GOV-06: Entitlement Management
Frequently asked questions about implementing and managing the GOV-06 security control in Microsoft 365 and Entra ID.
QWhat is GOV-06 (Entitlement Management)?▼
GOV-06 is a security control that without structured access provisioning, users accumulate permissions over time. entitlement management bundles resources into governed access packages with approval workflows and automatic expiration. It requires that access packages are configured for structured provisioning and approval workflows are defined for sensitive resources, access packages include expiration policies.
QWhy is Entitlement Management important for Microsoft 365 security?▼
Without structured access provisioning, users accumulate permissions over time. Entitlement management bundles resources into governed access packages with approval workflows and automatic expiration.
QHow do I implement GOV-06 in my tenant?▼
GOV-06 requires manual implementation. Requires P2 license (Identity Governance)
QWhat license do I need for GOV-06?▼
This control requires Azure AD Premium P2 (included in Microsoft 365 E5) or standalone P2.
QWhich security baseline includes GOV-06?▼
GOV-06 is included in the Enhanced Security baseline (Level 2). This level adds stricter controls for security-conscious organizations.
5
Questions
1
Related Controls
—
Categorized
Related Resources
Still have questions?
Our security experts are here to help. Start a free trial and get personalized guidance for your Microsoft 365 environment.
Start Free Trial