Loading...

Introducing Machine Learning based recommendations in Azure AD Access reviews

Introducing Machine Learning based recommendations in Azure AD Access reviews

Many of you are already using Azure AD access reviews to govern access of your employees, guests, and workload identities to sensitive resources. Over the years, one of the top requests from our customers is to make the review process easier so that reviewers can make quicker and more accurate decisions. Today, I’m excited to share that we’ve vastly enhanced our recommendations in access reviews using sophisticated machine learning models that determine users’ affiliation to the group being reviewed, based on the organization’s reporting structure. This additional recommendation makes the entire process much easier for reviewers, thereby increasing reviewer efficiency, reducing attestation fatigue, and ensuring that your sensitive resources are secure. 

 

Microsoft Entra Identity Governance is helping customers move beyond the traditional Identity governance approach of managing access, thereby reducing cost and increasing productivity.  

 

SHDriggers_0-1669156249840.png

 

 

What is User-to-Group Affiliation? 

The User-to-Group Affiliation recommendation compares users’ relative affiliation with other users in the group, based on the organization’s reporting structure. Our machine learning based scoring mechanism identifies the distance between the users in an organizational hierarchy to detect those users who are very distant from other users in the group i.e., have "low affiliation" and our system then provides a ‘Deny’ recommendation. 

 

Enabling this recommendation in access reviews is a one-click process 

Switching on this recommendation while creating access reviews is easy – select the decision helper “User-to-Group Affiliation” in settings during the access review creation experience and the rest is the same as any other access review. 

 

SHDriggers_1-1669156249845.png

 

 

Recommendations for Reviewers of access reviews: 

The reviewers of access reviews see the recommendations if a user has “Low Affiliation” with other users within the group along with our existing Inactive user recommendation. The reviewer can accept the recommendations by clicking on “Accept Recommendations” or can manually “Accept” or “Deny” access based on the recommendations, thereby helping the reviewer make a quick decision. 

 

SHDriggers_2-1669156249848.png

 

 

Additional details to enhance access review decision making: 

A reviewer who needs additional information to make an access decision can click on “Details” and will get an option to “Accept” or “Deny” access. If the reviewer selects the recommended option, the decision can be submitted directly, whereas, if the reviewer goes against the recommended option, a reason is required before the decision is submitted.  

 

SHDriggers_3-1669156249850.png

 

 

Try it now by navigating to the Entra Identity Governance and enabling access reviews on a group. 

 

Resources and Feedback: 

For more information, please visit User-to-Group Affiliation recommendation for Azure AD Access reviews 

As we work on simplifying identity governance processes through analytics, we want to hear from you! Please leave your comments down below or reach out to us on aka.ms/AzureADFeedback.  

 

Joseph Dadzie, Partner Director of Product Management 

Twitter: @joe_dadzie 

 

 

Learn more about Microsoft identity: 

Published on:

Learn more
Azure Active Directory Identity Blog articles
Azure Active Directory Identity Blog articles

Azure Active Directory Identity Blog articles

Share post:

Related posts

Sync identities from Rippling to Microsoft Entra ID

Today, we’re thrilled to announce that customers using Rippling HCM can now automatically provision users to on-premises Active Directory and ...

1 year ago

Microsoft Entra ID Governance for government

I’m pleased to announce that as of November 1, 2024, Microsoft Entra ID Governance is available for federal agencies, state and local governme...

1 year ago

Update to security defaults

As part of the Secure Future Initiative, we’ve evolved our security approach to align with three security principles: secure by design, secure...

1 year ago

Meet Microsoft Entra at Ignite 2024: November 18-22

Microsoft Ignite is just around the corner, taking place from Monday, November 18, 2024 through Friday, November 22, 2024, in Chicago, Illinoi...

1 year ago

Manage Microsoft Entra ID role assignments with Microsoft Entra ID Governance

I’m excited to announce that we now support Microsoft Entra role assignments in Microsoft Entra ID Governance's Entitlement Management feature...

1 year ago

The latest enhancements in Microsoft Authenticator

Hi folks,   I'm thrilled to announce three major Microsoft Entra ID advancements that will help you protect your users with phishing-resi...

1 year ago

Microsoft Security announcements and demos at Authenticate 2024

The Microsoft Security team is excited to connect with you next week at Authenticate 2024 Conference, taking place October 14 to 16 in Carlsba...

1 year ago

What's new in Microsoft Entra - September 2024

We’re excited to announce the general availability of Microsoft Entra Suite—one of the industry’s most comprehensive secure access solutions f...

1 year ago

Explore the key benefits of Microsoft Entra Private Access

The traditional network security models are becoming increasingly ineffective in a world where remote work and cloud services are the norm. Co...

1 year ago

Join us at the Microsoft Entra Suite Showcase!

This fall, we are bringing the Microsoft Entra Suite Showcase to cities worldwide. Join us to explore how our latest advancements in secure id...

1 year ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.