check before: 2025-08-14
Product:
Entra, Microsoft 365 Apps, Microsoft Graph, Purview Communication Compliance
Platform:
Developer, Online, World tenant
Status:
Change type:
Feature update, Admin impact
Links:

Details:
Summary:
Microsoft Entra ID is updating its data retention policy for access reviews. Starting August 15, 2025, only the last 12 months of access review data will be available via the user interface and APIs. Organizations should export historical data before this date and establish a routine for annual data storage.
Details:
We're updating the data retention policy for access reviews in Microsoft Entra ID Governance to improve performance and align with data minimization principles. Starting August 15, 2025, only access review data from the last 12 months will be available via the user interface and APIs.
Change Category:
XXXXXXX ... free basic plan only
Scope:
XXXXXXX ... free basic plan only
Release Phase:
Created:
2025-06-24
updated:
2025-06-24
Task Type
XXXXXXX ... free basic plan only
Docu to Check
XXXXXXX ... free basic plan only
MS How does it affect me
XXXXXXX ... free basic plan only
MS Preperations
XXXXXXX ... free basic plan only
MS Urgency
XXXXXXX ... free basic plan only
MS workload name
XXXXXXX ... free basic plan only
summary for non-techies**
Starting August 15, 2025, Microsoft Entra ID will retain only the most recent 12 months of access review data in the user interface and APIs, requiring organizations to export older data for compliance and audit purposes.
Direct effects for Operations**
Data Loss Risk
Historical access review data older than 12 months will be permanently inaccessible, risking compliance and audit failures if not exported beforehand.
- roles: Compliance Officer, IT Administrator
- references: https://learn.microsoft.com/entra/id-governance/custom-entitlement-report-with-adx-and-entra-id#example-various-queries-that-use-access-reviews
Compliance Monitoring Challenges
The change limits the ability to monitor and report on compliance activities effectively, as only the last 12 months of data will be available.
- roles: Compliance Officer, IT Administrator
- references: https://learn.microsoft.com/entra/id-governance/custom-entitlement-report-with-adx-and-entra-id#example-various-queries-that-use-access-reviews
Increased Administrative Burden
Admins will need to establish new routines for data export and storage, increasing workload and potential for errors if not properly managed.
- roles: IT Administrator, Data Governance Officer
- references: https://learn.microsoft.com/entra/id-governance/custom-entitlement-report-with-adx-and-entra-id#example-various-queries-that-use-access-reviews
User Experience Degradation
Users may experience delays or issues in accessing necessary historical data for decision-making or compliance checks, impacting productivity.
- roles: End User, IT Support
- references: https://learn.microsoft.com/entra/id-governance/custom-entitlement-report-with-adx-and-entra-id#example-various-queries-that-use-access-reviews
Documentation and Training Needs
Internal documentation will require updates and staff may need retraining on new data retention policies and procedures, leading to temporary confusion.
- roles: Training Coordinator, IT Administrator
- references: https://learn.microsoft.com/entra/id-governance/custom-entitlement-report-with-adx-and-entra-id#example-various-queries-that-use-access-reviews
Configutation Options**
XXXXXXX ... paid membership only
Opportunities**
Data Export Automation
Implement automated scripts to regularly export access review data before the retention policy change. This will ensure compliance and mitigate the risk of data loss.
- next-steps: Develop and schedule a PowerShell or Microsoft Graph API script to automate the export of access review data on a monthly basis.
- roles: Compliance Officers, IT Administrators, Data Analysts
- references: https://learn.microsoft.com/entra/id-governance/custom-entitlement-report-with-adx-and-entra-id#example-various-queries-that-use-access-reviews
Annual Review Report Generation
Establish a standardized process for generating and securely storing annual review reports to comply with governance requirements and maintain historical data accessibility.
- next-steps: Create a policy document outlining the annual report generation process and assign responsibilities to specific team members for compliance.
- roles: Compliance Officers, IT Administrators, Risk Management Teams
- references: https://learn.microsoft.com/entra/id-governance/custom-entitlement-report-with-adx-and-entra-id#example-various-queries-that-use-access-reviews
User Training and Awareness
Conduct training sessions for relevant stakeholders to ensure they understand the implications of the new retention policy and the importance of timely data exports.
- next-steps: Develop training materials and schedule sessions with teams that rely on access review data, ensuring they are aware of the changes and necessary actions.
- roles: HR Managers, IT Administrators, Compliance Officers
- references: https://learn.microsoft.com/entra/id-governance/custom-entitlement-report-with-adx-and-entra-id#example-various-queries-that-use-access-reviews
Potentional Risks**
XXXXXXX ... paid membership only
Data Protection**
XXXXXXX ... paid membership only
IT Security**
XXXXXXX ... paid membership only
Hypothetical Work Council Statement**
XXXXXXX ... paid membership only
DPIA Draft**
XXXXXXX ... paid membership only
explanation for non-techies**
XXXXXXX ... free basic plan only
** AI generated content. This information must be reviewed before use.
a free basic plan is required to see more details. Sign up here
A cloudsocut.one plan is required to see all the changed details. If you are already a customer, choose login.
If you are new to cloudscout.one please choose a plan.
Last updated 2 weeks ago