Access Reviews for Azure Subscriptions: Why They Matter and How to Implement Them
Access Reviews are one of the most underrated parts of Microsoft Entra ID Governance. If Access Packages define how users get access, Access Reviews define how access stays clean over time. When you’re dealing with multiple Azure subscriptions—Dev, Test, Prod, shared services, platform layers—Access Reviews become essential.
Why Access Reviews Matter for Subscription Access
1. Prevent Privilege Creep
People change roles, move teams, leave projects, or simply stop needing access. Without reviews, access accumulates. Access Reviews ensure that only the right people retain access.
2. Reduce Risk in Sensitive Subscriptions
Prod subscriptions often contain regulated workloads, customer data, or missioncritical systems. Regular reviews ensure only authorised users remain.
3. Enforce Least Privilege
Even if someone needs access, they may not need the same level of access. Reviews allow owners to downgrade or remove roles.
4. Support Compliance Requirements
ISO 27001, SOC 2, PCI DSS, and internal audit teams all require periodic access validation. Access Reviews provide a clean audit trail.
5. Automate Governance
Instead of manually checking IAM roles across subscriptions, Access Reviews centralise and automate the process.
Prerequisites
Before you configure Access Reviews:
- Microsoft Entra ID P2 licensing
- Identity Governance Administrator or Global Administrator
- Access Packages already created for subscription access
- Resource owners identified (who will review access)
- Defined review cadence (monthly, quarterly, semiannual)
Where Access Reviews Fit in the Governance Model
Access Reviews operate at two levels:
1. Access Package Assignments
Review who still needs the access granted by the Access Package.
2. Direct RBAC Assignments
Review users who have roles assigned directly on subscriptions (outside Access Packages).
For subscription governance, you should ideally use Access Package Reviews, because they:
- Track the reason access was granted
- Show the request history
- Allow reviewers to see expiry dates
- Remove access automatically if not approved
Step-by-Step: Creating Access Reviews for Subscription Access
Step 1 — Navigate to Access Reviews
- Go to Microsoft Entra admin center
- Open Identity Governance → Access Reviews
Step 2 — Create a New Review
- Click New access review
- Choose Access package assignments
- Select the Access Package (e.g., Subscription-A-Access)
Step 3 — Configure Review Settings
- Review name: Subscription A – Quarterly Access Review
- Description: Quarterly review of users with access to Subscription A via Access Package.
Step 4 — Choose Reviewers
Options include:
- Managers (based on Entra ID manager attribute)
- Resource owners
- Specific users or groups
- Self-review (user confirms they still need access)
For subscriptions, the best practice is:
- Resource owner for Dev/Test
- Platform team + resource owner for Prod
Step 5 — Set Recurrence
- Quarterly is typical
- Monthly for high-risk subscriptions
- One-time for audits or cleanup
Step 6 — Configure Auto-Apply
This is where governance becomes powerful.
- Auto-apply results: Enabled
- If reviewer doesn’t respond: Remove access
- Require justification: Enabled
Step 7 — Notifications
Enable:
- Reviewer reminders
- User notifications
- Escalation alerts (optional)
Step 8 — Start the Review
Once started:
- Reviewers receive tasks
- Users may be asked to confirm access
- Expired or unapproved access is automatically removed
Operational Tips
- Use shorter review cycles for Contributor/Owner roles
- Use longer cycles for Reader roles
- Monitor review completion rates
- Document review outcomes for audit teams
- Combine Access Reviews with Privileged Identity Management (PIM) for elevated roles
Summary
Access Reviews are the backbone of subscription governance. They ensure that access granted through Access Packages remains justified, compliant, and minimal. When combined with lifecycle policies and approvals, they create a fully governed access model that scales across all your Azure subscriptions.
