Houses of Parliament
Restoration & Renewal
External IdAM — Process Guide
Houses of Parliament Restoration & Renewal
External IdAM

External User Lifecycle Management

A step-by-step guide for aligning guest user lifecycles to their assigned Access Packages within R&R's external Identity and Access Management solution — ensuring access is automatically revoked and accounts are cleaned up when access packages expire.

Entra ID Governance · Entitlement Management · Access Packages Guest / B2B Users Entitlement Management Automated Lifecycle Entra ID Governance Version 1.0 Author: Koz Georgiou
Completion
0 / 7
Background & Purpose
What is External User Lifecycle Management?

When R&R invites external guest users (contractors, partners, suppliers) into the Microsoft 365 tenant via B2B Collaboration, those users are granted access through Access Packages — bundles of resources, group memberships, and application access with defined durations.

The lifecycle management process ensures that when a guest user's last active access package expires, two things happen automatically: their access to R&R resources is revoked, and their guest account is deleted from Entra ID after a 30-day grace period. Without this configuration, expired guest accounts would accumulate indefinitely — creating security vulnerabilities, licence waste, and compliance risk.

This guide covers two essential operations: marking individual guest users as governed by entitlement management, and configuring the tenant-wide lifecycle settings that control what happens when access packages expire.

Guest User Lifecycle Flow
Guest InvitedB2B Collaboration
Access Package
AssignedResources granted
Marked as
GovernedLifecycle linked
Last Package
ExpiresAccess revoked
Account DeletedAfter 30 days
🔐
Prerequisites & Required Permissions
Entra ID RoleIdentity Governance Administrator (minimum), activated via PIM using a PRV account
PortalEntra Admin Centre — entra.microsoft.com
Access PackagesAt least one access package must exist and be assigned to the target guest user(s)
Guest UsersThe external users must already be present in the tenant as B2B guest accounts
Section A — Mark Guest Users as Governed
1
Sign In with PRV Account & Elevate to Identity Governance Administrator
entra.microsoft.com
💡 Why is this step needed?
Identity Governance features — including entitlement management and lifecycle settings — are protected by role-based access control. Only users holding the Identity Governance Administrator role (or Global Admin) can modify access package assignments and lifecycle configurations. Using a PRV account and activating the role through PIM ensures just-in-time access with full audit logging, rather than standing administrative privileges.
#ActionNotes
1Open a browser and navigate to the Entra Admin Centreentra.microsoft.com
2Sign in with your PRV (privileged) accountNever use your standard user account for admin tasks
3Activate Identity Governance Administrator via PIMIf not already elevated — navigate to PIM → My Roles → Activate
ℹ Role Scope
The Identity Governance Administrator role grants access to entitlement management, access reviews, and Privileged Identity Management (for identity governance scenarios) — but does not grant full Global Admin privileges, following the principle of least privilege.
2
Navigate to Entitlement Management Access Packages
ID Governance
💡 Why is this step needed?
Access Packages are the core construct in Entra ID Entitlement Management. Each package bundles together resources, group memberships, and application access with defined assignment policies, approval workflows, and expiry periods. To mark a guest user as governed, you must navigate to the specific access package that has been assigned to them — because governance status is set at the access package assignment level, not at the user account level.
#ActionNotes
1In the Entra Admin Centre left navigation, select ID Governance
2Select Entitlement Management
3Click Access PackagesYou will see a list of all configured access packages
3
Open the Target Access Package & View Assignments
Entitlement Mgmt
💡 Why is this step needed?
Each access package has its own Assignments list — showing every user (internal or guest) who currently holds that package. You need to view this list to identify and select the specific guest user(s) whose lifecycle you want to link to entitlement management. A guest user may be assigned to multiple access packages, and the governed status applies per assignment — the account is only cleaned up when their last governed assignment expires.
#ActionNotes
1Click the name of the access package assigned to the target guest user(s)Opens the package's detail view
2Click Assignments in the left panelDisplays all current users assigned to this package
3Identify the guest user(s) you need to mark as governedGuest accounts show as user#EXT#@domain
4
Select Users & Click "Mark Guest as Governed"
Entitlement Mgmt
💡 Why is this step needed?
This is the critical action that links the guest user's account lifecycle to entitlement management. Once a guest is marked as governed, their account becomes subject to the tenant-wide lifecycle settings — meaning when their last access package assignment expires, the system will automatically block sign-in and then delete the guest account after the configured grace period (default: 30 days). Without marking a guest as governed, the account persists indefinitely — even after all access packages expire — creating orphaned accounts with no active business justification.
#ActionNotes
1Tick the checkbox next to the guest user(s) you want to governYou can select multiple users at once
2Click "Mark guest as governed" in the toolbarButton appears once at least one user is selected
3Confirm the action when prompted
⚠ Important — Scope of Governance
Marking a guest as governed applies to this specific access package assignment. If the same guest has assignments in other access packages, you should mark them as governed in each package. The account will only be cleaned up when all governed access package assignments have expired.
✔ What happens next?
The guest user is now subject to tenant-wide lifecycle settings. When their last governed access package expires, the system will: (1) block sign-in, (2) wait the configured grace period, and (3) delete the guest account automatically. No further manual action is required for that user's offboarding.
Section B — Tenant-Wide Lifecycle Settings
5
Navigate to Entitlement Management Control Configurations
ID Governance
💡 Why is this step needed?
The lifecycle settings that control what happens when a governed guest's last access package expires are configured at the tenant level — not per access package. This means a single configuration governs the behaviour for all external guest users across the entire R&R tenant. These settings define whether to block sign-in, delete the account, and the grace period before deletion. Getting these settings right is fundamental to automated external identity hygiene.
#ActionNotes
1Ensure you are signed into the Entra Admin Centre with your PRV account (Identity Governance Administrator)Same session from Section A, or re-elevate
2Navigate to ID Governance → Entitlement Management
3Click Control configurationsAlso labelled "Settings" in some portal versions
6
View Settings Under "Lifecycle of External Users"
Control Config
💡 Why is this step needed?
This section exposes the three key lifecycle behaviours for governed external users. Before making any changes, you should review the current settings to understand the existing configuration. These settings affect all governed guest users across the tenant, so changes should be made carefully and with approval from the Security and Identity team.
#ActionNotes
1Locate the "Lifecycle of external users" section
2Click "View settings"Opens the configuration panel for external user lifecycle behaviour
3Review the current settings before making any changesNote current values for change management records

Available Lifecycle Settings:

Block Sign-In
Whether to block the guest user from signing in once their last access package assignment has expired.
✦ Recommended: Enabled
Remove External User
Whether to automatically delete the guest account from Entra ID after the grace period has elapsed.
✦ Recommended: Enabled
Days Before Removal
The number of days after sign-in is blocked before the guest account is permanently deleted from the directory.
✦ R&R Default: 30 days
ℹ Tenant-Wide Impact
These settings apply to every governed guest user across the entire R&R tenant — not just individual access packages. Any change here affects the offboarding timeline for all external collaborators. Always obtain approval from the Head of Security before modifying these values.
7
Amend Settings & Save
Control Config
💡 Why is this step needed?
If the lifecycle settings need to be changed (for example, adjusting the grace period from 30 to 60 days, or enabling account deletion for the first time), this is where the change is applied. Once saved, the new settings take effect immediately for all governed guest users. This is the step that turns the entitlement management lifecycle from a passive record into an active, automated offboarding pipeline — ensuring R&R's external identity estate stays clean without requiring manual account reviews.
#ActionNotes
1Amend the lifecycle settings as requiredBlock sign-in, remove external user, days before removal
2Click SaveChanges take effect immediately for all governed guests
3Record the changes in your change management ticketNote previous values and new values for audit trail
⚠ Irreversible Impact Window
If a guest account is deleted after the grace period, it enters a soft-delete state for 30 days in Entra ID — during which it can be restored. After 30 days in soft-delete, the account is permanently purged. Ensure the grace period is sufficient for your business processes before reducing it.
✔ Configuration Complete
With governed users and tenant-wide lifecycle settings in place, the system will now automatically: block sign-in when the last access package expires, wait the configured grace period, then delete the guest account. No manual offboarding intervention is required — the external identity lifecycle is fully automated.