Use group-based reviews when access is commonly granted through SSO groups, because the review boundary matches how access is actually administered. Use user-based reviews for individually assigned access and privileged accounts. The right choice is the one that reflects the operating model, not the one that feels simpler on paper.
Why the review boundary should match how access is actually granted
Access reviews work best when the review unit matches the way entitlements are administered. If most access comes from group membership, group-based certification lets reviewers assess the actual access path instead of reconstructing it user by user. That makes the review faster, more accurate, and easier to defend when access is inherited through role or group assignment.
Group-based review is also the cleaner fit when one approval decision fans out to many permissions, because the control question is whether the group should exist and who should remain in it. For a broader access-governance view, IAM and IGA Basics explains why entitlement ownership and review boundaries matter more than review format alone.
When user-based reviews are the better control
User-based reviews are more appropriate when access is granted individually, when privileged accounts sit outside normal group structures, or when the account itself is the security boundary. In those cases, a group-only review can miss directly assigned permissions, stale exceptions, or access that bypasses standard provisioning.
That is why high-risk or exception-heavy environments usually need a user-level view for the accounts that matter most. A Privileged Access Management Guide is the right companion when you need to distinguish ordinary inherited access from elevated access that deserves tighter review.
For organisations that blend both models, the review design should follow the entitlement path, not a single policy preference. In practice, that means group-based certification for standard delegated access and user-based certification for direct grants, break-glass accounts, and other exceptions. The Access Reviews and Certification Guide is useful here because it focuses on the review process as a control, not just the administrative workflow.
How to decide which model is right for a given population
The decision hinges on whether the question is “who should belong to this access package or group?” or “should this person keep this specific access?” If the entitlement is inherited, a group review is usually more operationally honest. If the entitlement is direct, temporary, privileged, or atypical, user-level review is usually the better audit trail.
The same logic applies at scale. Large environments often need both views, because a pure user-based campaign can become noisy and slow, while a pure group-based campaign can obscure exceptions and unusual grants. A practical design also benefits from Role Mining and Role Design Guide, since well-structured roles and groups reduce review ambiguity before the campaign starts.
Risk and Threat Considerations
Review misalignment creates blind spots. Group-only certification can hide direct entitlements, while user-only certification can bury inherited access inside long permission lists and create reviewer fatigue. Either failure mode increases the chance of rubber-stamping, excess access persisting, or privileged access slipping past the review.
Failure mechanism: The review boundary does not match the access boundary, so reviewers validate the wrong object and miss the entitlement that actually confers access.
Impact: Orphaned, excessive, or privileged access can survive a certification cycle, which weakens least privilege and raises the likelihood of unauthorized use or easier lateral movement after compromise.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Access reviews and certification support ongoing account and entitlement oversight. |
| AC-6 — Least Privilege | The question is about preventing excessive access through the right review boundary. | |
| IA-5 — Authenticator Management | User-based reviews often surface direct credentials and privileged account controls. | |
| Recommendation — Review accounts and group membership against current need to retain only authorised access. Certify only the access required for each role, group, or account to enforce least privilege. Track and review authenticators tied to accounts so stale or excessive access is removed promptly. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Access review design is part of access control governance in Annex A. |
| A.5.18 — Access rights | The topic concerns periodic review and confirmation of access rights. | |
| Recommendation — Define review boundaries to match how access is granted and approved. Revalidate access rights periodically and revoke entitlements that no longer have business need. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | Periodic access reviews are a core access control management activity. |
| Recommendation — Implement periodic certification of group and user access and remediate exceptions quickly. | ||
Practitioner Guidance
What to prioritise: Start by mapping how access is granted for the population you are certifying. If the environment is group-driven, review groups and their membership; if it is exception-driven or privilege-heavy, review accounts and direct grants first.
What to verify: Confirm that every access review item has a clear owner, a single review boundary, and a reversible remediation path. If reviewers cannot tell whether a permission is inherited or direct, the model is not ready for certification.
Common mistake: Treating group-based review as universally simpler. It is simpler only when the operating model is already group-centric; otherwise it shifts complexity into unresolved exceptions and false confidence.
Practitioner takeaway: Choose the review unit that matches the entitlement source of truth, because the control is only as strong as the boundary it asks reviewers to judge.
Related resources from NHI Mgmt Group
- How should security teams use user-based access reviews for offboarding and project closures?
- When should organisations prioritise application-based reviews over user-based or group-based reviews?
- How should organisations use user access reviews to reduce insider threat risk?
- Should organisations use attribute-based access control or identity reviews to manage modern access risk?