Managed Entra ID Identity Hygiene and Access Reviews
Managed Entra ID Identity Hygiene and Access Reviews is monthly identity operations for a Microsoft Entra ID tenant that has already been set up properly: IT Partner finds and cleans up stale users and guests, watches app registration secrets and certificates before they expire, reviews privileged-role and PIM assignments, checks Conditional Access against the baseline documented at onboarding, reviews enterprise-application consents, runs your quarterly access-review campaigns end to end — configuring them, chasing reviewers, archiving the evidence — and delivers a monthly report written for auditors. The service costs $3 per user per month with no long-term contract. It is the operations layer after IT Partner's Microsoft Entra ID Governance Implementation or Conditional Access Policy Implementation, built for organizations of roughly 50 to 1,000 users that have no identity engineer to keep the result clean.
What this engagement is
Identity is where auditors and cyber insurers look first, and it decays monthly. Leavers keep enabled accounts because HR told nobody. Guests invited for one project linger for years with access to the SharePoint site that now holds the board pack. An app registration's client secret expires at two in the morning and takes an integration down — or never expires and becomes a long-lived credential nobody remembers issuing. The Global Administrator count creeps upward. A Conditional Access policy gets a temporary exclusion for the CEO's trip that never comes off. Users consent to a productivity app that asked for read access to every mailbox. None of this is dramatic. It is entropy, in the one system that gates everything else — and it is exactly what an auditor's evidence request or an insurer's renewal questionnaire is designed to surface. Our guide to Entra ID Governance: access reviews, PIM, and lifecycle workflows explains the machinery Microsoft provides; this service is the person who runs it every month. Each month, IT Partner works a fixed cycle against the baseline documented at onboarding. Stale accounts: member users and guests past the inactivity thresholds you agreed are identified from sign-in activity, confirmed with their owners, and disabled or removed with your approval, within the monthly allowance in your service order. Application credentials: every app registration and service principal secret and certificate is tracked against its expiry, flagged on the agreed lead time, and unused credentials and abandoned applications are recommended for removal. Privileged access: Entra role assignments and PIM eligibility are reviewed against the minimum you approved — who holds Global Administrator, who is permanently active where they should be eligible, whose activation nobody would approve today. Conditional Access: the live policy set is compared with the baseline, and every drift — a new exclusion, a disabled policy, a report-only policy that never went to enforcement — is either remediated or documented as an agreed change with an owner and an expiry. Enterprise applications: new consents and high-privilege permission grants are reviewed, and unused integrations are flagged. Every quarter, the access-review campaigns you scoped run end to end: we configure them, brief and chase the reviewers, apply the outcomes, and archive the decisions as evidence. And every month closes with a report written for the people who will eventually ask for it — auditors, insurers, and your own leadership. Licensing is stated plainly, because it decides what the service can do. Conditional Access needs Microsoft Entra ID P1, included in Microsoft 365 Business Premium, E3, and E5. Privileged Identity Management and access reviews need Microsoft Entra ID P2 — included in Microsoft 365 E5 and Enterprise Mobility + Security E5, or licensed on its own — for the users who hold eligible assignments, act as approvers, or perform reviews. The Microsoft Entra ID Governance add-on (or the Microsoft Entra Suite) unlocks the advanced review features we lean on where available: inactive-user recommendations, machine-learning affiliation recommendations, multi-resource reviews, and lifecycle workflows. Guest governance actions are metered by Microsoft per governed guest per month through an Azure subscription. Without P2, we still run the hygiene cycle from sign-in activity, credential inventories, role reports, and Conditional Access exports — but formal access-review campaigns cannot run, and we say so at onboarding rather than imply them. The boundaries are equally plain: initial implementation is a project, reactive administration is Microsoft Entra Administrator on Demand, and threat detection and response belong to Multi-Platform MDR and Microsoft Sentinel Ongoing Monitoring — this service reduces the attack surface those services watch; it does not watch it for them.
Success criteria
What you receive
How the work unfolds
Access is established through GDAP roles you approve — least-privilege, time-bound, never standing global admin. We inventory the tenant: Conditional Access policies, roles and PIM, applications and credentials, guests, licensing. The baseline document becomes the contract for everything after: inactivity thresholds, the privileged-access minimum, the review scopes and cadence, and the monthly allowance are agreed in the service order, and anything already broken is flagged in writing — absorbed into the first cycles where it is ordinary cleanup, or scoped as a project where it is structural.
Stale member accounts and guests are identified against the thresholds, confirmed with owners, and disabled or removed with your approval. Application credentials nearing expiry are flagged to their owners on the agreed lead time; unused credentials and abandoned applications are recommended for removal. New consents and permission grants are reviewed.
Role and PIM assignments are compared with the approved minimum and corrected with your approval. The live Conditional Access set is compared with the baseline; drift is reverted or recorded as an agreed change with an owner and an expiry. The baseline itself is updated deliberately when you approve a change, so it stays a living document rather than a stale snapshot.
Each quarter, the agreed review scopes run in Microsoft Entra access reviews: we configure the campaigns and their no-response outcome, brief the reviewers, chase completion through the review window, apply the results, and archive the decisions and completion evidence. Where your licensing includes Entra ID Governance, inactive-user and affiliation recommendations do part of the reviewers' thinking for them.
The monthly report closes each cycle: what was found, what was fixed, what was accepted and why, and what we recommend next. Quarterly, we add a short roadmap — governance features worth adopting, licensing gaps worth closing, and a plain statement when something has outgrown the monthly scope and needs a separately quoted project.
Prerequisites
Who does what
IT Partner
- Document the baseline and run the monthly hygiene, privileged-access, and Conditional Access drift cycles.
- Track application credentials against expiry and flag them to their owners on the agreed lead time.
- Configure, chase, apply, and archive the quarterly access-review campaigns.
- Execute approved hygiene changes within the monthly allowance and record every action.
- Deliver the monthly auditor-ready report and the quarterly roadmap.
- Escalate honestly: signals that look like compromise go to your incident path or MDR provider immediately, not into next month's report.
- Name honestly, and quote separately, any request that exceeds the monthly scope.
Your team
- Maintain the Microsoft Entra licensing that matches the agreed scope, and keep the named contact and reviewer pool current.
- Approve or decline the recommended disablements, removals, role changes, and Conditional Access corrections within the monthly cycle — the decisions are yours; we document and execute them.
- Tell us about leavers, reorganizations, mergers, and new applications early enough to plan.
- Ensure reviewers complete their quarterly reviews; agree the no-response outcome in advance.
- Own the vendor relationships for third-party applications whose credentials or permissions we flag.
- Review the monthly report and act on recommendations that require project work.
What's not included
Limitations & technical notes
Frequently asked questions
What is Managed Entra ID Identity Hygiene and Access Reviews?
A recurring monthly service in which IT Partner operates the identity hygiene of your existing Microsoft Entra ID tenant: stale user and guest cleanup, app registration secret and certificate expiry watch, privileged-role and PIM assignment review, Conditional Access drift checks against a documented baseline, enterprise-app consent review, quarterly access-review campaigns run end to end, and a monthly report written for auditors. It costs $3 per user per month with no long-term commitment.
Who is this service for?
Organizations of roughly 50 to 1,000 users that have already invested in Entra ID governance or Conditional Access — with us or with anyone — and have no identity engineer to keep it clean afterward. If your auditor's last evidence request took three weeks to answer, or your insurer's renewal asked about privileged-access reviews and the honest answer was 'we mean to', this service is the missing role.
What Entra licensing do we need?
It depends on the scope you want. Conditional Access needs Microsoft Entra ID P1, which Microsoft 365 Business Premium, E3, and E5 include. PIM and access reviews need Microsoft Entra ID P2 — included in Microsoft 365 E5 and EMS E5, or licensed standalone — for the users with eligible assignments, the approvers, and the reviewers. The Microsoft Entra ID Governance add-on or the Microsoft Entra Suite unlocks inactive-user recommendations, affiliation recommendations, multi-resource reviews, and lifecycle workflows. Microsoft also meters guest governance actions per governed guest per month through an Azure subscription. We verify all of this at onboarding, tell you exactly what your licensing supports, and quote any Microsoft costs before you buy anything.
We only have Business Premium. Is there still value?
Yes, with an honest boundary. Business Premium includes Entra ID P1, so the Conditional Access drift check, stale-account cleanup from sign-in activity, application credential watch, role review, and consent review all run in full. What P1 cannot do is formal access-review campaigns or PIM — those need P2. Many clients start the hygiene cycle on P1, and add P2 for the privileged users and reviewers when they want the quarterly review evidence; we will tell you at onboarding which report sections your licensing can and cannot fill.
How is this different from Microsoft Entra Administrator on Demand?
Direction and rhythm. Administrator on Demand is reactive and hourly: you raise a task, we do it. This service is proactive and fixed: a scheduled monthly cycle that finds the problems nobody raised, on a per-user fee, producing evidence as it goes. Most clients keep both — the hourly service for the unexpected, this one for the discipline — and the monthly cycle tends to shrink the number of unexpected tasks.
How is this different from MDR or Sentinel monitoring?
MDR and Sentinel monitoring watch for active attacks and respond, around the clock. This service shrinks what those attacks can use: fewer dormant accounts to hijack, fewer forgotten secrets to steal, fewer standing admins to phish, fewer Conditional Access gaps to slip through. One is detection and response; the other is hygiene. They are complementary and deliberately non-overlapping — if our monthly cycle turns up something that looks like compromise rather than entropy, it goes to your incident path or MDR provider immediately, not into next month's report.
What does a quarterly access-review cycle actually involve?
For each scope agreed at onboarding — group and team memberships, application assignments, privileged roles, guests — we configure the campaign in Microsoft Entra access reviews with the no-response outcome you chose, brief the reviewers on what they are deciding and why, chase completion through the review window, apply the results (removals happen), and archive the decisions and completion records as evidence. Where your licensing includes Entra ID Governance, inactive-user and affiliation recommendations are turned on so reviewers get a suggested answer instead of a blank list.
What happens with stale accounts and guests?
Each month we identify member users and guests past the inactivity thresholds recorded in your service order, confirm with their owners or your contact, and disable or remove them with your approval — recording each decision, including the decision to keep an account. Disabling comes before deleting, so a wrongly flagged account is a one-minute reversal. Microsoft's guest governance metering applies to guests governed through access reviews and is a Microsoft cost we name at onboarding.
What is the app credential watch, and why does it matter?
Every app registration and service principal in your tenant can hold client secrets and certificates, and each one has an expiry — or does not, which is worse. Expired credentials break integrations at inconvenient hours; unexpired, unused ones are standing credentials waiting to be found. We track them all against expiry, flag renewals to their owners on the agreed lead time, and recommend removing credentials and applications nobody uses, using Microsoft Entra's recommendations where your licensing surfaces them and our own inventory where it does not.
Do you decide who loses access?
No. We find, recommend, and document; you decide; we execute and record. Access decisions are business decisions, and an auditor wants to see that the business made them — which is why every action in the monthly report carries an approver, not just a timestamp.
What is in the monthly report?
Accounts disabled or removed with their approvals, credentials renewed or retired, the privileged-access state against the approved minimum, Conditional Access drift found and how it was resolved, consents reviewed, quarterly review status and evidence references, and open recommendations with owners. It is written so an auditor's evidence request, a cyber-insurance questionnaire, and a leadership update can all be answered from the same document without rework.
What access do you need to our tenant?
Least-privilege GDAP that you approve — Microsoft's granular, time-bound partner access model. Our default request is Microsoft's standard starter relationship; anything more is requested per task and expires. We never ask for standing Global Administrator, and our default access policy is published so you can compare it against what we actually request.
Our tenant is a mess. Can you still take it on?
Usually, yes — the onboarding baseline exists to find out. We document what is there, flag what is broken or risky in writing, and absorb ordinary cleanup into the first monthly cycles. If the baseline reveals structural problems — no Conditional Access at all, hundreds of stale guests, a decade of app registrations — we say so plainly and quote the cleanup or the implementation as a project, so the monthly fee stays honest about what it covers.
How does billing work, and can we stop?
Monthly, at $3 per user in the agreed scope, reconciled monthly as headcount changes, with no long-term contract: stop any month, and all we ask is payment of previously approved invoices. Everything the service produced stays yours — the baseline, the reports, the archived review evidence, and every cleanup already done. No lock-in in either direction is a published IT Partner term, not a promotional line.
How quickly can the service start?
The first monthly cycle is the onboarding: GDAP access, the baseline document, the service order with thresholds, review scopes, and allowance, and the first hygiene pass. From the second cycle the service is in steady state, and the first quarterly review campaign runs on the cadence agreed at onboarding. If we performed your governance or Conditional Access implementation, onboarding is mostly a handover to ourselves and the baseline already exists in draft.