Did you select the Role you wanted to review?
Access Reviews fail for Microsoft Entra Roles
Hi,
Can somebody clarify whether my understanding of the Access Reviews is correct?
We're creating access reviews for Entra Roles. It has the banner now about license requirements about features previously in preview changing but I don't think that should impact what I'm trying to do.
I've assigned one of our user's admin account with the Privileged Role Administrator role. I also given the account an E5 licence and I can see that Microsoft Entra ID P2 is enabled as part of it.
When the user tried setting up an access review using the steps below the Instance Status for the Access Review shows as Failed.
- Browse to Identity Governance > Privileged Identity Management.
- Select Microsoft Entra roles.
- Under Manage, select Access reviews, and then select New to create a new access review.
- Below are the settings to configure.
- Give it a meaningful name,
- Enter the start date and select Quarterly.
- Duration in days set to 21.
- Select the correct end date, should be 3 weeks after the start date.
- Users scope: All users and groups
- Inactive users only: Select False
- Assignment type: All active and eligible assignments
- Reviewers: Manager
- Upon completion : Enable
- Show Recommendations: Enable
- Require Reason on approval: Disabled
- Mail Notifications: Enable
- Reminders: Enable
- Mail Notifications: Enable
- Require Reason on approval: Disabled
- Show Recommendations: Enable
- Upon completion : Enable
- Reviewers: Manager
- Assignment type: All active and eligible assignments
- Inactive users only: Select False
- Users scope: All users and groups
- Select the correct end date, should be 3 weeks after the start date.
- Duration in days set to 21.
- Enter the start date and select Quarterly.
- Give it a meaningful name,
The Current Results are greyed out but if I go into Review History and click on the Failed Access review I can see results in there.
I've retried it with Global Admin but that also fails.
I think the account has the correct licence and I don't think it needs Microsoft Entra ID Governance for what we're trying to do.
How can I figure out what it's failing on?
I appreciate your time. Thanks