question

HRaja-6229 avatar image
0 Votes"
HRaja-6229 asked HRaja-6229 answered

Access Reviews for Privileged access groups (Preview)

I've created a Privileged access groups (Preview) with JIT enabled, I wanted to setup an Access Review as part of the group. I've gone through the steps and created it, but it showing blade? On the Audit logs, it shows completed. Any ideas? Is there any replication time?78311-revie.png


azure-active-directoryazure-ad-access-reviews
revie.png (35.0 KiB)
· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

After you go through the steps to create a "New access review", when you click on the notifications icon, does it give you any error or does it tell you that the access review was created successfully?

80795-image.png

If it shows as successful but still isn't showing in the pane, I would try logging out and logging in with a new browser session in incognito. There was an outage last week around the time when you posted this that may be related to the issue.

0 Votes 0 ·
image.png (25.9 KiB)
MarileeTurscak-MSFT avatar image
0 Votes"
MarileeTurscak-MSFT answered

If the access review was successful, you should get an alert in "Notifications" indicating the success. Then you can click into the alert itself to review the access review.

80844-image.png


80785-image.png

My review took a few minutes to show up in the blade after getting the notification that the review was created successfully.

80845-image.png

If you try the steps I gave in the comments and still have this issue, we can reach out to the product team and report this.


image.png (38.8 KiB)
image.png (117.0 KiB)
image.png (59.8 KiB)
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

HRaja-6229 avatar image
0 Votes"
HRaja-6229 answered

@MarileeTurscak Thanks for the responce, I did check the notification area and it was created but it didn't populated under Access Reviews under Groups > Activity Section > Access Reviews. I did use Privileged Role Administrator role, then I tried again with GA accout and it worked and Access Review was created. I'm just wondering if privileged access group settings (preview) - needs GA account, since only in Preview...

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

MarileeTurscak-MSFT avatar image
0 Votes"
MarileeTurscak-MSFT answered

That seems like that would be the reason. Based on the documentation's prerequisites you need to either be a Global Admin or a User Admin to create an Access Review.

That said, it's odd that you received an alert that the access review was successfully created if you didn't have the proper permissions to create it. If you can reproduce that and get a screenshot we can report this as a bug.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

HRaja-6229 avatar image
0 Votes"
HRaja-6229 answered HRaja-6229 edited

@MarileeTurscak OK, I know it worked with GA, but as you can see, I have both User Admin and Priv Role Admin and created the Group.
81489-active.png


Group Created
81514-newgrp.png


But when I go to Identity Goverence > Access Review, i've not able to select the Group?
81523-accessreviewgreyed.png



Hope the abvove makes sense?


active.png (9.7 KiB)
newgrp.png (17.4 KiB)
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

HRaja-6229 avatar image
0 Votes"
HRaja-6229 answered

@MarileeTurscak
This get even stranger, if i go another route, it does allow me to create the review, but doesnt show (like I did before)

81467-adgroup.png


I now can create it goiing via Groups and Access Reviews, but doest show>
81532-reviewsetup.png


81533-status.png



adgroup.png (37.1 KiB)
reviewsetup.png (25.7 KiB)
status.png (17.3 KiB)
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

HRaja-6229 avatar image
0 Votes"
HRaja-6229 answered

81469-noreview.png



noreview.png (32.6 KiB)
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.