5.1. Entitlement Management
💡 First Principle: Access should be a product, not a favor. Entitlement management packages the resources a scenario needs (groups, apps, sites) into a requestable bundle with policy attached — who may ask, who approves, when it expires — so granting access stops being ad-hoc tickets and becomes a governed, self-service pipeline with lifecycle built in from the first day.
The cost of its absence is the access-sprawl story every auditor knows: new hires wait days while tickets bounce; project teams accumulate permissions nobody removes; partners keep access years after the contract ended. Entitlement management attacks all three at once — and it's an Entra ID Governance licensing feature (P2 covers a subset; full lifecycle features sit in the Governance add-on), a distinction stems occasionally probe.
⚠️ Common Misconception: Entitlement management and access reviews solve the same problem. Entitlement management governs how access is requested and granted (packages, policies, approvals, expiration); access reviews interrogate whether existing access is still justified. A package can embed reviews, but the exam tests them as distinct tools with distinct verbs.