Mar 05 2020
08:55 AM
- last edited on
Jan 14 2022
04:45 PM
by
TechCommunityAP
Mar 05 2020
08:55 AM
- last edited on
Jan 14 2022
04:45 PM
by
TechCommunityAP
Right now, we are collaborating with external users using B2B functionalities. These external users are automatically added to our Azure AD Directory when they accept and register thru MFA.
Now we want to set up expiration on these external users (guest user lifecycle) that automatically removes these guest users from our Azure AD directory after X days. Otherwise the list of external users will continue to grow with time.
Any help appreciated!
Mar 05 2020 02:02 PM
@Jonathan Nunez , hope you are well?
I think you would need to look at identity governance within Azure AAD.
Specifically around Access Packages and Access Reviews.
This will require AAD P2 licencing and possibly E5.
Best,
Steve
Mar 06 2020 10:54 AM
Mar 07 2020 02:05 AM
Solution
I think you can find some information to your question here:
https://docs.microsoft.com/en-us/azure/active-directory/governance/create-access-review
Oct 06 2021 07:41 AM
Aug 18 2022 02:16 AM - edited Aug 18 2022 02:18 AM
There use cases Access Reviews is suboptimal, we highly appreciate an option to time limited guest user accounts in Azure (for example for test purposes in Azure, Company Users want Guest Accounts. And we all know it, it will happen that Users stay on the Guest User becasue there no compliant device restrictions etc.! Aslong we cant limit them in a timly manner there is no option for us). Access Reviews etc are not granular enough for this scenario.
May 02 2023 04:22 AM
Adding an Expiration Date for Azure AD Guest Accounts
Microsoft has long been asked to support guest account expiration, just like the functionality available for on-premises Active Directory accounts. Engineering priorities have not allowed the developers to work on the feature, but it's possible to do the job with PowerShell as we explain here.
Mar 07 2020 02:05 AM
Solution
I think you can find some information to your question here:
https://docs.microsoft.com/en-us/azure/active-directory/governance/create-access-review