Why reviews approve everything
A manager is sent a list of forty entitlements and given a week to confirm them. The list says what each person can reach. It does not say whether they have used it, when, or for what. Faced with a name they recognise and an entitlement they cannot evaluate, the safe answer is always to approve.
That is not negligence. It is the only rational response to being asked a question you have not been given the information to answer. The review process produced a signature, an audit artefact, and no change to the attack surface.
Change the question
The fix is to stop asking whether access should exist and start showing what it has done. Every row in a review should carry:
- Last use, with a date. Ninety days of no use is the single most powerful column on the sheet, because it is very hard to argue with.
- What it was used for — the change or case references the sessions were opened against. If the reason field was never populated, that is its own finding.
- Reach, expressed in systems rather than in group names. “Domain Admins” means nothing to the person signing; “every domain controller and every hypervisor” means a great deal.
- What granted it, and when, and who approved it. Entitlements with no traceable origin are the ones to remove first.
None of that is available if access is granted through directory group membership and used through shared accounts. It is available as a by-product if access is brokered through a gateway that records the grant, the reason and the session.
Make removal the default
The second structural fix is to reverse the default. In most programmes, an entitlement survives unless someone actively removes it, and inaction preserves access. Invert that: an entitlement not affirmatively recertified within the window expires.
This is uncomfortable the first time it runs, and it needs a fast, well-publicised restoration path so that a missed review is an inconvenience rather than an outage. But it converts the review from a paperwork exercise into a control with teeth, because doing nothing now produces the safe outcome instead of the unsafe one.
Review less, more often
A quarterly review of everything is a large, low-attention event. A continuous review of the things that matter is a small, high-attention one. Split the estate:
- Highest-reach roles — monthly, by a named owner, with usage evidence attached.
- Everything else — on a slower cycle, or not at all if it has been converted to just-in-time access and no longer stands.
- Third parties and contractors — on contract boundaries rather than on the calendar, because that is when the access should actually end.
The best recertification programme is a small one, because most of what used to be reviewed no longer exists between engagements. That is the connection worth making: just-in-time access does not sit alongside recertification, it shrinks it.
What good looks like
A review cycle is working when it produces removals, when the reviewers can explain their decisions without opening another system, and when the evidence of the review — who reviewed, what they saw, what they decided — is exportable without assembling it by hand.
That last point is what turns the exercise from a compliance cost into something usable. If an inspector asks why an administrator held access to a particular system in March, the answer should be a record, not a reconstruction. Our note on chain of custody for administrative access covers what that record has to survive.