SC‑300 Study Portal Path 5

Unit 5: Monitor access review findings

Purpose of this unit

After access reviews are created and started, they must be monitored and acted upon. This unit focuses on how reviewers perform access reviews, how decisions are recorded, and how administrators can interpret outcomes. Monitoring ensures that access reviews actually lead to risk reduction, not just configuration effort.

Access reviews across Microsoft services

Microsoft Entra ID access reviews can be used to manage access for:

This allows organizations to apply a consistent governance model across identities and resources, regardless of where access is granted.

Performing access reviews using My Apps

Reviewers can perform access reviews either directly from an email notification or through the My Apps portal.

Start an access review from email

This method is ideal for reviewers who don’t regularly visit the portal.

Start an access review from My Apps

If the reviewer doesn’t have the email or prefers the portal:

Important behaviors:

Reviewing user access

Once inside the access review, reviewers see a list of users whose access must be evaluated.

Ways to make decisions

There are two supported approaches:

Approve or deny access manually

Reviewers can take action in two ways:

Additional options and behaviors:

All decisions are saved once Save is selected.

Important decision behaviors

Example:

Approve or deny access using recommendations

Microsoft Entra provides recommendations based on user activity, such as sign-in behavior.

How to use recommendations:

This helps reviewers make faster, data-driven decisions, especially for large reviews.

Why monitoring access reviews matters (exam focus)

Monitoring access review findings ensures that:

Misconfigurations or ignored reviews can leave excessive access in place, which defeats the purpose of identity governance.