(+351) 21 24 10006  ·  info@bconcepts.pt
Carnaxide, Lisbon

How to implement Data Access Reviews in Data Governance

João Barros 03 de October de 2026 4 min read

Managing who has access to which data is critical for security and compliance. This tutorial shows how to implement a Data Access Reviews process in Data Governance to review, validate and record accesses periodically, reducing excessive privilege risks.

Prerequisites

  • An account with administrator permissions in an identity platform (for example Azure AD) and in the data source (for example Azure SQL, ADLS, Power BI).
  • Catalog of users and dataset owners (at least in a spreadsheet or an inventory tool).
  • Basic knowledge of PowerShell or scripting to automate extraction of permission lists.

Step 1: Define the scope and frequency of the Data Access Review

Before starting, choose which assets to review (e.g.: databases, ADLS containers, Power BI workspaces) and how often (monthly, quarterly). Defining the scope avoids reviewing irrelevant accesses and helps focus efforts where risk is higher.

Step 2: Extract the current access list

Programmatically collect the accesses for each asset. Example with PowerShell for Azure SQL and Azure AD (simplified):

# Exemplo: exportar logins e roles de uma base Azure SQL
# Requer Az.Sql e Az.Accounts
Connect-AzAccount
$rg = 'rg-exemplo'
$sqlServer = 'sqlserver-exemplo'
$databases = Get-AzSqlDatabase -ResourceGroupName $rg -ServerName $sqlServer
foreach ($db in $databases) {
  $dbName = $db.DatabaseName
  $query = "SELECT dp.name AS principal, dp.type_desc, dr.role_principal_id, r.name AS role_name FROM sys.database_principals dp LEFT JOIN sys.database_role_members dr ON dp.principal_id = dr.member_principal_id LEFT JOIN sys.database_principals r ON dr.role_principal_id = r.principal_id WHERE dp.type_desc IN ('SQL_USER','WINDOWS_USER','EXTERNAL_USER')"
  Invoke-AzSqlDatabaseQuery -ResourceGroupName $rg -ServerName $sqlServer -DatabaseName $dbName -Query $query | Export-Csv -Path "accesses-$dbName.csv" -NoTypeInformation
}

Step 3: Map owners and responsables

Associate each asset with an owner responsible for validating the accesses. Use a CSV file or a simple table with columns: asset, owner_email, type. Without clear owners, reviews will fail.

Step 4: Prepare the review package

Create a package with the list of users, privileges and a suggested action (keep, remove, reduce). Include context: business owner, purpose of access and date of last review. A simple template in CSV or Excel is sufficient to start.

Step 5: Send the review and collect responses

Automate the sending via e-mail or a workflow tool (for example Power Automate) with links to approve/reject. In the body of the request explain why the review is happening and the deadline. At large scale, use forms that automatically record decisions.

Step 6: Apply approved actions

After receiving decisions, apply the changes. Example to remove a user from a role in Azure SQL via T-SQL executed by PowerShell:

# Remover user de role numa base Azure SQL via Invoke-Sqlcmd (exemplo)
$server = 'tcp:sqlserver-exemplo.database.windows.net'
dbat = 'db_exemplo'
$userToRemove = 'user@empresa.com'
$sql = "ALTER ROLE db_datareader DROP MEMBER [${userToRemove}];"
Invoke-Sqlcmd -ServerInstance $server -Database $dbat -Query $sql -Username 'admin@empresa.com' -Password (ConvertTo-SecureString 'PASSWORD' -AsPlainText -Force)

Step 7: Record and audit decisions

Keep an immutable record of the reviews: who validated, date, decision and justification. You can use SharePoint/OneDrive or a central repository (CSV or database). For compliance, retain these records for the period required by the retention policy.

Verify the result

Confirm that removed accesses no longer appear in the original extractions and that owners validated the entries. Test with a test user to verify the access was indeed blocked. Also check the review logs to ensure traceability.

Conclusion

A Data Access Reviews process reduces excessive privilege risk and demonstrates compliance. Next steps: automate extraction and sending with scripts, integrate with Microsoft Purview or a GRC tool, and schedule periodic reviews. Tip: start with a reduced scope (only critical assets) to learn and adjust the process.