Entitlement Management Access Package Request Policy
In brief
The documentation now specifies that existing guest users can be directly assigned, but external users who are not yet in the directory cannot be invited through direct assignment when access is limited to administrator direct assignments.
What Entra admins need to know
Review this guidance when assigning external users under the “None (administrator direct assignments only)” policy.
This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.

After you create the access package, you can directly assign specific internal andusers, including guest users who are already in the directory. However, if **Who can get access** is set to **None (administrator direct assignments only)**, an external user who isn't yet in your directory can't be invited through the assignment. To invite an external user through an access package assignment, use a policy that allows users not in your directory. The external user must be within the scope of the policy, such as being part of a configured connected organization in scope or being allowed by **All users (All connected organizations + any external user)**. If you don't want external users to request the access package. If you specify an external user, a guest user account is created in your directory.package, leave all options under **Who can request access** unchecked except for **Admin**. For information about directly assigning a user, see [View, add, and remove assignments for an access package](entitlement-management-access-package-assignments.md).
- Skip to the Who can request access section.
@@ -147,7 +147,7 @@ Follow these steps if you want to bypass access requests and allow administrator  - After you create the access package, you can directly assign specific internal and external users to the access package. If you specify an external user, a guest user account is created in your directory. For information about directly assigning a user, see [View, add, and remove assignments for an access package](entitlement-management-access-package-assignments.md).+ After you create the access package, you can directly assign specific users, including guest users who are already in the directory. However, if **Who can get access** is set to **None (administrator direct assignments only)**, an external user who isn't yet in your directory can't be invited through the assignment. To invite an external user through an access package assignment, use a policy that allows users not in your directory. The external user must be within the scope of the policy, such as being part of a configured connected organization in scope or being allowed by **All users (All connected organizations + any external user)**. If you don't want external users to request the access package, leave all options under **Who can request access** unchecked except for **Admin**. For information about directly assigning a user, see [View, add, and remove assignments for an access package](entitlement-management-access-package-assignments.md). 1. Skip to the [Who can request access](#who-can-request-access) section. 