Access Reviews should let you review guest users access on the directory level. Using a dynamic group with all guest users in it, I should be able to have access reviews DELETE the user from the Azure Active Directory rather than just removing the user from a group.6 votes
Hi Sigurd, thanks so much for the feedback! If you could reach out to me I would love to chat more to understand your use case and have you participate in our private preview of the delete scenario.
Expand access reviews to support Azure Subscription and Resources for explicit assigned identity.10 votes
Thanks for the feedback, we have this work in planning.
Would be great having the opportunity to edit or add a message into the Email sent by Azure.
Eg. When someone has the role membership denied by a role owner, the user should get the email WITH the reason and not just the email saying that the has been removed.
Also would be great allowing the GA's to add a message or create the reminders by themselves AND schedule it.3 votes
Thanks, the team is reviewing this ask!
Would be great if Access Reviews could include the on-prem group Domain Admins, and the Cloud based group GLobal Admins. Right now this is not possible.5 votes
Thank you John for the feedback! My understanding is that you are referring to access reviews of privileged roles in the PIM experience.
In regards to reviewing on-prem group Domain Admins, historically, groups like that were blocked by AAD connecto for not sending them to AAD, so they are filtered out.
For cloud based group Global Admins, you can review global admins in the current PIM experience, these 2 articles should help you get started –
If you have any more questions – feel free to email email@example.com
There should be a validation message to check the end date before or equal start date.4 votes
Thanks Manli, I have emailed you on 9/11 asking for specifics, could you please check or elaborate on the scenario here? Appreciated!
It would be VERY beneficial to apply an Access Review policy to new groups as they are created, eliminating the management overhead of creating new policies AFTER each group created.
Also, if a Access Review Policy could be applied to multiple groups at a time, Access Reviewmanagement overhead would be reduced.32 votes
Good news – we have made more progress on this ask! We started private preview of reviews on all guests in Teams/Office groups. Please fill out this form to be included in the private preview! We look forward hearing your feedback, working together to improve this feature, and sharing more updates with you very soon!
Our organization requires Managers to approve access to Applications. Please give the option to require a manager to approve application access via the Access Reviews option.18 votes
Hi Justin, thanks for the feedback! It will definitely be helpful to have managers as the reviewers, there is a “manager” attribute in AAD’s user profile, but it’s currently a string only. We are working to improve the architecture first, then we can leverage the data to automatically assign managers to be reviewers. If you have any more feedback or questions on this, feel free to comment on this thread or email firstname.lastname@example.org.
- Don't see your idea?