Menu
Modern Workplace Blog
  • Home
  • About: Kenneth van Surksum
  • Cookie Policy
Modern Workplace Blog
February 9, 2021February 9, 2021

First look at Access Reviews for guests in all Teams and Microsoft 365 Groups

In January, Microsoft announced that they released a public preview allowing entitled customers to create Azure AD access reviews for guest users across all Microsoft Teams and Microsoft 365 Groups in the organization.

By implementing Access Reviews, an identity governance feature you can review members of groups, enterprise applications and roles within your Azure Active Directory. Access Reviews requires Azure AD Premium P2 licenses for users who benefit from the functionality, see: How many licenses must you have?

Some scenario’s in which you might want to use Access Reviews are:

  • Validate membership of Azure AD privileged roles on a regular basis
  • Validate access to Applications on a regular basis
  • Review members of policy exception groups, for example users excluded for a particular Conditional Access policy
  • And now also, owners of a Teams or Microsoft 365 group can review the guest memberships on a regular basis

Access Reviews for Azure AD privileged roles have been described in my article about Azure AD Privileged Identity Management (PIM), which can be found here: Lessons learned while implementing Azure AD Privileged Identity Management (PIM)

The need for Governance of Guest users

From a governance perspective, having external guest users in your Azure AD environment is a challenge. As you might know Guest users can be created in your Azure Active Directory when:

  • A user in your Azure AD shares a specific document with an external user
  • A user in your Azure AD invites an external user to become member of a Microsoft Teams or SharePoint site
  • There might also be some other scenarios….

Fact is, that once a Guest user account has been created, it can stay in your Azure AD for ever and ever. This is a challenging security risk, since those Guest users have access to your company data. Might the account of the Guest user been compromised, then the person in possession of the compromised Guest account also has access to your company data. It’s possible to require Guest user to also require a second factor authentication though, which is a good first security measure you can take.

What you want to do though, is have some process in place where users sharing data with External Users can easily review this access once in a while and have a way to remove the access to external users if that access is not needed anymore.

Some of these challenges can be solved with the Access Review for Guest users functionality, let’s have a look.

Access Reviews for guests in all Teams and Microsoft 365 Groups

You can create an access review from the Identity Governance blade in the Azure AD administration portal.

— All 
—pplicstions 
Privllegee Identit._ 
Z•otectio 
Azure Active Directory admin center 
Dashboard > Insight243.V. > Identity Governance 
Identity Governance I Access reviews 
Filter by type 
R uou« 
O 
—I— scce" 
Getting sty red 
Type 
— Columns 
paceges 
Search by 
Connected orgsniuticré 
name or owrær 
Cæated On 
No to displsy 
Reports 
Settings 
Identity 
Aure A r" u 
Tems of 
of use 
Audit logs 
Troubleshoot 
+ Support 
re guest
Access reviews

If you click on “+ New access review”, the new access reviews creation experience will open. From this page you can either select to create an access review for a Microsoft Teams or Microsoft Groups or you can create one for an Application.

New access review 
Welcome to the new access reviews creation experience (preview)! It would like to return to the old experience, click here. 
New to access reviews? Click here to learn more. 
uest 
Review type 
Reviews 
Settings 
Review Create 
Step 1: Select what to review 
@ Teams + Groups 
to 
teams + grmaps 
Step 2: Select which Teams + Groups 
All groups with g 
o 
Seet tesm 
s + gmups 
Select group(s) to 
Step 3: Select review scope 
@ Guut cnly 
All uærs 
C) 
Applications 
to 
—pplicstions
Review type

Once Teams + Groups is selected, you can choose whether you want to include all Microsoft 365 groups with guest users, or if you want to select your Teams and Groups for which the access review is applicable. If you select “(Preview) All Microsoft 365 groups with guest users” you can only have Guest users in your scope. If you select an individual group you can also select “All users”. You can continue with the configuration by clicking on the “Next: Reviews” button, which will bring you to the review tab.

Dashboard > Identity Gcn•ernance > 
New access review 
Welcome to the new access reviews creation experience (preview)! It would like to return to the old experience, click here. 
New to access reviews? Click here to learn more. 
Review type 
Reviews 
Settings 
Review Create 
Select reviewers 
Gmup owner(s) 
If do not exist. select fyllback to t th 
Select fillback 
Specify recurrence of review 
Month ly 
Durstion (in d.ys) 
St—rt date 
02/09/2021 
Ene on specific 
on 
E number cf
Reviews

On the review tab you can select the reviewers for this access review. This can either be:

  • Group owner(s)
  • Selected user(s) or group(s)
  • Users review own access
  • (Preview) Managers of users

You can also define the schedule, which can either be weekly, monthly, quarterly, semi-annually or annually. The duration of the review in days, the start date and when the access review should end. Once finished you can continue to the settings tab by clicking on “Next: Settings”

New access review 
Welcome to the new access reviews creation experience (preview)! It would like to return to the old experience, click here. 
New to access reviews? Click here to learn more. 
e m sil 
Addition—I content for 
Review type 
Reviews 
Settings Review Create 
Upon completion settings 
Auto apply rewlts to 
L' don't CJ 
Enable reviewer decision helpers 
No sigr.ln within 30 O 
Advanced settings 
Email notificat&
Settings

On the settings tab you can configure the following settings:

Upon completion settings, where you can define what must be done with the results of the access review. So for example if the reviewer specifies that the access for the guest user is not needed anymore, the access is removed. If you disable this setting you’ll see that the access is not necessary anymore in the access review reporting. You can also specify what happens if the reviewer doesn’t respond, by default “No change” is selected, but you can also select; Remove access, Approve access and Take recommendations.

You also have the option to enable reviewer decision helpers, which will notify the decision maker if the account being reviewed hasn’t signed-in within the last 30 days. (too bad you adjust this value)

Last but not least, you can configure some advanced settings.

  • Justification required, which requires the reviewer to supply a reason for approval
  • Email notifications, which enables Azure AD to send emails to reviewers when an access review starts, and to admins when a review completes
  • Reminders, where Azure AD will send reminder emails for Access Reviews in progress to all reviewers at the midpoint of the review period
  • Additional content for reviewer email which will show some additional text in the email sent to reviewers. Best practices are to include context on why users are being asked to do this review and where they should go if they have questions.

Once finished you can continue to the Review and Create settings tab by clicking on “Next: Review + Create”

Review and create

On the review and create tab you can review the settings you just set, and you can provide a name and description for the Access Review for later identification. If you are satisfied with the settings you can click on Create to create the Access Review.

Reviewer Experience

Once the access review is active, the reviewer will get an email like the one below. The email is localized, that’s why it’s in Dutch.

Received localized email

The reviewer can start the access review by clicking on the Start Review button, which will open a Web browser to the My Access panel.

Review available on the My Access page

From here the review can see which Guest user has access to the Microsoft 365 group, notice that there is a recommendation to deny access, because the user hasn’t signed-in in the last 30 days.

From the overview the reviewer can select the Guest user account, and select either Approve, Deny, Don’t know or Accept recommendations. For each choice made you have to provide a reason, as specified in the properties of the access review earlier.

Justification needed

The reviewer can change its decision for as long as the access review is running

Change decision options

For each group you can view the status of the access review from the Azure AD management portal

Access review status in the Azure AD admin portal

Once the access review is finished, or you an admin stops the access review the denied guest account is automatically removed from the M365 Group.

Conclusion

Access Reviews for guests in all Teams and Microsoft 365 Groups is a welcome addition to the Access Reviews functionality. The big advantage is that newly created Microsoft Teams and/or Microsoft 365 groups fall under the regime of the access review and therefore maintaining the solutions requires minimal effort.

Removing access from a Microsoft 365 group doesn’t remove the Guest account from Azure AD though, and it might be that individual documents are still shared with the Guest user. So you must still build something which can help you report on that.

Tweet
Follow me
Tweet #WPNinjasNL

1 thought on “First look at Access Reviews for guests in all Teams and Microsoft 365 Groups”

  1. Logu says:
    July 9, 2021 at 8:01 pm

    Hi, This is really useful and I’m planning to implement this feature, but I’m not sure how to apply settings to get email if any changes happened to the assigned groups and weekly once review email. It would be really helpful if you could provide some suggestions on the same. Thanks!

    Reply

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Founding member of:

Recent Posts

  • MAM vs. MDM: Choosing the Right Mobile Management Approach
  • Comparing Web Filtering and Security: Microsoft Entra Internet Access (Global Secure Access) vs. Microsoft Defender for Endpoint (MDE)
  • Navigating New Authentication Methods: SMS for Password Reset, Not for MFA
  • From SPF to DANE: Securing Microsoft 365 Email Communications
  • Protecting your Break Glass accounts in Entra now that MFA gets enforced on more and more Admin portals

Books

System Center 2012 Service Manager Unleashed
Amazon
System Center 2012 R2 Configuration Manager Unleashed: Supplement to System Center 2012 Configuration Manager
Amazon
System Center Configuration Manager Current Branch Unleashed
Amazon
Mastering Windows 7 Deployment
Amazon
System Center 2012 Configuration Manager (SCCM) Unleashed
Amazon

Archives

  • February 2025
  • January 2025
  • September 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • September 2023
  • August 2023
  • February 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • May 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • October 2019
  • August 2019
  • July 2019
  • November 2016
  • November 2015
  • June 2015
  • May 2015
  • November 2014
  • July 2014
  • April 2014
  • March 2014
  • February 2014
  • January 2014
  • November 2013
  • August 2013
  • April 2013
  • March 2013
  • January 2013
  • December 2012
  • November 2012
  • August 2012
  • July 2012
  • June 2012

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Categories

  • ABM (4)
  • Advanced Threat Protection (4)
  • Announcement (44)
  • Azure (3)
  • AzureAD (73)
  • Certification (2)
  • Cloud App Security (5)
  • Conditional Access (58)
  • Configuration Manager (24)
  • Entra (2)
  • Entra Id (8)
  • Events (14)
  • Exchange Online (9)
  • Identity Protection (5)
  • Intune (27)
  • Licensing (2)
  • Microsoft Defender (1)
  • Microsoft Defender for Endpoint (1)
  • Microsoft Endpoint Manager (35)
  • Mobile Application Management (4)
  • Modern Workplace (74)
  • Office 365 (10)
  • Overview (11)
  • Power Platform (1)
  • PowerShell (2)
  • Presentations (9)
  • Privileged Identity Management (5)
  • Role Based Access Control (2)
  • Security (63)
  • Service Manager (4)
  • Speaking (30)
  • Troubleshooting (4)
  • Uncategorized (11)
  • Windows 10 (15)
  • Windows 11 (5)
  • Windows Update for Business (4)
  • WMUG.nl (16)
  • WPNinjasNL (32)

Tags

#ABM #AzureAD #community #conditionalaccess #ConfigMgr #IAM #Intune #m365 #MEM #MEMCM #microsoft365 #modernworkplace #office365 #security #webinar #wmug_nl ATP authentication strength AzureAD Branding Community Conditional Access ConfigMgr ConfigMgr 2012 Email EXO Identity Intune Licensing M365 MCAS MFA Modern Workplace Office 365 OSD PIM Policy Sets Presentation RBAC roles Security System Center Task Sequence troubleshooting webinar

Recent Comments

  • brc on Protecting your Break Glass accounts in Entra now that MFA gets enforced on more and more Admin portals
  • [m365weekly] #186 – M365 Weekly Newsletter on MAM vs. MDM: Choosing the Right Mobile Management Approach
  • Dean Gross on Comparing Web Filtering and Security: Microsoft Entra Internet Access (Global Secure Access) vs. Microsoft Defender for Endpoint (MDE)
  • nikhil tech on Protecting your Break Glass accounts in Entra now that MFA gets enforced on more and more Admin portals
  • Kenneth on Comparing Web Filtering and Security: Microsoft Entra Internet Access (Global Secure Access) vs. Microsoft Defender for Endpoint (MDE)

This information is provided “AS IS” with no warranties, confers no rights and is not supported by the author.

Copyright © 2021 by Kenneth van Surksum. All rights reserved. No part of the information on this web site may be reproduced or posted in any form or by any means without the prior written permission of the publisher.

Shorthand: Don’t pass off my work as yours, it’s not nice.

©2025 Modern Workplace Blog | Powered by WordPress and Superb Themes!
This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Cookie settingsACCEPT
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT