| # | Action | Notes |
|---|---|---|
| 1 | Open a browser and navigate to the Entra Admin Centre | entra.microsoft.com |
| 2 | Sign in with your PRV (privileged) account | Never use your standard user account for admin tasks |
| 3 | Activate Identity Governance Administrator via PIM | If not already elevated — navigate to PIM → My Roles → Activate |
| # | Action | Notes |
|---|---|---|
| 1 | In the Entra Admin Centre left navigation, select ID Governance | |
| 2 | Select Entitlement Management | |
| 3 | Click Access Packages | You will see a list of all configured access packages |
| # | Action | Notes |
|---|---|---|
| 1 | Click the name of the access package assigned to the target guest user(s) | Opens the package's detail view |
| 2 | Click Assignments in the left panel | Displays all current users assigned to this package |
| 3 | Identify the guest user(s) you need to mark as governed | Guest accounts show as user#EXT#@domain |
| # | Action | Notes |
|---|---|---|
| 1 | Tick the checkbox next to the guest user(s) you want to govern | You can select multiple users at once |
| 2 | Click "Mark guest as governed" in the toolbar | Button appears once at least one user is selected |
| 3 | Confirm the action when prompted |
| # | Action | Notes |
|---|---|---|
| 1 | Ensure you are signed into the Entra Admin Centre with your PRV account (Identity Governance Administrator) | Same session from Section A, or re-elevate |
| 2 | Navigate to ID Governance → Entitlement Management | |
| 3 | Click Control configurations | Also labelled "Settings" in some portal versions |
| # | Action | Notes |
|---|---|---|
| 1 | Locate the "Lifecycle of external users" section | |
| 2 | Click "View settings" | Opens the configuration panel for external user lifecycle behaviour |
| 3 | Review the current settings before making any changes | Note current values for change management records |
Available Lifecycle Settings:
| # | Action | Notes |
|---|---|---|
| 1 | Amend the lifecycle settings as required | Block sign-in, remove external user, days before removal |
| 2 | Click Save | Changes take effect immediately for all governed guests |
| 3 | Record the changes in your change management ticket | Note previous values and new values for audit trail |