Additional Microsoft Entra services and features related to identity, access, and network security
Catalog Access Review Challenges
Ignoring the fact that you can review a group and attest to the members whose access is assigned through an access package, I expected a review of a catalog to require the reviewer to attest to the assignments for each access package.
Instead, it creates a review segment for each resource in the catalog and includes the external assignments that are not a result of the access package. It then allows the reviewer to revoke one or more of those individual assignments and invalidate the access package, leaving it in an inconsistent state.
Not only is that a potentially enormous amount of work, but it's also seriously flawed. Does anyone know if this will be addressed for the general release, or if that is perceived to be a valid process?