Cross-product topic

Governance

A cross-product view of Microsoft Entra changes related to Governance.

Latest Governance changes

Automatic Governance Relationships

Governance

When you create a new Microsoft Entra tenant using the secure add-on tenant creation feature, you're prompted to select an existing subscription and resource group from your billing account. When you create your new tenant, Microsoft generates a new billing a…

Create a configuration monitor

Governance

Learn how to create a configuration monitor in Microsoft Entra Tenant Governance to evaluate a tenant against a configuration baseline and report drift

Create a governed workforce tenant

Governance

Learn how to securely create a governed Microsoft Entra workforce tenant and establish governance from your home tenant.

Create configuration snapshots

Governance

Learn how to create configuration snapshots in Microsoft Entra Tenant Governance to capture tenant configuration for baselines or audit evidence

Cross-tenant delegated administration

Governance

Learn about cross-tenant delegated administration and the GDAP-based permission model for managing tenants in Microsoft Entra.

Customize Workflow Email

Governance

In the message body, you can customize the email text to personalize it for each recipient. You can optionally include built-in user attributes, custom security attributes, directory extensions, and on-premises extension attributes by embedding them in the te…

Governance Policy Templates

Governance

- Manage the governed tenant without needing a local or business-to-business (B2B) account in that tenant.

Interpret tenant discovery data

Governance

Learn how to interpret tenant discovery data, signals, and metrics in Microsoft Entra Tenant Governance to assess related tenants

Lifecycle Workflow Tasks

Governance

With customized emails, you're able to include dynamic attributes within the subject and body to personalize these emails. You can include built-in user attributes, custom security attributes, directory extensions, and on-premises extension attributes. The li…

Related tenants in Tenant Governance

Governance

Learn how Microsoft Entra Tenant Governance discovers related tenants through identity, application, and billing signals across your organization

Lifecycle Workflow Inactive Users

Governance

1. Under the **Days of inactivity**, enter the number of days you want the trigger to run for if exceeded, and then select **Next**.

Lifecycle Workflow Templates

Governance

The **Pre-Offboard inactive users** template is designed to configure tasks that must be completed before offboarding inactive users.

Governance Policy Templates

Governance

Learn about governance policy templates and how to use them to enforce consistent governance across tenants in Microsoft Entra

Groups Lifecycle

Governance

For more information on Microsoft Entra groups, see:

Entitlement Management Access Package Assignments

Governance

In entitlement management, you can see who is assigned to access packages, their policy, status, and identity lifecycle (preview). If an access package has an appropriate policy, you can also directly assign identities to an access package. This article descr…

Entitlement Management Access Package Manage Lifecycle

Governance

Guest users that already existed in your tenant by being invited are ungoverned. After an ungoverned guest that requests access packages lose their last access package assignment, they'll remain in the tenant indefinitely. If there are guests that have an acc…

Entitlement Management Delegate

Governance

To determine the least privileged role for a task, you can also reference [Least privileged roles by task in Microsoft Entra ID](../identity/role-based-access-control/delegate-by-task.md#entitlement-management-least-privileged-roles).

Migrate Copilot Studio Agents To Agent Id

Governance

Learn how to recreate Microsoft Copilot Studio agents with Microsoft Entra Agent ID for enhanced governance and security. No in-place migration path exists today.

What's new in Microsoft Entra Agent ID

Governance

Learn about new features and updates in Microsoft Entra Agent ID at general availability, including non-Microsoft integrations, migration guides, and enterprise governance.

Account Discovery

Governance

Learn how to use Account Discovery to find and categorize existing user accounts in target applications, match them to Microsoft Entra ID users, and prepare for provisioning governance.

Agent Access Packages

Governance

This article explains how access packages provide governance for agent identity access to resources.

Groups Sensitivity Labels

Governance

Learn how to apply sensitivity labels to cloud security groups in Microsoft Entra ID for consistent classification and governance.

What's new in Microsoft Entra Agent ID

Governance

Learn about new features and updates in Microsoft Entra Agent ID at general availability, including non-Microsoft integrations, migration guides, and enterprise governance.

Licensing Governance

Governance

|[EM - Agents and service principals assigned to access packages](~/id-governance/entitlement-management-access-package-create.md#allow-users-service-principals-and-agent-identities-in-your-directory-to-request-the-access-package)|||||| :white_check_mark: |

Migrate Copilot Studio agents to Agent ID

Governance

Learn how to recreate Microsoft Copilot Studio agents with Microsoft Entra Agent ID for enhanced governance and security. No in-place migration path exists today.

Migrate From Sap Idm

Governance

In SAP IDM, the Identity Store represents identity data through entry types such as `MX_PERSON`, `MX_ROLE`, or `MX_PRIVILEGE`.

Lifecycle Workflow Tasks

Governance

Lifecycle Workflows allow you to automate the updating of user attributes for users in your organization. You're able to customize the task name and description for this task in the Microsoft Entra admin center.

What's new in Microsoft Entra Agent ID

Governance

Learn about new features and updates in Microsoft Entra Agent ID at general availability, including third-party integrations, migration guides, and enterprise governance.

Create a monitor (preview)

Governance

Learn how to create and configure a tenant configuration monitor in Microsoft Entra Tenant Governance to track configuration drift

Enable tenant discovery (preview)

Governance

Learn how to enable tenant discovery in Microsoft Entra Tenant Governance to identify related tenants across your organization

Pim How To Add Role To User

Governance

1. Select a role you want to assign, select a member you want to assign to the role, and then select **Next**.

Update or delete a monitor (preview)

Governance

Learn how to update or delete a configuration monitor in Microsoft Entra Tenant Governance when baselines or requirements change

Microsoft Entra Id Governance Licensing For Guest Users

Governance

| Access Reviews | [Access Review – inactive users](../identity/users/clean-up-stale-guest-accounts.md#monitor-guest-accounts-at-scale-with-inactive-guest-insights) | Bill when guest user is included in review.<br><br>**API**<br> https://graph.microsoft.com/v…

Approve activation requests for group members and owners

Governance

With Privileged Identity Management (PIM) and Microsoft Entra ID, you can configure activation of group membership and ownership to require approval. You can also choose users or groups from your Microsoft Entra organization as delegated approvers.

Assign Microsoft Entra roles in Privileged Identity Management

Governance

With Microsoft Entra ID, a Global Administrator can make **permanent** Microsoft Entra admin role assignments. These role assignments can be created using the [Microsoft Entra admin center](~/identity/role-based-access-control/permissions-reference.md) or usi…

Bring groups into Privileged Identity Management

Governance

In Microsoft Entra ID, you can use Privileged Identity Management (PIM) to manage just-in-time membership in the group or just-in-time ownership of the group. Use groups to provide access to Microsoft Entra roles, Azure roles, and various other scenarios. To…

Email notifications in PIM

Governance

Privileged Identity Management (PIM) lets you know when important events occur in your Microsoft Entra organization, such as when a role is assigned or activated. Privileged Identity Management keeps you informed by sending you and other participants email no…

Extend or renew PIM for groups assignments

Governance

Privileged Identity Management (PIM) in Microsoft Entra ID provides controls to manage the access and assignment lifecycle for group membership and ownership. Administrators can assign start and end date-time properties for group membership and ownership. Whe…

Plan a Privileged Identity Management deployment

Governance

**Privileged Identity Management (PIM)** provides a time-based and approval-based role activation to mitigate the risks of excessive, unnecessary, or misused access permissions to important resources. These resources include resources in Microsoft Entra ID, A…

Roles you can't manage in Privileged Identity Management

Governance

You can manage just-in-time assignments to all [Microsoft Entra roles](~/identity/role-based-access-control/permissions-reference.md) and all [Azure roles](/azure/role-based-access-control/built-in-roles) using Privileged Identity Management (PIM) in Microsof…