skip to content

What Is Access Certification?

Access certification is the process of periodically reviewing and validating user access rights to ensure they align with job responsibilities and comply with security policies. Also called user access review or access recertification, it is a core pillar of identity governance and administration (IGA): the framework that governs who has access to what, and why.

During an access certification campaign, designated reviewers assess each user's entitlements, confirm whether those rights are still appropriate, and approve or revoke access accordingly. This enforces the principle of least privilege, ensuring no user accumulates permissions beyond what their role requires. Access certification is a fundamental control for regulatory compliance and a primary defence against privilege creep.

Try Out ADManager Plus Access Review Software For Free

Our team of specialists has built user access review and access certification software for Active Directory managers and admins, available as a free trial before purchase.

Benefits of Access Certification Campaigns

Enhanced security

Reduce the risk of unauthorised access by identifying and removing users' inappropriate access rights through access certification.

Compliance demonstration

Comply with mandates and organisational policies by maintaining an auditable record of access reviews, including access recertification and changes. Each completed campaign produces an audit trail: a timestamped log of who reviewed what, what decisions were made, and what remediation was taken.

Minimised insider threats

Periodically reviewing users' access rights can help detect and revoke unnecessary privileges and keep malicious insiders at bay.

Resource optimisation

Reviewing and revoking users' access to enterprise resources and group memberships helps reduce licence and subscription costs.

Prevent privilege creep

Regularly review access permissions through access recertification to avoid the accumulation of privileges. Privilege creep prevention is most effective when reviews are scheduled periodically and triggered by role changes.

Improved efficiency

Streamline access management processes by running automated certification campaigns, including access recertification, to identify and revoke access for over-privileged accounts.

Accelerated certification

Make quicker, more informed certification decisions and simplify reviews with access recommendations. Risk-based prioritisation surfaces the highest-risk entitlements first, reducing reviewer fatigue and improving the accuracy of each decision.

Use cases

Use case 1: Secure privileged accounts

Run a customised certification campaign to manage the privileges of accounts with access to sensitive information, including service accounts and API keys, and revoke privileges as and when needed. Non-human identities carry the same access risks as user accounts and must be included in certification scope.

Secure privileged accounts

Use case 2: Meeting compliance and audit requirements

Each certification campaign conducted in ADManager Plus is stored and can be viewed by stakeholders. A detailed history of the campaign, including certifier name, action performed, and comments added by the certifier, is recorded in a full audit trail. Compliance teams can use this evidence during regulatory audits under ISO 27001, UK GDPR, or Cyber Essentials requirements.

Meeting compliance and audit requirements

Use case 3: Recertifying user access

Schedule and run access certification campaigns frequently at a desired time to review and recertify users' access rights, ensuring that users' access is consistently validated and aligned with current roles and responsibilities. Unlike the initial certification, the user access recertification process repeats on a defined schedule, and can also be triggered by role changes, transfers, or security incidents.

Scheduling an access recertification campaign in ADManager Plus

Why Choose ADManager Plus for Access Certification Campaigns

Unlike traditional manual processes, ADManager Plus enables IT and compliance leaders to run efficient access certification campaigns across Active Directory as part of a broader identity governance and administration strategy. Designed to save time and reduce errors, it ensures only the right people have the right access.

With ADManager Plus, you can:

  • Conduct Active Directory access reviews quickly with prebuilt reports.
  • Automate review reminders and workflows.
  • Certify user access across applications, groups, and shared resources.
  • Document every review step for compliance audits.

Key Benefits of Our Access Review Software

Our access review software equips your team with the tools needed to maintain security, demonstrate compliance, and simplify administration:

  • Automated certification workflows: Schedule recurring access certification campaigns to validate user rights periodically and trigger reviews on role changes or security events.
  • Granular entitlement reviews: Assess access at the user, group, or OU level for precise oversight of every permission and group membership.
  • Audit-ready reports: Export comprehensive records of completed access reviews to satisfy regulatory requirements and support compliance audit readiness.
  • Collaborative approvals with SoD enforcement: Assign review tasks to managers or application owners and flag segregation of duties conflicts automatically for resolution.

How ADManager Plus Streamlines Active Directory Access Reviews

Manual reviews often result in delays, missed risks, and compliance gaps. ADManager Plus automates the process to:

  • Generate targeted reports showing who has access to what, across Active Directory and Microsoft 365 entitlements.
  • Highlight excessive permissions, enable orphaned account detection, identify non-human identities with unreviewed access, and surface policy violations.
  • Launch access certification campaigns to revalidate rights instantly.
  • Empower reviewers with an intuitive interface, requiring no technical expertise.

By replacing spreadsheets and emails with structured, automated workflows, ADManager Plus makes Active Directory and Microsoft 365 access reviews both reliable and repeatable.

How Access Certification Campaigns Work

Access certification campaigns follow a structured five-step process that validates user entitlements and produces a compliance audit trail:

  1. Scope: Define which users, groups, and entitlements the campaign will cover. Campaigns can target the entire directory, specific OUs, privileged accounts, or Microsoft 365 role assignments.
  2. Assign reviewers: Designate certifiers, typically line managers or data owners, who are responsible for reviewing each user's access rights.
  3. Review and decide: Reviewers assess each entitlement against the user's current role and select approve, revoke, or modify. Risk-based prioritisation surfaces the highest-risk permissions first, reducing reviewer fatigue on large campaigns.
  4. Automated remediation: Once decisions are submitted, ADManager Plus enforces them automatically, revoking group memberships, adjusting NTFS permissions, and removing Microsoft 365 role assignments without manual intervention.
  5. Audit trail: Every decision is recorded in a timestamped log, including the reviewer name, action taken, and any comments. This audit trail serves as evidence for regulatory audits.

Access recertification is the periodic repetition of this cycle on a defined schedule. Campaigns can also be event-driven: triggered automatically when a user changes role, transfers to a new department, or is flagged by a security alert, rather than waiting for the next scheduled review.

ADManager Plus handles this entire workflow within a single access certification software platform, covering Active Directory, NTFS permissions, and Microsoft 365 roles.

Role of Identity Governance and Administration

Identity governance and administration (IGA) is the framework that governs how user identities and their associated entitlements are managed across an organisation's systems. It combines identity governance, which provides visibility, compliance reporting, and analytics over who has access to what, with identity administration, which covers provisioning, deprovisioning, and identity lifecycle management.

Access certification is a core pillar of IGA: the review-and-validate mechanism that keeps governance policies accurate over time. Without regular certification, entitlements drift as users change roles, join new teams, or move between departments, and the access rights they once needed accumulate unchecked.

IGA platforms like ADManager Plus centralise access provisioning, identity lifecycle management, and certification into a unified model, automating campaign scheduling, tracking entitlements across systems, and generating audit-ready reports that demonstrate access control certification compliance.

Role-Based Access Control and Entitlement Reviews

Role-based access control (RBAC) is a model in which permissions are assigned to roles rather than to individual users. A user acquires access rights by being assigned to a role, and that role determines the entitlements they hold: specific permissions, group memberships, and application access rights.

Entitlement reviews are the granular evaluation of these permissions during an access certification campaign. Reviewers assess whether each entitlement a user holds is still appropriate for their current role, and whether any permissions have accumulated beyond what the role requires.

RBAC simplifies access certification by allowing reviewers to validate role assignments rather than inspecting individual permissions one by one. When a user holds entitlements outside their defined role, certification surfaces this role drift for correction.

Entitlement reviews also enforce segregation of duties (SoD): the principle that no single user should hold conflicting permissions that would allow them to both initiate and approve a transaction, or access and modify the same sensitive resource. Certification campaigns detect SoD violations and flag them for remediation, supporting both internal policy and external audit requirements.

Principle of Least Privilege and Preventing Privilege Creep

The principle of least privilege holds that every user, application, or system should have only the minimum access necessary to perform its function, and nothing more. Access certification is the mechanism that enforces this principle on a recurring basis by surfacing permissions that have grown beyond what each user's current role requires.

Privilege creep is the gradual accumulation of access rights that builds up when users change roles, take on temporary responsibilities, or move between departments. Each change may add permissions, but old permissions are rarely removed. Over time, users hold access rights from multiple roles simultaneously, significantly exceeding the least privilege standard. Access certification detects this drift and corrects it by prompting reviewers to revoke permissions that no longer align with job function.

Orphaned accounts represent a related risk: accounts belonging to departed employees or contractors that remain active in the directory. Certification campaigns surface these accounts for disabling or deletion.

Non-human identities, including service accounts, API keys, and automated processes, must also be included in certification scope. These identities frequently hold privileged access and are rarely reviewed, making orphaned account detection and non-human identity certification critical components of a complete access governance programme.

Regulatory Compliance and Audit Trails

Access certification is a primary control for demonstrating regulatory compliance. Regulators and auditors need evidence that access rights are actively managed, reviewed, and corrected on a recurring schedule, not simply asserted.

The audit trail produced by each certification campaign provides this evidence: a timestamped record of who reviewed which entitlements, what approve or revoke decisions were made, when remediation occurred, and which reviewer was accountable. This documented record is the artefact that compliance teams present during audits under GDPR, HIPAA, PCI DSS, ISO 27001, SOX, Cyber Essentials, FCA SM&CR, and NHS DSPT requirements.

Privileged access requires particular attention. Domain administrators, service account owners, and users with elevated rights carry higher risk and should undergo certification more frequently than standard users, with tighter controls and a shorter review cycle.

ADManager Plus generates audit-ready reports at the close of each campaign, capturing the full decision history in a format suitable for regulatory submission. Compliance audit readiness is built into the workflow, not added as an afterthought.

Privileged Access and Certification Frequency

Privileged accounts, including domain administrators, service accounts with elevated rights, and users with access to sensitive data, represent the highest risk in any AD environment. Standard quarterly certification cycles are often insufficient for these accounts. Security frameworks including Cyber Essentials and ISO 27001 recommend more frequent review of privileged access, and some regulated sectors require monthly or continuous monitoring.

Frequently Asked Questions

Access certification (also called user access review or access recertification) is the identity governance process of periodically verifying that each user holds only the access rights their current role requires. It is not a professional credential but a security and compliance control.

Microsoft Access is a database application. A Microsoft Office Specialist (MOS) certification covers Microsoft Access as a database tool. This page covers access certification as an identity governance process: reviewing and validating user access rights in systems like Active Directory and Microsoft 365.

The most widely recognised professional cybersecurity certifications are CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager), and CompTIA Security+. These are professional credentials. Access certification, by contrast, is a recurring identity governance and access management process, not a professional qualification.

Get Started with ADManager Plus: Access Certification Software for Active Directory

Take control of identity governance with ADManager Plus. Whether you are launching your first access certification campaign, addressing ISO 27001 access control requirements, or replacing spreadsheet-based reviews, ADManager Plus delivers structured automation, comprehensive audit trails, and accountability at every stage of the access certification process.

Manage access certification campaigns, enforce least privilege access, and maintain full audit trail coverage across Active Directory and Microsoft 365 with ADManager Plus.

 

Explore More ADManager Plus Features

Active Directory Management 

Make your everyday Active Directory management tasks easy and light with ADManager Plus's AD Management features. Create, modify and delete users in a few clicks!

Active Directory password management 

Reset password and set password propertied from a single web-based console, without compromising on the security of your AD! Delegate your password-reset powers to the helpdesk technicians too!

Active Directory computer reports 

Granular reporting on your AD Computer objects to the minutest detail. Monitor...and modify computer attributes right within the report. Reports on Inactive Computers and operating systems.

Microsoft Exchange Management 

Create and manage Exchange mailboxes and configure mailbox rights using ADManager Plus's Exchange Management system. Now with support for Microsoft Exchange 2010!!

Active Directory Cleanup 

Get rid of the inactive, obsolete and unwanted objects in your Active Directory to make it more secure and efficient...assisted by ADManager Plus's AD Cleanup capabilities.

Active Directory automation 

A complete automation of AD critical tasks such as user provisioning, inactive-user clean up etc. Also lets you sequence and execute follow-up tasks and blends with workflow to offer a brilliant controlled-automation.

Need Features? Tell Us

If you want to see additional features implemented in ADManager Plus, we would love to hear from you. Click here to continue

Get a Prompt Quote

Our team is available to discuss your access certification requirements, whether you need to automate campaign scheduling, demonstrate compliance audit readiness, or enforce least privilege access across Active Directory.

Contact us for a no-obligation quote tailored to your environment.

ADManager Plus Trusted By

Alcatel LucentCHSiCisco
General ElectricIBM
L & T InfotechNorthrop GrummanSymantec
ToshibaToyota
UPSVolkswagen
The one-stop solution to Active Directory Management and Reporting