It would be VERY beneficial to apply an Access Review policy to new groups as they are created, eliminating the management overhead of creating new policies AFTER each group created.
Also, if a Access Review Policy could be applied to multiple groups at a time, Access Reviewmanagement overhead would be reduced.17 votes
Thanks for the comment! Yes this is a great scenario and the team is invested already, should be making some updates in the next few months. If you have any more feedback or questions on this, feel free to comment on this thread or email firstname.lastname@example.org.
Our organization requires Managers to approve access to Applications. Please give the option to require a manager to approve application access via the Access Reviews option.8 votes
Hi Justin, thanks for the feedback! It will definitely be helpful to have managers as the reviewers, there is a “manager” attribute in AAD’s user profile, but it’s currently a string only. We are working to improve the architecture first, then we can leverage the data to automatically assign managers to be reviewers. If you have any more feedback or questions on this, feel free to comment on this thread or email email@example.com.
Expand access reviews to support Azure Subscription and Resources for explicit assigned identity.6 votes
Thanks for the feedback, we have this work in planning.
Access Reviews should let you review guest users access on the directory level. Using a dynamic group with all guest users in it, I should be able to have access reviews DELETE the user from the Azure Active Directory rather than just removing the user from a group.3 votes
Hi Sigurd, thanks so much for the feedback! If you could reach out to me I would love to chat more to understand your use case and have you participate in our private preview of the delete scenario.
Would be great if Access Reviews could include the on-prem group Domain Admins, and the Cloud based group GLobal Admins. Right now this is not possible.3 votes
Thank you John for the feedback! My understanding is that you are referring to access reviews of privileged roles in the PIM experience.
In regards to reviewing on-prem group Domain Admins, historically, groups like that were blocked by AAD connecto for not sending them to AAD, so they are filtered out.
For cloud based group Global Admins, you can review global admins in the current PIM experience, these 2 articles should help you get started –
If you have any more questions – feel free to email firstname.lastname@example.org
There should be a validation message to check the end date before or equal start date.3 votes
Thanks Manli, I have emailed you on 9/11 asking for specifics, could you please check or elaborate on the scenario here? Appreciated!
I've used MSOffice for decades and because of stupid "security" excuses, I get locked out of my license becuase of network issues that are detected, yet there is nothing wrong with the network. Why can't software companies write secure software to make it easier for legitimate users rather than making more and more difficult for legitimate users to access their own documents? Haskers are always one step ahead of you anyway.1 vote
Currently with PIM you have to manually create a new access review each time you want one to occur which is tedious, manual, error prone work, easy to forget, etc. Generally, access reviews are required on a recurring basis (monthly, quarterly, yearly for example). There should be the capability to select a frequency for an access review and have it automatically occur at that interval. At a minimum, it would be ideal to have an option for monthly, quarterly, and yearly, but any frequency would be even better.1 vote
Right now, you can only do out of the box emails and approvals. Integrating as an application from flow will allow you to create different approval processes as needed; and customize email messages as needed.1 vote
Hi Justin, thanks so much for the feedback! We currently use AEO (Azure email orchestrator) for sending emails, I can see how Flow can be helpful here, will look into it with the team, thanks for the suggestion! Do you know any services customizing their emails using Flow? I would love to know!
Would be great having the opportunity to edit or add a message into the Email sent by Azure.
Eg. When someone has the role membership denied by a role owner, the user should get the email WITH the reason and not just the email saying that the has been removed.
Also would be great allowing the GA's to add a message or create the reminders by themselves AND schedule it.1 vote
Thanks, the team is reviewing this ask!
If a group is empty the owner still get's an email to complete a review, this is confusing as they don't know what to do when they click the link to the review as there are no actions to complete. Access Review should be smart enough to know that an email to the manager is not necessary if there are no members to review.1 vote
Thank you Joachim for the feedback! That is a valid point and we have this feature in our roadmap. Please stay tuned for updates! If you have any more questions – feel free to email email@example.com.
- Don't see your idea?