- Entra ID Application assignment
- Teams membership, Office 365 group membership, or Entra ID security group membership
- Guest users only
- All users
With Entra ID Access Reviews, you can periodically review whether users should continue to have membership in an Entra ID group. It is a requirement that the group be sourced in Entra ID , so UW Groups are not compatible with this feature. Office 365 groups (commonly with names that begin with og_ at the UW) or Entra ID security groups are in scope for this capability. This capability helps ensure which users should retain membership in a group, helping to reduce the possibility that access to resources is retained past when they should be. The periodicity of the access review determines the maximum amount of time someone who has "left" would retain access.
The combination of an Entra ID sourced group, PIM activation, and Entra ID Access Review provide a strong access control combination to help ensure only the right people have access at the right time. However, it is possible to use a UW group with PIM, if an Entra ID Access Review is not required. This combination takes more effort to setup, requiring UW-IT involvement, so we do ask that customers limit requests for this capability to scenarios which justify the extra effort. PIM and Access Reviews do require the user to have UW Microsoft Advanced Service Level to satisfy Microsoft licensing requirements. To request an Access Review or the combination noted, please open a request to UW-IT (help@uw.edu) with a subject line of "Microsoft Infrastructure: Access Review", with the details of your scenario.