SC‑300 Study Portal Path 5

Unit 3: Create access reviews for groups and apps

Why create access reviews for groups and apps

Access to groups and applications changes frequently due to:

Without review, these assignments often become stale.

Creating access reviews allows administrators to:

Prerequisites

Before creating access reviews, ensure:

Create an access review (step-by-step)

Step 1: Open Identity Governance

Step 2: Select what to review

You must choose the resource type.

Available options

If you select Teams + Groups

You have two choices:

Use the first option for broad guest cleanup. Use the second option for targeted governance.

If you select Applications

Step 3: Select scope

Define who is reviewed.

Scope options

If “All Microsoft 365 groups with guest users” was selected, scope is automatically Guest users only.

Step 4: Select reviewers

Reviewers are responsible for approving or denying access.

Reviewer options

Important: Reviewer selection cannot be changed after the review starts.

Step 5: Configure recurrence

Define how often the review runs.

Frequency options

Duration

Start and end dates

Step 6: Configure completion behavior

This determines what happens after the review ends.

Auto-apply results

If reviewers don’t respond

Choose what happens to unreviewed users:

Guest user actions (if denied)

Options include:

Guest actions are limited when reviewing everyone or all groups.

Step 7: Enable decision helpers

Decision helpers provide recommendations based on:

Reviewers can accept recommendations in bulk.

Step 8: Advanced settings

Available options

Step 9: Review and create

Step 10: Start the access review

Access review status lifecycle

StatusMeaning
NotStartedWaiting to begin
InitializingDiscovering users
StartingSending notifications
InProgressReview active
CompletingFinalizing
Auto-ReviewingSystem applying defaults
Auto-ReviewedDecisions recorded
ApplyingChanges applied
AppliedCompleted
FailedReview error

Creating access reviews via APIs

All portal actions can also be performed via:

Used for: