ACCESS REGISTER AND LIFECYCLE CHECKLIST Instructions: Copy the blank record for each person/service and application. Record actual permissions, decisions and implementation evidence. Keep the completed register private. Store secrets in an approved vault, not here. BLANK ACCESS RECORD Identity / person or service: ____________________ Manager, sponsor or business owner: ____________________ Application / tenant / application owner: ____________________ Role and business reason: ____________________ Authentication and provisioning method: ____________________ Approved start / end / review dates: ____________________ Approver and approval reference: ____________________ Review decision (keep/change/remove/investigate): ____________________ Action owner / due date: ____________________ Actual result / test / evidence reference: ____________________ Verified by / completion date: ____________________ FICTIONAL EXAMPLE — NOT A REAL ACCOUNT Identity: Morgan, contractor; sponsor: operations lead. Application: project workspace; owner: project manager. Role: read-only access to assigned project documents for a review. Approval: request EXAMPLE-17; duration: start through agreed project end. Review decision: remove after final deliverable is accepted. Evidence: owner confirmed external share removed in the application; test invitation no longer grants access. Coordinator records completion. Actual dates and service-specific tests must be filled for a real record. JOINER [ ] Approved identity, role and start date received. [ ] Individual account and role baseline created. [ ] Supported authentication enrolled through approved process. [ ] Required task works; unrelated administrative action unavailable. [ ] Owner and next review date recorded. MOVER [ ] Compare previous access with new role. [ ] Grant new approved access and remove obsolete permissions. [ ] Give temporary overlaps an owner and expiry. [ ] Check groups, shared resources, integrations and privileged roles. [ ] Verify each application and record failures for follow-up. LEAVER Effective time and authorized manager: ____________________ Coordinator: ____________________ [ ] Block new sign-ins; disable relevant accounts. [ ] Revoke sessions/tokens as supported; check local and external accounts. [ ] Transfer required ownership and preserve records before deletion. [ ] Retrieve equipment/physical credentials; address shared secrets. [ ] Verify application results and session-lifetime limitations. [ ] Close only after unresolved failures are assigned and escalated. Source context: Microsoft Entra lifecycle overview and task definitions. These document one implementation; verify your own provider's behavior. https://learn.microsoft.com/en-us/entra/id-governance/what-are-lifecycle-workflows https://learn.microsoft.com/en-us/entra/id-governance/lifecycle-workflow-tasks Yenra | Updated September 9, 2026 Guide: https://yenra.com/identity-management/