{"id":7891,"date":"2022-03-03T08:01:37","date_gmt":"2022-03-03T16:01:37","guid":{"rendered":"https:\/\/www.microsoft.com\/insidetrack\/blog\/?p=7891"},"modified":"2026-04-07T06:42:34","modified_gmt":"2026-04-07T13:42:34","slug":"using-microsoft-azure-ad-entitlement-management-to-empower-microsoft-employees-and-protect-the-company","status":"publish","type":"post","link":"https:\/\/www.microsoft.com\/insidetrack\/blog\/using-microsoft-azure-ad-entitlement-management-to-empower-microsoft-employees-and-protect-the-company\/","title":{"rendered":"Using Microsoft Azure AD entitlement management to empower Microsoft employees and protect the company"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-7436 size-medium\" style=\"margin-top: 0px;\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2021\/10\/ms-digital-stories-300x122.png\" alt=\"Microsoft Digital stories\" width=\"300\" height=\"122\" srcset=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2021\/10\/ms-digital-stories-300x122.png 300w, https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2021\/10\/ms-digital-stories.png 400w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><em>We periodically update our stories, but we can\u2019t verify that they represent the full picture of our current situation at Microsoft. We leave them on the site so you can see what our thinking and experience was at the time.<\/em><\/p>\n<p>Microsoft is leveraging identity governance capabilities in Microsoft Azure AD entitlement management (EM) service to give its employees access to the files and resources they need to do their jobs while preventing them from accessing information they shouldn\u2019t see.<\/p>\n<p>Until recently, those kinds of protections had to be implemented by hand for each individual work project, which resulted in a patchwork experience for employees and managers alike and was a primary driver for support tickets.<\/p>\n<p>Today, this capability is enabled by Microsoft Azure Active Directory (Azure AD) EM, a transition that has centralized access provisioning and governance and has freed up resources for teams across the company.<\/p>\n<p>\u201cBy centralizing this functionality into an easy-to-use service, provisioning for a whole ecosystem can be linked to a single, role-based package,\u201d says Lionel Godolphin, a senior software engineer with the Microsoft Federal team in Microsoft Cloud and AI. \u201cBoth onboarding\u2014and equally importantly, offboarding\u2014are managed via a single policy with built-in approval processes.\u201d<\/p>\n<p>Integration and the implementation of seamless onboarding and offboarding experiences are challenges for every large and small organization. The way some of these integration services have been envisioned created unnatural barriers, which then require additional provisioning, access, and management. Enterprise organizations face a range of challenges when trying to implement and manage employee access, but Microsoft Azure AD entitlement management can be used to address these challenges.<\/p>\n<p>It\u2019s all about helping everyone involved in a project feel more confident in the work they\u2019re doing.<\/p>\n<p>\u201cIt\u2019s important for us to give our employees the freedom they need to do their job while also making sure they don\u2019t get into things that they shouldn\u2019t,\u201d Godolphin says. \u201cThis protects them, and it protects the company.\u201d<\/p>\n<blockquote class=\"quote-body\"><p>Imagine you\u2019re new at Microsoft. You\u2019ve got your team, and not only do you have to get access to the sales systems, but you need access to all the sub-systems. They are not only disparate, but there may be different prerequisites\u2014it is not just one provisioning. Jumping through all those hoops to get set up as a new employee is a terrible experience for anyone.<\/p>\n<p class=\"source\">\u2014Lionel Godolphin, senior software engineer, Microsoft Federal<\/p>\n<\/blockquote>\n<p>The Microsoft Federal engineering team worked to build out auto-provision access to resources employees on the larger Microsoft Federal team need to do their confidential work supporting government agencies. The solution they built helps the team streamline onboarding and offboarding of employees, transforming what was a manual process into a compliant, one-click experience.<\/p>\n<h2>Getting up to speed, but without all the tickets<\/h2>\n<p>When a new team member joins Microsoft Federal, the organization that engineers solutions to empower governments, access must be granted to the user for each system in the environment they need to do their job.<\/p>\n<p>\u201cImagine you\u2019re new at Microsoft,\u201d Godolphin says. \u201cYou\u2019ve got your team, and not only do you have to get access to the sales systems, but you need access to all the sub-systems. They are not only disparate, but there may be different prerequisites\u2014it is not just one provisioning. Jumping through all those hoops to get set up as a new employee is a terrible experience for anyone.\u201d<\/p>\n<p>Ensuring employees are enrolled in the right systems (and unenrolling them at the right time) can be tedious, especially if manual steps must be taken and system access is controlled by multiple teams. Each system might require its own onboarding request, which generates a lot of tickets and can introduce delays. Delays are a problem given the nature of Microsoft Federal\u2019s sensitive tented work.<\/p>\n<p>Microsoft Federal\u2019s sales team, for example, uses a system that required multiple integration points and tools as part of the overall sales processes. From several roles in Microsoft Dynamics 365, to reporting systems, to downstream services, each employee on the sales team requires a complimentary set of permissions.<\/p>\n<p>To solve this challenge, the Microsoft Federal engineering team developed a solution that leveraged Microsoft Azure AD entitlement management to streamline user access provisioning to make it a seamless, secure, and compliant experience. Additionally, with a little effort, Godolphin and his team were able to leverage Microsoft PowerApps to connect EM to the company human resources system. Thanks to auto-provisioning based on their human resources profile, an automated provision solution build on top of the Microsoft Azure AD EM service, now that same new employee shows up and has access to the entire sales ecosystem automatically.<\/p>\n<p>Launched in November 2019, Microsoft Azure AD entitlement management is an <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/governance\/identity-governance-overview\" target=\"_blank\" rel=\"noopener\">identity governance feature<\/a>\u00a0that enables organizations to manage identity and access lifecycle at scale, by automating access request workflows, access assignments, reviews, and expiration.<\/p>\n<p>Employees in organizations need access to various groups, applications, and sites to perform their job. Managing this access is challenging. As requirements change and new applications are added, users need additional access rights. Similarly, rights need to be added or taken away when new employees join or leave the company. This scenario gets more complicated when you collaborate with outside organizations, you may not know who in the other organization needs access to your organization&#8217;s resources and they won&#8217;t know what applications, groups, or sites your organization is using.<\/p>\n<blockquote class=\"quote-body\"><p>We are the voice of the internal customers, we work with internal customers to understand their access provision pain points, scenarios and bring requirements, gap analysis to the Azure AD Identity Governance product team and co-develop with them to enable critical Microsoft internal scenarios.<\/p>\n<p class=\"source\">\u2014Jennifer Jiao, principal PM manager, Microsoft<\/p>\n<\/blockquote>\n<p>Microsoft Azure AD entitlement management can help you efficiently manage access to groups, applications, and Microsoft SharePoint Online sites for internal users, and for users outside your organization who need access to those resources.<\/p>\n<p>When it comes to federal services, ensuring a lifecycle policy is in place automatically removes users after a set period that has been predetermined and established. In addition, you can comply with Cybersecurity Maturity Model Certification (CMMC) federal guidelines.<\/p>\n<p>\u201cWe are the voice of the internal customers, we work with internal customers to understand their access provision pain points, scenarios and bring requirements, gap analysis to the Azure AD Identity Governance product team and co-develop with them to enable critical Microsoft internal scenarios,\u201d says Jennifer Jiao, principal PM manager working on the project.<\/p>\n<h2>An improved experience for everyone<\/h2>\n<p>The Microsoft Federal Sales team has a commitment to create an air-gapped and separate space to manage all the sales for the federal government. The impetus for the initiative is to keep and maintain secure data, which builds confidence with government entities while supporting a secure space for discussion and planning for government requirements, with Government Community Cloud (GCC) high security.\u00a0GCC is a Microsoft cloud computing environment provisioned in Microsoft\u2019s multi-tenant data centers for exclusive use by or for governments and enrolled affiliates.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"74\" class=\"alignnone size-medium wp-image-7448\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2021\/10\/key-takeaways-300x74.png\" alt=\"Key Takeaways\" srcset=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2021\/10\/key-takeaways-300x74.png 300w, https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2021\/10\/key-takeaways.png 500w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/p>\n<ul class=\"c-list\">\n<li>Automate the access provision process through EM to allow requesting access across multiple resources at once through an access package to reduce the effort and time for employees to get access they needed for their job. Take the time to get your people onboarded and off boarded quickly to reduce security risk.<\/li>\n<li>Leveraging EM for access governance ensures approval workflow, access expiration\/renew, and auditing are in place to secure Microsoft Federal systems.<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"81\" class=\"alignnone size-medium wp-image-7482\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2021\/10\/related_links-300x81.png\" alt=\"Related links\" srcset=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2021\/10\/related_links-300x81.png 300w, https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2021\/10\/related_links.png 500w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/p>\n<ul class=\"c-list\">\n<li><a href=\"https:\/\/docs.microsoft.com\/azure\/active-directory\/governance\/entitlement-management-overview\" target=\"_blank\" rel=\"noopener\">Learn more about Microsoft Azure AD entitlement management.<\/a><\/li>\n<li><a href=\"https:\/\/techcommunity.microsoft.com\/t5\/azure-active-directory-identity\/onboard-partners-more-easily-with-new-azure-ad-entitlement\/ba-p\/2466924\" target=\"_blank\" rel=\"noopener\">Check out how to onboard partners more easily with Microsoft Azure AD entitlement management features.<\/a><\/li>\n<li><a href=\"https:\/\/techcommunity.microsoft.com\/t5\/azure-active-directory-identity\/azure-ad-entitlement-management-is-now-generally-available\/ba-p\/1022399\" target=\"_blank\" rel=\"noopener\">Learn more about how Microsoft Azure AD entitlement management is now generally available.<\/a><\/li>\n<li><a href=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/upgrading-microsofts-core-human-resources-system-with-sap-successfactors\/\">Read about upgrading Microsoft\u2019s core Human Resource system with SAP SuccessFactors.<\/a><\/li>\n<li><a href=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/using-a-zero-trust-strategy-to-secure-microsofts-network-during-remote-work\/\">Explore using a Zero Trust strategy to secure Microsoft\u2019s network during remote work.<\/a><\/li>\n<li><a href=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/onboarding-new-microsoft-employees-with-microsoft-teams-while-working-remotely\/\">Learn more about onboarding new Microsoft employees with Microsoft Teams while working remotely.<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>We periodically update our stories, but we can\u2019t verify that they represent the full picture of our current situation at Microsoft. We leave them on the site so you can see what our thinking and experience was at the time. Microsoft is leveraging identity governance capabilities in Microsoft Azure AD entitlement management (EM) service to [&hellip;]<\/p>\n","protected":false},"author":120,"featured_media":7895,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_hide_featured_on_single":false,"_show_featured_caption_on_single":true,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[],"coauthors":[635],"class_list":["post-7891","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","program-ms-digital-stories","m-blog-post"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Using Microsoft Azure AD entitlement management to empower Microsoft employees and protect the company - Inside Track Blog<\/title>\n<meta name=\"description\" content=\"See how Microsoft is automating giving employees access to job resources using Microsoft Azure AD entitlement management (EM).\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/using-microsoft-azure-ad-entitlement-management-to-empower-microsoft-employees-and-protect-the-company\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Using Microsoft Azure AD entitlement management to empower Microsoft employees and protect the company - Inside Track Blog\" \/>\n<meta property=\"og:description\" content=\"See how Microsoft is automating giving employees access to job resources using Microsoft Azure AD entitlement management (EM).\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/using-microsoft-azure-ad-entitlement-management-to-empower-microsoft-employees-and-protect-the-company\/\" \/>\n<meta property=\"og:site_name\" content=\"Inside Track Blog\" \/>\n<meta property=\"article:published_time\" content=\"2022-03-03T16:01:37+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-04-07T13:42:34+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2022\/03\/10228_wordpress_hero.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"2300\" \/>\n\t<meta property=\"og:image:height\" content=\"1293\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Danni White\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Danni White\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/using-microsoft-azure-ad-entitlement-management-to-empower-microsoft-employees-and-protect-the-company\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/using-microsoft-azure-ad-entitlement-management-to-empower-microsoft-employees-and-protect-the-company\\\/\"},\"author\":{\"name\":\"Danni White\",\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/#\\\/schema\\\/person\\\/11d1c526d8316e309e87cf514dd11e2b\"},\"headline\":\"Using Microsoft Azure AD entitlement management to empower Microsoft employees and protect the company\",\"datePublished\":\"2022-03-03T16:01:37+00:00\",\"dateModified\":\"2026-04-07T13:42:34+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/using-microsoft-azure-ad-entitlement-management-to-empower-microsoft-employees-and-protect-the-company\\\/\"},\"wordCount\":1335,\"image\":{\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/using-microsoft-azure-ad-entitlement-management-to-empower-microsoft-employees-and-protect-the-company\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/uploads\\\/prod\\\/2022\\\/03\\\/10228_wordpress_hero.jpg\",\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/using-microsoft-azure-ad-entitlement-management-to-empower-microsoft-employees-and-protect-the-company\\\/\",\"url\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/using-microsoft-azure-ad-entitlement-management-to-empower-microsoft-employees-and-protect-the-company\\\/\",\"name\":\"Using Microsoft Azure AD entitlement management to empower Microsoft employees and protect the company - Inside Track Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/using-microsoft-azure-ad-entitlement-management-to-empower-microsoft-employees-and-protect-the-company\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/using-microsoft-azure-ad-entitlement-management-to-empower-microsoft-employees-and-protect-the-company\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/uploads\\\/prod\\\/2022\\\/03\\\/10228_wordpress_hero.jpg\",\"datePublished\":\"2022-03-03T16:01:37+00:00\",\"dateModified\":\"2026-04-07T13:42:34+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/#\\\/schema\\\/person\\\/11d1c526d8316e309e87cf514dd11e2b\"},\"description\":\"See how Microsoft is automating giving employees access to job resources using Microsoft Azure AD entitlement management (EM).\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/using-microsoft-azure-ad-entitlement-management-to-empower-microsoft-employees-and-protect-the-company\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/using-microsoft-azure-ad-entitlement-management-to-empower-microsoft-employees-and-protect-the-company\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/using-microsoft-azure-ad-entitlement-management-to-empower-microsoft-employees-and-protect-the-company\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/uploads\\\/prod\\\/2022\\\/03\\\/10228_wordpress_hero.jpg\",\"contentUrl\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/uploads\\\/prod\\\/2022\\\/03\\\/10228_wordpress_hero.jpg\",\"width\":2300,\"height\":1293,\"caption\":\"Lionel Godolphin and Jennifer Jiao are part of Microsoft\u2019s bid to use Microsoft Azure entitlement management to help employees securely access resources they need to do their jobs. (Photos by Lionel Godolphin and Jennifer Jiao)\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/using-microsoft-azure-ad-entitlement-management-to-empower-microsoft-employees-and-protect-the-company\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Using Microsoft Azure AD entitlement management to empower Microsoft employees and protect the company\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/\",\"name\":\"Inside Track Blog\",\"description\":\"How Microsoft does IT\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/#\\\/schema\\\/person\\\/11d1c526d8316e309e87cf514dd11e2b\",\"name\":\"Danni White\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/e8ff22aa5623d549353f216a225f4eccff838abd454c577b693a3f340c501600?s=96&d=mm&r=g0c85df5306cbab256580d0b007c9198e\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/e8ff22aa5623d549353f216a225f4eccff838abd454c577b693a3f340c501600?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/e8ff22aa5623d549353f216a225f4eccff838abd454c577b693a3f340c501600?s=96&d=mm&r=g\",\"caption\":\"Danni White\"},\"url\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/author\\\/dwhite\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Using Microsoft Azure AD entitlement management to empower Microsoft employees and protect the company - Inside Track Blog","description":"See how Microsoft is automating giving employees access to job resources using Microsoft Azure AD entitlement management (EM).","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.microsoft.com\/insidetrack\/blog\/using-microsoft-azure-ad-entitlement-management-to-empower-microsoft-employees-and-protect-the-company\/","og_locale":"en_US","og_type":"article","og_title":"Using Microsoft Azure AD entitlement management to empower Microsoft employees and protect the company - Inside Track Blog","og_description":"See how Microsoft is automating giving employees access to job resources using Microsoft Azure AD entitlement management (EM).","og_url":"https:\/\/www.microsoft.com\/insidetrack\/blog\/using-microsoft-azure-ad-entitlement-management-to-empower-microsoft-employees-and-protect-the-company\/","og_site_name":"Inside Track Blog","article_published_time":"2022-03-03T16:01:37+00:00","article_modified_time":"2026-04-07T13:42:34+00:00","og_image":[{"width":2300,"height":1293,"url":"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2022\/03\/10228_wordpress_hero.jpg","type":"image\/jpeg"}],"author":"Danni White","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Danni White","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/using-microsoft-azure-ad-entitlement-management-to-empower-microsoft-employees-and-protect-the-company\/#article","isPartOf":{"@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/using-microsoft-azure-ad-entitlement-management-to-empower-microsoft-employees-and-protect-the-company\/"},"author":{"name":"Danni White","@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/#\/schema\/person\/11d1c526d8316e309e87cf514dd11e2b"},"headline":"Using Microsoft Azure AD entitlement management to empower Microsoft employees and protect the company","datePublished":"2022-03-03T16:01:37+00:00","dateModified":"2026-04-07T13:42:34+00:00","mainEntityOfPage":{"@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/using-microsoft-azure-ad-entitlement-management-to-empower-microsoft-employees-and-protect-the-company\/"},"wordCount":1335,"image":{"@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/using-microsoft-azure-ad-entitlement-management-to-empower-microsoft-employees-and-protect-the-company\/#primaryimage"},"thumbnailUrl":"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2022\/03\/10228_wordpress_hero.jpg","inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/using-microsoft-azure-ad-entitlement-management-to-empower-microsoft-employees-and-protect-the-company\/","url":"https:\/\/www.microsoft.com\/insidetrack\/blog\/using-microsoft-azure-ad-entitlement-management-to-empower-microsoft-employees-and-protect-the-company\/","name":"Using Microsoft Azure AD entitlement management to empower Microsoft employees and protect the company - Inside Track Blog","isPartOf":{"@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/using-microsoft-azure-ad-entitlement-management-to-empower-microsoft-employees-and-protect-the-company\/#primaryimage"},"image":{"@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/using-microsoft-azure-ad-entitlement-management-to-empower-microsoft-employees-and-protect-the-company\/#primaryimage"},"thumbnailUrl":"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2022\/03\/10228_wordpress_hero.jpg","datePublished":"2022-03-03T16:01:37+00:00","dateModified":"2026-04-07T13:42:34+00:00","author":{"@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/#\/schema\/person\/11d1c526d8316e309e87cf514dd11e2b"},"description":"See how Microsoft is automating giving employees access to job resources using Microsoft Azure AD entitlement management (EM).","breadcrumb":{"@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/using-microsoft-azure-ad-entitlement-management-to-empower-microsoft-employees-and-protect-the-company\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.microsoft.com\/insidetrack\/blog\/using-microsoft-azure-ad-entitlement-management-to-empower-microsoft-employees-and-protect-the-company\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/using-microsoft-azure-ad-entitlement-management-to-empower-microsoft-employees-and-protect-the-company\/#primaryimage","url":"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2022\/03\/10228_wordpress_hero.jpg","contentUrl":"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2022\/03\/10228_wordpress_hero.jpg","width":2300,"height":1293,"caption":"Lionel Godolphin and Jennifer Jiao are part of Microsoft\u2019s bid to use Microsoft Azure entitlement management to help employees securely access resources they need to do their jobs. (Photos by Lionel Godolphin and Jennifer Jiao)"},{"@type":"BreadcrumbList","@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/using-microsoft-azure-ad-entitlement-management-to-empower-microsoft-employees-and-protect-the-company\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.microsoft.com\/insidetrack\/blog\/"},{"@type":"ListItem","position":2,"name":"Using Microsoft Azure AD entitlement management to empower Microsoft employees and protect the company"}]},{"@type":"WebSite","@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/#website","url":"https:\/\/www.microsoft.com\/insidetrack\/blog\/","name":"Inside Track Blog","description":"How Microsoft does IT","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.microsoft.com\/insidetrack\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/#\/schema\/person\/11d1c526d8316e309e87cf514dd11e2b","name":"Danni White","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/e8ff22aa5623d549353f216a225f4eccff838abd454c577b693a3f340c501600?s=96&d=mm&r=g0c85df5306cbab256580d0b007c9198e","url":"https:\/\/secure.gravatar.com\/avatar\/e8ff22aa5623d549353f216a225f4eccff838abd454c577b693a3f340c501600?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/e8ff22aa5623d549353f216a225f4eccff838abd454c577b693a3f340c501600?s=96&d=mm&r=g","caption":"Danni White"},"url":"https:\/\/www.microsoft.com\/insidetrack\/blog\/author\/dwhite\/"}]}},"jetpack_featured_media_url":"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2022\/03\/10228_wordpress_hero.jpg","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p9hcZA-23h","_links":{"self":[{"href":"https:\/\/www.microsoft.com\/insidetrack\/blog\/wp-json\/wp\/v2\/posts\/7891","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.microsoft.com\/insidetrack\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.microsoft.com\/insidetrack\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.microsoft.com\/insidetrack\/blog\/wp-json\/wp\/v2\/users\/120"}],"replies":[{"embeddable":true,"href":"https:\/\/www.microsoft.com\/insidetrack\/blog\/wp-json\/wp\/v2\/comments?post=7891"}],"version-history":[{"count":10,"href":"https:\/\/www.microsoft.com\/insidetrack\/blog\/wp-json\/wp\/v2\/posts\/7891\/revisions"}],"predecessor-version":[{"id":23004,"href":"https:\/\/www.microsoft.com\/insidetrack\/blog\/wp-json\/wp\/v2\/posts\/7891\/revisions\/23004"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.microsoft.com\/insidetrack\/blog\/wp-json\/wp\/v2\/media\/7895"}],"wp:attachment":[{"href":"https:\/\/www.microsoft.com\/insidetrack\/blog\/wp-json\/wp\/v2\/media?parent=7891"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.microsoft.com\/insidetrack\/blog\/wp-json\/wp\/v2\/categories?post=7891"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.microsoft.com\/insidetrack\/blog\/wp-json\/wp\/v2\/tags?post=7891"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www.microsoft.com\/insidetrack\/blog\/wp-json\/wp\/v2\/coauthors?post=7891"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}