Browse all topics
Microsoft Entra (Identity)

Entra ID Governance explained

By Emil Björk · Microsoft ecosystem consultant, Gothenburg

Microsoft's identity governance product — access reviews, entitlement management, lifecycle workflows, and separation of duties — plus the P2 vs Entra Suite vs standalone licensing maze, and a rollout order that works.

Microsoft Entra ID Governance is Microsoft's identity governance and administration (IGA) product: the layer that answers who has access to what, why do they have it, and when does it go away. Authentication and Conditional Access decide whether a sign-in succeeds; governance decides whether the access behind that sign-in should exist at all. It competes with SailPoint, Saviynt, and Omada — and for organisations already standardised on Entra ID, it has become the default answer rather than the budget option.

The product is four capabilities under one name, and it helps to keep them distinct.

Access reviews

Access reviews put an expiry date on trust. On a schedule you choose, someone — the resource owner, the user's manager, or the users themselves — must re-confirm that access to a group, an application, a Teams team, or a privileged role is still needed. Decisions can be auto-applied: reject or ignore a review, and the access is removed.

Two design points separate useful review programmes from checkbox theatre. First, review the right things: guest accounts, privileged role eligibility, and high-impact application groups — not every group in the tenant, which trains reviewers to bulk-approve. Second, turn on auto-apply and the ML-assisted recommendations (which flag users with no recent sign-in or low affiliation with other members); a review whose outcome nobody enforces is a report, not a control.

Entitlement management

Entitlement management packages access. An access package bundles the groups, app roles, and SharePoint site permissions a role needs — "New sales hire", "Contractor: project Falcon" — behind a self-service request with approval steps, justification, time limits, and automatic expiry. Guests from partner organisations can request packages too, which turns B2B collaboration from "someone invited them and forgot" into a governed lifecycle with a defined end date.

This is the piece that changes day-to-day behaviour the most: instead of helpdesk tickets asking for seven group memberships (three of which get forgotten, four of which are never removed), access is requested, approved, granted, and expired as one unit.

Lifecycle workflows

Lifecycle workflows automate joiner, mover, and leaver events. A joiner workflow can generate a Temporary Access Pass and send onboarding email before day one; a leaver workflow can, on the employee's last day, disable the account, revoke sessions and MFA methods, remove group memberships, and notify the manager — automatically, driven by employment dates coming from your HR-driven provisioning.

Leaver automation alone justifies the product for many organisations. Manual offboarding fails quietly and constantly, and every failure is a live account for a departed employee. If you deploy nothing else from this product, deploy the leaver workflow.

Separation of duties

Separation-of-duties checks let entitlement management enforce incompatibility rules: a user holding access package A (say, vendor creation) cannot also request package B (payment approval). It's the narrowest of the four capabilities and depends entirely on entitlement management being the way access is actually granted — but for finance and ERP scenarios it's the control auditors ask about by name.

The licensing maze

This is where most confusion lives, so plainly:

  • Entra ID P2 (included in Microsoft 365 E5) carries some governance features: access reviews, basic entitlement management, and PIM. Many organisations run a respectable programme on P2 alone.
  • Entra ID Governance is a separate add-on licence on top of P1 or P2 that unlocks the full product: lifecycle workflows, ML-assisted review recommendations, separation-of-duties checks, and the richer entitlement management features (including Verified ID integration in approval flows). There are two SKU shapes — a full add-on for P1 customers and a cheaper "step-up" for P2 customers — which exist so P2/E5 customers don't pay twice for what they own.
  • The Entra Suite includes ID Governance alongside Internet Access, Private Access, Identity Protection, and premium Verified ID.

So the honest buying guidance: E5 does not give you the full governance product — that assumption is the single most common licensing mistake in this space. If governance is your only gap, buy the Governance step-up; the Suite is only better value if the ZTNA and secure web gateway products are genuinely on your roadmap. Governed users need the licence; per Microsoft's licensing model, guests are covered under a monthly-active-users arrangement rather than per-seat — check the current terms rather than assuming either way.

Rollout order for a green-field IGA deployment

Deploying all four capabilities at once fails; each one needs organisational muscles the previous one builds. The order that works:

  1. Get the joiner/leaver data flowing. Lifecycle workflows are only as good as the employment dates behind them — connect HR-driven provisioning (Workday, SuccessFactors, or API-driven) first.
  2. Deploy the leaver workflow, then the joiner workflow. Highest risk reduction, no end-user behaviour change, easy to demonstrate to auditors.
  3. Start access reviews narrow: guest accounts tenant-wide, then privileged role eligibility, then the top 20 sensitive application groups. Auto-apply results from day one.
  4. Introduce entitlement management for new access requests — start with one department's onboarding package and external-partner access, and let it spread by being easier than tickets.
  5. Add separation-of-duties rules once entitlement management is the normal path — they're meaningless before then.
  6. Only then consider the long tail: custom workflow extensions via Logic Apps, Verified ID in approvals, and reviews of everything else.

Run in that order, a mid-sized organisation gets from nothing to a defensible IGA position in a few months — with the boring, catastrophic failure mode (departed users with live access) fixed in the first few weeks.

Frequently asked questions

Is Entra ID Governance included in Entra ID P2 or Microsoft 365 E5?
Only partially. P2 (and therefore E5) includes access reviews and basic entitlement management. The full product — lifecycle workflows, ML-assisted review recommendations, separation-of-duties checks, richer entitlement management — requires the Entra ID Governance add-on licence or the Entra Suite.
What's the difference between the Entra ID Governance licence and the Entra Suite?
Entra ID Governance is one product, sold as an add-on on top of Entra ID P1 or P2. The Entra Suite is a bigger bundle that includes ID Governance plus Internet Access, Private Access, Identity Protection, and premium Verified ID. Buy Governance alone if identity governance is the only gap; the Suite only pays off if you'll deploy the network access products too.
Do access reviews actually remove access?
Yes, if you configure them to. Reviews can auto-apply results — removing users the reviewer rejected or who never responded. Reviews configured to only produce a report are the reason many organisations think reviews 'don't work'; enforcement is a setting, and you should turn it on.
What should a green-field IGA rollout deploy first?
Lifecycle workflows for joiner/leaver automation first (biggest risk reduction per effort), then access reviews on guest accounts and privileged roles, then entitlement management to replace ad-hoc access requests, and separation-of-duties checks last, once entitlement management is the normal way access is granted.

Further reading

Spot something wrong or want a topic covered? Send it through the contact form.