user-access-review

Review Entra ID accounts for risky authentication, privileged access, and entitlement misalignment.

Updated Aug 27, 2026
One-click install
npx skills add https://github.com/afoxnyc3/chelsea-piers-itops --skill user-access-review
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: user-access-review
Source: https://github.com/afoxnyc3/chelsea-piers-itops/tree/main/chelsea-piers-itops/skills/user-access-review
Command: npx skills add https://github.com/afoxnyc3/chelsea-piers-itops --skill user-access-review

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

It reduces the risk of inappropriate access by quickly assessing a user’s Entra ID / Azure AD account, security posture, and entitlements.

Core Features & Use Cases

  • Identity & sign-in review: Evaluates MFA registration, last sign-in recency, and recent risk events to spot risky or stale accounts.
  • Entitlement visibility: Reports assigned Microsoft 365 licenses and highlights inactive-but-licensed users for reclamation.
  • Group and privileged access checks: Audits security/M365 group memberships and flags Tier 0/Tier 1 admin roles and guest access that extends beyond intended scope.

Quick Start

Review a user’s Entra ID access by running: /user-access-review [email protected]

Frequently Asked Questions about user-access-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I audit Entra ID access for risky authentication and privileged roles?

An Entra ID access audit evaluates MFA registration, recent sign-in activity, and risk events to identify risky authentication and privileged access. It checks for entitlement misalignment, Tier 0/Tier 1 admin roles, and stale accounts.

What is the best way to check Microsoft 365 group membership and license assignments for offboarding?

Checking Microsoft 365 group membership and license assignments during offboarding involves auditing security and M365 groups while reporting assigned licenses. This process highlights inactive-but-licensed users for reclamation and flags guest access extending beyond intended scope.

Can I review Azure AD sign-in risk events and MFA registration for any username?

Yes, you can review Azure AD sign-in risk events and MFA registration by resolving an identity via any username, UPN, or display-name input. The review collects risk events and produces a structured access report for security alert investigations.

Does Entra ID access review work for targeted security alert investigations and access requests?

Entra ID access review works for targeted security alert investigations, access requests, and offboarding. It resolves the target identity and collects license assignments, group memberships, and risk events to produce a structured access review report.

How do I identify inactive but licensed Microsoft 365 users for license reclamation?

To identify inactive but licensed Microsoft 365 users for license reclamation, an access audit reports assigned Microsoft 365 licenses and evaluates last sign-in recency. This highlights inactive accounts with active licenses so you can reclaim them.