
User-Centric Access Reviews (UAR) in Entra ID Governance are now generally available. Reviewers see all of a user's access — groups, apps and access packages — in a single unified view. How to configure it, what it costs, and why NIS2 compliance demands exactly this.
Who actually has access to what? That question is harder to answer in practice than it appears. Users accumulate access to groups, applications, and documents over time, and those permissions build up. After a project handover, a role change, or an extended leave of absence, the original access rights remain while the need for them has long since disappeared. This pattern is called access sprawl, and it is one of the slow-burning risk factors in any organisation with more than a handful of employees.
The solution is periodic access reviews. In Entra ID Governance, this functionality has existed for years, but execution was fragmented: one review per group, one review per application, each its own separate cycle. Anyone working through five reviews for a single user quickly lost the overview and the motivation. In September 2026, Microsoft changes that: User-Centric Access Review (UAR) is now generally available.
The name explains it: the review centres on the user, not on the system. Until now, an IT administrator or business owner who wanted to assess a colleague's access worked through multiple separate screens: first the group members of Group A, then the assignments of Application B, then the active access packages. UAR brings that together in one catalogue view per user.
A reviewer opens one screen and sees: which Entra ID groups the user is a member of, which applications are assigned, and which access packages are active. Per item, the reviewer makes a decision — keep, remove, or provide justification. Everything in one workflow, one audit trail. The time investment per user drops significantly.
Catalogues are a core concept in Entra ID Governance. A catalogue is a logical container of related resources: groups, applications, and access packages belonging to a particular purpose or team. Think of a 'Finance' catalogue with all financial apps and security groups, or a 'Projects' catalogue for temporary collaboration resources.
By organising resources in catalogues, you set up governance per department or domain. UAR works at catalogue level: the reviewer sees a user's complete access within a catalogue in a single overview. This means you can scope governance tightly — a finance manager reviews only the Finance catalogue, a project owner only the Projects catalogue — without anyone seeing more than necessary.
An extension that adds significant practical value: UAR also supports so-called disconnected apps. Connected apps are applications directly linked to Entra ID via SAML, OIDC, or app provisioning. Disconnected apps — sometimes called 'bring-your-own-data' resources — are applications not integrated through Entra, but tracked manually as an access resource.
This matters for most organisations. Microsoft 365 apps are neatly connected, but an older CRM, a supplier portal, or a line-of-business application often is not. With UAR, you include those disconnected resources in the same review cycle without the application itself first needing to integrate with Entra. You enter the access data manually, and UAR treats it as an equivalent resource in the review overview.
Alongside the UAR release, Microsoft brings a smaller but useful improvement: cloning of Lifecycle Workflows. Lifecycle Workflows automate the steps during employee onboarding, transitions, and offboarding. For new staff: create accounts, grant access, send a welcome email. On termination: disable accounts, revoke access, notify the manager.
With the new cloning option, you no longer need to rebuild an existing workflow from scratch when you need a variant. Clone the onboarding workflow for department A, adjust the specific steps for department B, and save. For IT teams managing multiple onboarding variants — for example per role, per location, or per contract type — this saves considerable manual effort.
Access reviews are not optional exercises. The NIS2 directive, mandatory for many organisations in the Netherlands, requires periodic verification that access rights are still justified. ISO 27001 states the same in control A.9. Cyber insurers are increasingly asking for evidence of active access governance as a condition for coverage or lower premiums.
The problem has always been practicality. An access review that costs an administrator two hours per employee gets postponed or executed superficially. UAR concretely lowers that threshold: all access in one screen, one click per decision, one audit trail as evidence. For organisations that must demonstrate active access governance, this is no longer an abstract promise.
UAR requires a Microsoft Entra ID Governance or Microsoft Entra Suite licence. Entra ID Governance is available as an add-on to Entra ID P2, costing approximately seven euros per user per month. Entra Suite bundles access governance, identity protection, Global Secure Access, and Verified ID in a single licence.
For organisations with only Entra P1 or P2, UAR means an additional licensing layer. The advice is to first determine which user groups are in scope for access reviews: typically privileged users, employees with access to sensitive data, and contractors with temporary access. Licence the Governance layer for that group, not automatically for the entire organisation.
The setup process runs in five steps. First, determine which catalogues are relevant. Which resource groups do you want to manage centrally and review periodically? Structure them per department, per project, or per application domain.
Second, add resources to the catalogue. Groups, apps, and access packages are linked via the Entra portal. Disconnected resources are entered manually with their associated access data and owners.
Third, create an access review in Entra ID Governance and choose 'User-Centric' as the review type. Set the frequency (monthly, quarterly, annually), who the reviewer is (manager, resource owner, or specific individuals), and what happens if there is no response within the review period.
Fourth, reviewers receive an email with a task link and open one screen per user. Per resource they choose: keep, remove, or provide justification. All decisions are recorded in the audit log.
Fifth, after the review period closes, selected removals are applied automatically — or presented to an administrator for confirmation, depending on your setting. The result is traceable and exportable as compliance evidence.
Start with one catalogue and one user group. The perfect access review does not exist; a limited and repeatable review is always better than a comprehensive one that never gets executed. Involve a business owner as reviewer — they typically know better than the IT team whether access is still justified.
Actively document the results. During an external audit or a cyber insurance assessment, the Entra ID Governance audit log is your evidence. UAR makes that evidence considerably easier to produce than a manually maintained spreadsheet. Want help setting up Entra ID Governance, building catalogues, or conducting a first access review? Contact Zarioh for a no-obligation conversation.
Zarioh Digital Solutions
IT specialists from Utrecht, the Netherlands. We help businesses with Microsoft 365, AI agents, hosting and telephony — and share what we learn in practice. Follow us on LinkedIn

Security

Security

Security