Lab 24: Manage the lifecycle of external users in Microsoft Entra Identity Governance settings

Login type = Microsoft 365 admin

Lab scenario

You can select what happens when an external user, who was invited to your directory through an access package request being approved, no longer has any access package assignments. This can happen if the user relinquishes all their access package assignments, or their last access package assignment expires. By default, when an external user no longer has any access package assignments, they are blocked from signing in to your directory. After 30 days, their guest user account is removed from your directory.

Estimated time: 5 minutes

Exercise 1 - Microsoft Entra Identity Governance settings

Task 1 - Manage the lifecycle of external users in Microsoft Entra Identity Governance settings

  1. Sign in to Microsoft Entra admin center at https://entra.microsoft.com as your Global Administrator.

    Note: You may be prompted to complete Multi-Factor Authentication (MFA) during sign-in. Follow the prompts to configure or verify your authentication method before continuing.

  2. In the left navigation menu, expand the ID Governance, then select Entitlement management.

  3. On the **Identity Governance Getting Started** page, in the left navigation, under Entitlement management select Control configurations.
  4. In **Identity Governance Control configurations, locate **Lifecycle of external users, and then select View settings.

    Screen image displaying the Identity governance settings page with manage the lifecycle of external users highlighted.

  5. In the Lifecycle of external users pane, review the available settings for external users.

  6. To block external users from signing in after they lose their last access package assignment, select Block external user from signing in to directory.

    Note: If an external user is blocked from signing in, they cannot request additional access packages. Do not enable this setting if the user will need future access.

  7. To automatically remove external users after they lose their last access package assignment, select Remove external user.

    Note: Entitlement management only removes accounts that were invited through entitlement management. Also, note that a user will be blocked from signing in and removed from this directory even if that user was added to resources in this directory that were not access package assignments. If the guest was present in this directory prior to receiving access package assignments, they will remain. However, if the guest was invited through an access package assignment, and after being invited was also assigned to a OneDrive for Business or SharePoint Online site, they will still be removed.

  8. If you want to remove the guest user account in this directory, you can set the number of days before it is removed. If you want to remove the guest user account as soon as they lose their last assignment to any access packages, set Number of days before removing external user from directory to 0.

  9. If you’ve made any changes, select Save.

Exercise summary

In this exercise, you reviewed and configured the Identity Governance settings that control what happens to external users when their last access-package assignment ends. This exercise showed how Entitlement Management automates external-user lifecycle cleanup.