3.4.1. Microsoft Entra ID Governance
💡 First Principle: Entra ID Governance is the umbrella capability set for managing the full identity lifecycle — from the moment access is requested, through periodic verification, to eventual removal — so that access doesn't just get granted once and forgotten.
Entitlement management and access packages are core to this: instead of an admin manually granting a new hire access to a dozen individual resources, an access package bundles everything a role typically needs into one requestable, and often time-bound or approval-gated, package. This turns access provisioning (and later, deprovisioning) into a governed, auditable workflow rather than ad hoc individual grants.
⚠️ Exam Trap: Entra ID Governance is the umbrella term covering access reviews, entitlement management, and PIM together — the exam may test whether you recognize a specific scenario as belonging under this broader governance capability rather than treating it as an unrelated standalone feature.
Reflection Question: Why does bundling related resources into a single requestable access package reduce the risk of over-provisioning compared to granting each resource individually?