M365 Changelog: Enforce policy approval settings for admins

Summary

Starting August 26, 2024, changes to Entitlement Management will enforce approval settings for Global Administrators and Identity Governance Administrators, preventing them from bypassing access package policy approvals. No action is needed from your organization as this is an automatic update.

MC847883 – Microsoft is making some changes to access package approval settings in Entitlement Management. We’re introducing a new configuration that will prevent Global Administrators and Identity Governance Administrators from bypassing approval settings configured in access package policies.

When this will happen:

Starting August 26, 2024

How this affects your organization:

You are receiving this message because our reporting indicates that your organization has one or more users with active access package assignments.

If a Global Administrator or Identity Governance Administrator attempts to directly assign a user to a package and selects a policy with an approval setting that they do not meet, then the request will need to be approved by a designated approver.

What you need to do to prepare:

No action is required on your end. This change is being rolled out to all customers and is in accordance with Microsoft Entra ID Governance best practices.

For additional information, click here to learn more.