Houses of Parliament Restoration & Renewal
External IdAM

Access Package Management

Step-by-step guide for manually assigning Entra ID Access Packages to invited external users following CTC clearance.

Koz Georgiou 27 Mar 2026 v1.0
Progress
0 / 10

Overview

This guide covers how to assign access packages to invited users in Microsoft Entra ID. Due to Counter Terrorism Check (CTC) clearance requirements for external users, manual assignment has been adopted as the most appropriate approach to align with business security needs. Tick off each step as you complete it — click any card to expand the explanation.

1
Assigning an Access Package

Follow each step sequentially. Click the expand arrow to reveal the reasoning behind each action.

Step 1
Sign in to the Entra Admin Centre
Why this matters
A privileged account with the Identity Governance Administrator role is the minimum permission required to manage entitlement resources. Using a PRV account ensures the action is traceable and follows least-privilege principles.
Step 2
Navigate to Catalogs
Why this matters
Catalogs are containers that group related access packages and their resources together. This navigation takes you to the governance hub where all entitlement catalogues are centrally managed.
Step 3
Open the "External Guest Roles" Catalog
Why this matters
This is the dedicated catalog for external (guest) user access. Separating external roles into their own catalog enforces clear boundaries between internal and external entitlements and simplifies auditing.
Step 4
Select the Access Package
Why this matters
Access packages bundle specific resource roles (e.g. SharePoint sites, Teams, security groups) into a single assignable unit. Selecting the correct package ensures the user receives exactly the permissions needed for their engagement.
Step 5
Start a New Assignment
Why this matters
The Assignments blade shows all current, expired, and pending assignments for this package. Creating a new assignment here triggers the structured form that enforces policy compliance (approval, time-bounding, justification).
Step 6
Select Policy & Directory Scope
  • Select policy — choose Initial Policy
  • Scope — select Identities in my directory
Why this matters
The policy defines the approval workflow, access duration rules, and review cadence. "Identities in my directory" scopes the search to users who have already been invited as guests in Entra ID, ensuring only CTC-cleared individuals can be found and assigned.
Step 7
Search and Add Identities
Why this matters
This is the manual selection step that replaces self-service. By hand-picking users, the administrator ensures that only individuals who have completed CTC clearance receive access — preventing premature or unauthorized provisioning.
Step 8
Configure Assignment Settings
  • Bypass approval — set to No
  • Assignment starts on — enter the start date & time
  • Assignment ends on — enter the end date & time
Why this matters
Keeping approval active ensures a second pair of eyes reviews the assignment. Time-bounding access is a core Zero Trust principle — it prevents indefinite "standing access" and ensures external permissions are automatically revoked when the engagement ends.
Step 9
Provide Business Justification
Why this matters
The justification creates an audit trail. It records the business reason for granting external access and is referenced during access reviews, compliance audits, and any future incident investigations.
Step 10
Submit the Assignment
Why this matters
Once submitted, Entra ID will process the assignment — provisioning the bundled resource roles to each selected user. If approval is required, the designated approver will be notified before access is granted.

All Steps Complete

You've successfully walked through the entire access package assignment process.