Access Recertification Campaigns That Actually Get Done
Access recertification campaigns explained: how to run recurring access reviews with reminders and follow-up that mid-market IT teams can sustain.
Access recertification campaigns are the recurring reviews where managers and system owners confirm that the access people hold still matches what they actually need. Done well, they catch stale permissions before an auditor does. Done badly, they turn into a spreadsheet nobody opens, a deadline that slips, and a rubber-stamp "approve all" click that defeats the whole point. For mid-market IT teams without a dedicated identity governance function, the gap between those two outcomes usually comes down to process, not intent.
This article looks at what makes a recertification campaign work in practice: how to scope it, how to keep it from becoming a burden on the business owners who have to actually do the reviewing, and how reminders and follow-up turn a one-off exercise into a habit that sticks. We will also look at where automation reduces the manual grind that causes most campaigns to fail in the first place.
Why Access Recertification Campaigns Exist
Access accumulates. People change roles, join projects, get temporary elevated rights for a migration, and move departments, and in the vast majority of cases nobody goes back afterward to remove what is no longer needed. Recertification is the mechanism that forces that cleanup to happen on a schedule instead of never.
The compliance driver
Frameworks like ISO 27001, NIS2, and SOC 2 all expect evidence that access rights are periodically reviewed and confirmed by someone accountable, not just granted once and forgotten. Auditors typically want to see who reviewed what, when, and what happened to access that was flagged as no longer needed. A recertification campaign, run consistently, produces exactly that trail.
The security driver
Compliance is the reason recertification gets budget, but security is the reason it matters day to day. Standing access that outlives its purpose is one of the most common paths to a breach with real consequences: a former project member who still has access to a finance system, an old contractor account that was never fully removed, a role change that left legacy permissions in place. None of that shows up as a security incident until it does.
What a Campaign Actually Involves
A recertification campaign is more than sending a spreadsheet of user names to a manager and hoping for the best.
The core components
- Scope: which systems, groups, or roles are in this cycle. Not everything needs to be reviewed every quarter.
- Reviewers: usually the resource owner or the reviewee's manager, someone close enough to the access to make an informed call.
- Decision options: approve, revoke, or in some cases modify. Reviewers need a real choice, not just a checkbox that confirms the status quo.
- Deadline and escalation: a due date, plus a defined path for what happens when a reviewer misses it.
- Evidence: a record of who reviewed what and when, kept somewhere an auditor can actually find it later.
Why "review everything, all the time" does not work
Reviewing every permission in the tenant every month sounds thorough and is, in practice, how campaigns die. Reviewers get flooded with requests, start clicking through without reading, and the exercise becomes theater instead of a real check. A tighter scope, reviewed more carefully and more often for the access that matters most, beats a sprawling review that nobody has time to do properly.
Designing a Campaign Mid-Market Teams Can Actually Sustain
Enterprise IGA suites are built around campaigns that assume a dedicated governance team running them. Most mid-market IT teams do not have that team, so the campaign design has to fit around people who are already doing this on top of a full-time job.
Risk-based scoping
Not all access carries equal weight. A good starting point:
- High-risk access (admin roles, finance systems, access to sensitive data): review quarterly, at minimum.
- Standard business access (department shares, common applications): review every six months.
- Low-risk, self-service or automatically scoped access: review annually, or lean on the fact that attribute-based rules keep it accurate between reviews.
Small, targeted batches beat one giant campaign
Sending every manager in the company a review at the same time, twice a year, creates a spike of work everyone dreads and half-ignores. Splitting reviews by department, system, or risk tier, and staggering them across the year, keeps each individual review small enough that a manager can actually give it attention instead of speed-clicking through it.
Make the reviewer's job genuinely easy
If a reviewer has to go dig through a group membership list or ask IT what a role actually grants, most will approve everything just to get it over with. The review needs to show, in plain language, who has what and why they got it, ideally tied back to the attribute (department, job title, project) that originally justified the access.
Reminders and Follow-Up: Where Most Campaigns Actually Fail
The review design can be perfect and the campaign still stalls, because reminders and follow-up are the part that gets skipped when everything runs manually.
The manual follow-up problem
A typical manual process looks like: export a list, email it to managers, wait, chase the ones who did not respond, chase them again, eventually give up and mark the rest as "reviewed" by default so the campaign can close. That last step quietly undoes the entire point of the exercise.
What good follow-up looks like
- Automated reminders at set intervals, not a person remembering to send a nudge email.
- Escalation to a second approver or IT if a reviewer does not respond within a defined window.
- A visible status view so someone owns the campaign's completion rate, rather than it trailing off unnoticed.
- No silent default approval. Unreviewed access should be flagged, not waved through.
| Campaign element | Manual approach | Sustainable approach |
|---|---|---|
| Reminders | Ad hoc email from IT | Scheduled, automatic |
| Non-responders | Chased manually, often given up on | Escalated automatically after a deadline |
| Evidence | Scattered emails and spreadsheets | Centralized, timestamped record |
| Scope | Everything at once | Risk-tiered, staggered batches |
How ServiceChanger Supports Recertification
ServiceChanger's access automation (ABAC) assigns users to Entra ID and on-prem AD groups based on attributes like department, location, and job title, so a meaningful share of access stays correct automatically between review cycles instead of drifting the way manually managed group membership does. Group mining looks at existing access patterns and suggests which groups reflect a real, attribute-based structure, which makes scoping a recertification campaign faster because you are reviewing a cleaner starting point.
On top of that, ServiceChanger includes access reviews built for exactly this recurring cadence: reviewers get a clear view of who holds what and why, campaigns can be scoped by group, role, or risk tier, and reminders and follow-up run on a schedule instead of depending on someone remembering to chase people down. The goal is not a heavier process, it is a lighter one that still holds up under an audit.
For the fuller picture on keeping access clean and auditable across your Microsoft environment, see our guide to access governance and compliance. For more on the review side specifically, browse our Access Reviews articles, or see how attribute-based structure reduces what needs reviewing in the first place in our Governance coverage.
FAQ
What is an access recertification campaign? It is a scheduled process where managers or system owners review the access a set of users holds and confirm whether it should be kept, changed, or revoked. It is typically run on a recurring cadence, such as quarterly or semi-annually, and is used both for security hygiene and to satisfy compliance frameworks that require periodic access review.
How often should we run recertification campaigns? It depends on the risk level of the access being reviewed. High-risk access like admin roles or finance systems is usually reviewed quarterly, standard business access every six months, and low-risk or attribute-driven access annually is often sufficient.
What causes recertification campaigns to fail? The most common causes are scope that is too broad for reviewers to handle carefully, no automated reminders or escalation for non-responders, and a fallback that silently approves unreviewed access just to close the campaign on time.
Can access recertification be automated in Entra ID and on-prem AD? Native tooling covers parts of the process, but scheduling, reminders, escalation, and a clean audit trail across both Entra ID and on-prem AD typically require dedicated review tooling. Attribute-based access management also reduces how much manual review is needed in the first place, since correctly scoped access stays accurate between cycles.
If your recertification process currently lives in a spreadsheet and a string of chase-up emails, it is worth seeing what a lighter, automated version looks like. Get in touch to see ServiceChanger's access reviews in action.
You might also like
Entra Group Naming Convention: A Structure That Scales
A good Entra group naming convention lets people and automation reason about access at a glance. Learn the structure, prefixes, and rules that hold up.
Quarterly License Review: A Lightweight Cadence
A quarterly license review beats a panic audit at renewal. Learn how to build a lightweight, repeatable cadence for Microsoft 365 license spend.
Orphaned Accounts: A Top Offboarding Risk
Orphaned accounts and standing access are a leading breach vector. Learn why offboarding leaves accounts behind and how automated leaver flows close the gap.