Azure Active Directory

Welcome to the Azure Active Directory suggestions and feedback site! We love hearing from you. If you have suggestions, please submit an idea or vote up an idea. We are monitoring the site actively.

Thank you for joining our community and helping improve Azure AD!

How can we improve Azure Active Directory?

(thinking…)

Enter your idea and we'll search to see if someone has already suggested it.

If a similar idea already exists, you can support and comment on it.

If it doesn't exist, you can post your idea so others can support it.

Enter your idea and we'll search to see if someone has already suggested it.

  • Hot ideas
  • Top ideas
  • New ideas
  • My feedback
  1. Access Reviews: Apply to new groups and/or multiple groups

    It would be VERY beneficial to apply an Access Review policy to new groups as they are created, eliminating the management overhead of creating new policies AFTER each group created.
    Also, if a Access Review Policy could be applied to multiple groups at a time, Access Reviewmanagement overhead would be reduced.

    17 votes
    Sign in
    Check!
    (thinking…)
    Reset
    or sign in with
    • facebook
    • google
      Password icon
      Signed in as (Sign out)

      We’ll send you updates on this idea

      3 comments  ·  Access Reviews  ·  Flag idea as inappropriate…  ·  Admin →
    • Add Manager Option to Reviewers in Access Reviews

      Our organization requires Managers to approve access to Applications. Please give the option to require a manager to approve application access via the Access Reviews option.

      8 votes
      Sign in
      Check!
      (thinking…)
      Reset
      or sign in with
      • facebook
      • google
        Password icon
        Signed in as (Sign out)

        We’ll send you updates on this idea

        2 comments  ·  Access Reviews  ·  Flag idea as inappropriate…  ·  Admin →

        Hi Justin, thanks for the feedback! It will definitely be helpful to have managers as the reviewers, there is a “manager” attribute in AAD’s user profile, but it’s currently a string only. We are working to improve the architecture first, then we can leverage the data to automatically assign managers to be reviewers. If you have any more feedback or questions on this, feel free to comment on this thread or email accessreviews@microsoft.com.

      • Access review for subscription

        Expand access reviews to support Azure Subscription and Resources for explicit assigned identity.

        6 votes
        Sign in
        Check!
        (thinking…)
        Reset
        or sign in with
        • facebook
        • google
          Password icon
          Signed in as (Sign out)

          We’ll send you updates on this idea

          1 comment  ·  Access Reviews  ·  Flag idea as inappropriate…  ·  Admin →
        • Access reviews should also apply to Directory access

          Access Reviews should let you review guest users access on the directory level. Using a dynamic group with all guest users in it, I should be able to have access reviews DELETE the user from the Azure Active Directory rather than just removing the user from a group.

          3 votes
          Sign in
          Check!
          (thinking…)
          Reset
          or sign in with
          • facebook
          • google
            Password icon
            Signed in as (Sign out)

            We’ll send you updates on this idea

            0 comments  ·  Access Reviews  ·  Flag idea as inappropriate…  ·  Admin →

            Hi Sigurd, thanks so much for the feedback! If you could reach out to me I would love to chat more to understand your use case and have you participate in our private preview of the delete scenario.

            /Fionna

          • Access review - domain admin & Global Admin

            Hi,

            Would be great if Access Reviews could include the on-prem group Domain Admins, and the Cloud based group GLobal Admins. Right now this is not possible.

            3 votes
            Sign in
            Check!
            (thinking…)
            Reset
            or sign in with
            • facebook
            • google
              Password icon
              Signed in as (Sign out)

              We’ll send you updates on this idea

              0 comments  ·  Access Reviews  ·  Flag idea as inappropriate…  ·  Admin →

              Thank you John for the feedback! My understanding is that you are referring to access reviews of privileged roles in the PIM experience.

              In regards to reviewing on-prem group Domain Admins, historically, groups like that were blocked by AAD connecto for not sending them to AAD, so they are filtered out.

              For cloud based group Global Admins, you can review global admins in the current PIM experience, these 2 articles should help you get started –
              docs.microsoft.com/en-us/azure/active-direc..

              docs.microsoft.com/en-us/azure/active-direc..

              If you have any more questions – feel free to email accessreviews@microsoft.com

            • Access review

              There should be a validation message to check the end date before or equal start date.

              3 votes
              Sign in
              Check!
              (thinking…)
              Reset
              or sign in with
              • facebook
              • google
                Password icon
                Signed in as (Sign out)

                We’ll send you updates on this idea

                2 comments  ·  Access Reviews  ·  Flag idea as inappropriate…  ·  Admin →
              • 这是kkr儿童的愚蠢事情

                这是kkr儿童的愚蠢事情

                1 vote
                Sign in
                Check!
                (thinking…)
                Reset
                or sign in with
                • facebook
                • google
                  Password icon
                  Signed in as (Sign out)

                  We’ll send you updates on this idea

                  0 comments  ·  Access Reviews  ·  Flag idea as inappropriate…  ·  Admin →
                • Why can't I use my software?

                  I've used MSOffice for decades and because of stupid "security" excuses, I get locked out of my license becuase of network issues that are detected, yet there is nothing wrong with the network. Why can't software companies write secure software to make it easier for legitimate users rather than making more and more difficult for legitimate users to access their own documents? Haskers are always one step ahead of you anyway.

                  1 vote
                  Sign in
                  Check!
                  (thinking…)
                  Reset
                  or sign in with
                  • facebook
                  • google
                    Password icon
                    Signed in as (Sign out)

                    We’ll send you updates on this idea

                    0 comments  ·  Access Reviews  ·  Flag idea as inappropriate…  ·  Admin →
                  • Recurring PIM Access Reviews

                    Currently with PIM you have to manually create a new access review each time you want one to occur which is tedious, manual, error prone work, easy to forget, etc. Generally, access reviews are required on a recurring basis (monthly, quarterly, yearly for example). There should be the capability to select a frequency for an access review and have it automatically occur at that interval. At a minimum, it would be ideal to have an option for monthly, quarterly, and yearly, but any frequency would be even better.

                    1 vote
                    Sign in
                    Check!
                    (thinking…)
                    Reset
                    or sign in with
                    • facebook
                    • google
                      Password icon
                      Signed in as (Sign out)

                      We’ll send you updates on this idea

                      1 comment  ·  Access Reviews  ·  Flag idea as inappropriate…  ·  Admin →
                    • Integrate with Microsoft Flow for Customizing Emails and Approvers

                      Right now, you can only do out of the box emails and approvals. Integrating as an application from flow will allow you to create different approval processes as needed; and customize email messages as needed.

                      1 vote
                      Sign in
                      Check!
                      (thinking…)
                      Reset
                      or sign in with
                      • facebook
                      • google
                        Password icon
                        Signed in as (Sign out)

                        We’ll send you updates on this idea

                        0 comments  ·  Access Reviews  ·  Flag idea as inappropriate…  ·  Admin →

                        Hi Justin, thanks so much for the feedback! We currently use AEO (Azure email orchestrator) for sending emails, I can see how Flow can be helpful here, will look into it with the team, thanks for the suggestion! Do you know any services customizing their emails using Flow? I would love to know!

                        /Fionna

                      • PIM Access Reviews Emails Alerts

                        Would be great having the opportunity to edit or add a message into the Email sent by Azure.
                        Eg. When someone has the role membership denied by a role owner, the user should get the email WITH the reason and not just the email saying that the has been removed.

                        Also would be great allowing the GA's to add a message or create the reminders by themselves AND schedule it.

                        1 vote
                        Sign in
                        Check!
                        (thinking…)
                        Reset
                        or sign in with
                        • facebook
                        • google
                          Password icon
                          Signed in as (Sign out)

                          We’ll send you updates on this idea

                          0 comments  ·  Access Reviews  ·  Flag idea as inappropriate…  ·  Admin →
                        • Access Reviews: Skip review if no members are eligable for review

                          If a group is empty the owner still get's an email to complete a review, this is confusing as they don't know what to do when they click the link to the review as there are no actions to complete. Access Review should be smart enough to know that an email to the manager is not necessary if there are no members to review.

                          1 vote
                          Sign in
                          Check!
                          (thinking…)
                          Reset
                          or sign in with
                          • facebook
                          • google
                            Password icon
                            Signed in as (Sign out)

                            We’ll send you updates on this idea

                            0 comments  ·  Access Reviews  ·  Flag idea as inappropriate…  ·  Admin →
                          • Don't see your idea?

                          Feedback and Knowledge Base