, and show you how to continue from foundational knowledge into full SC-300 exam preparation.
Next: SC-300 Review and Next Steps →