Accountability should sit with the certification owner, supported by the application owner, security team, and access governance function. Each party has a distinct role in initiating the review, making decisions, and preserving evidence. If reviews are missed or undocumented, organisations should treat it as a governance failure, not just a workflow delay.
Why This Matters for Security Teams
Microsoft 365 access reviews are a control, not an administrative courtesy. When a certification is late or evidence is missing, the issue is not just overdue paperwork. It means no one can prove who approved continued access, whether exceptions were justified, or whether privileged access drifted beyond policy. That creates audit exposure, weakens segregation of duties, and can leave standing access in place longer than intended.
For security teams, the accountability question matters because reviews usually span multiple owners: the certification owner drives the review, the application owner validates business need, and governance teams preserve the record. If evidence cannot be produced, control failure is already present even if the access list was eventually reviewed. This is consistent with the broader NHI governance problem described in the Ultimate Guide to NHIs, where weak lifecycle discipline and poor visibility routinely turn access management into an after-the-fact cleanup exercise. The same pattern appears in the 52 NHI Breaches Analysis, where delayed action and missing oversight repeatedly amplify impact.
Current guidance from the OWASP Non-Human Identity Top 10 and NIST SP 800-53 Rev. 5 Security and Privacy Controls treats accountability, evidence retention, and timely review as core control outcomes, not optional process steps. In practice, many security teams encounter this only after an auditor asks for proof and the review window has already closed.
How It Works in Practice
Accountability should be assigned before the review starts, and the record should make that assignment obvious. The certification owner is responsible for completing the review on time and recording the decision. The application owner confirms whether access is still needed. The access governance or identity team ensures the campaign runs, reminders are issued, exceptions are tracked, and evidence is retained. Security or GRC functions typically verify that the process meets control requirements and that missing evidence is escalated, not quietly recreated later.
In Microsoft 365 environments, the practical control points are straightforward: define the review scope, name the accountable owner, set a due date, document escalation thresholds, and retain the export or attestation log. If a reviewer cannot complete the certification, the fallback should be a preapproved delegate, not an open-ended delay. If evidence is missing, the organisation should treat that as a control exception and record why it failed, what compensating action was taken, and who approved the exception. This is especially important for privileged groups, service-linked accounts, and access tied to sensitive collaboration spaces, because those entitlements are often forgotten until the next audit cycle.
For broader identity governance, the same principles from the NHI Lifecycle Management Guide apply: ownership, review cadence, and evidence retention need to be explicit, repeatable, and machine-checkable where possible. The control objective is not simply that a review happened, but that it happened on time and can be proven later. These controls tend to break down in decentralised Microsoft 365 estates where business units manage their own review schedules because ownership becomes fragmented and evidence retention becomes inconsistent.
Common Variations and Edge Cases
Tighter certification controls often increase operational overhead, so organisations must balance auditability against reviewer fatigue and business disruption. That tradeoff becomes visible when hundreds of access assignments roll up to one owner, or when reviewers lack enough context to make a defensible decision within the review window.
There is no universal standard for this yet, but current guidance suggests using clear escalation paths and documented delegations rather than extending deadlines informally. If the certification owner is unavailable, the delegated approver should be preassigned and logged. If the application owner and certification owner disagree, the decision should move to the governance function for resolution rather than lingering unresolved. For high-risk access, missing evidence should trigger automatic remediation or access revocation until proof is restored.
This issue is not limited to human accounts. The same governance failure appears when service accounts or app registrations are included in broader identity review scopes, especially if teams assume access can be validated later. The Ultimate Guide to NHIs — Key Challenges and Risks shows why late review and weak evidence handling are dangerous: identities with standing privilege accumulate risk quickly when no one can prove timely oversight.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AA-02 | Identity management requires timely review and traceable ownership. |
| OWASP Non-Human Identity Top 10 | NHI-01 | Ownership and lifecycle control are central to accountable access governance. |
| NIST SP 800-63 | Identity assurance depends on reliable lifecycle and verification records. | |
| NIST Zero Trust (SP 800-207) | AC-2 | Zero Trust reinforces least privilege and continuous access validation. |
| CSA MAESTRO | Agentic governance emphasises explicit accountability and auditable decisions. |
Map every access review to a responsible owner and verify evidence is stored with the entitlement record.
Related resources from NHI Mgmt Group
- Who is accountable when user access reviews are incomplete or not evidence-ready?
- Who is accountable for completing access reviews and preserving evidence for audit purposes?
- When do NHI access reviews create more value than a one-time cleanup?
- Who is accountable when user access reviews are not completed on time?