Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› Should organisations prioritise just-in-time access before expanding recertification…
Governance, Ownership & Risk

Should organisations prioritise just-in-time access before expanding recertification cycles?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 6, 2026 Domain: Governance, Ownership & Risk

Yes, when privileged roles are the main exposure. Recertification checks what already exists, but just-in-time access prevents unnecessary elevation from lingering in the first place. If the environment still relies on standing admin access, reducing duration of privilege usually delivers faster risk reduction than making review cycles more frequent.

Why JIT usually delivers faster risk reduction than longer recertification cycles

When standing privilege is the core exposure, the biggest gain comes from shrinking the time a powerful entitlement exists, not from asking reviewers to approve it again more often. JIT changes the exposure window itself. Recertification still matters, but it is a slower control because it validates what is already present rather than preventing unnecessary elevation from persisting.

That is why JIT is usually the stronger first move when privileged access is broad, frequent, or easy to leave in place. Just-in-Time Access and Zero Standing Privilege Guide shows the control logic clearly: make privilege eligible, time-bound, and explicit instead of permanently available. In practice, this also reduces the review burden that recertification inherits when entitlement sprawl is already large.

Recertification remains useful for governance, but it is not a substitute for removing standing access paths. Access Reviews and Certification Guide is most valuable when organisations need to improve review quality, close the loop on removals, and avoid rubber-stamping. If the privilege model itself is weak, making reviews more frequent only means reviewing the same excess more often.

Where recertification still belongs in the control stack

Recertification is strongest as a validation and cleanup control. It helps identify stale grants, confirm ownership, and catch access that JIT alone will not redesign, such as inherited role structures, dormant entitlements, or bad approvals. IAM and IGA Basics is the right conceptual frame here: provisioning, authorization, access reviews, and role governance are related, but they do different jobs.

That means the sequencing question matters. If the environment still depends on permanent admin access, JIT often gives more immediate risk reduction because it reduces exposure duration and blast radius at the point of use. If the core problem is entitlement hygiene, role design, or weak ownership, recertification helps expose those defects, but it will not fix them on its own. In mature programmes, review cycles become a backstop for controls that should already be right-sized.

JIT also works best when tied to a broader privileged access model rather than treated as a one-off feature. Privileged Access Management Guide is relevant because it links JIT with vaulting, session control, and zero standing privilege. That combination matters more than a shorter review cadence when the main issue is uncontrolled elevation.

What should drive the sequencing decision

If the question is “what should we do first?”, the deciding factor is the dominant failure mode. When the main problem is standing privileged access, the first objective is to stop unnecessary privilege from being continuously available. When the main problem is poor ownership or entitlement drift, recertification may need to tighten governance first, but it should still feed a move toward JIT rather than become the long-term answer.

For organisations with service accounts, cloud admins, or emergency roles, the same logic applies. Service Account Security Guide and Break-Glass and Emergency Access Account Guide both reinforce a practical point: some access must exist, but it should be rare, tightly bounded, and observable rather than permanently active. JIT is the better default for routine elevation; recertification is the better control for confirming that exceptional access remains exceptional.

Risk and Threat Considerations

Standing privilege creates a larger attack window, more opportunities for misuse, and a weaker accountability story when access is not actively needed. Recertification can discover excess after it has already been granted, but it does not stop an attacker or careless insider from using that privilege during the interval between reviews.

Failure mechanism: Excess privilege persists because review cycles are periodic, while elevated access is available continuously. If access is not time-bound, compromise, misuse, and lateral movement can happen long before the next certification campaign closes the gap.

Impact: The organisation carries more standing exposure than it needs, especially for admin, cloud, and service access. That increases the chance that a single account compromise or mistaken approval can translate into broad operational or security impact.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-2 — Account ManagementJIT and recertification both affect who has active access and for how long.
AC-6 — Least PrivilegeThe question is about reducing unnecessary elevation before it lingers.
IA-5 — Authenticator ManagementJIT and privileged access controls depend on managing credentials that enable elevation.
Recommendation — Limit standing access and revoke unneeded privilege promptly. Apply least privilege to minimise standing admin access and elevation scope. Rotate and control authenticators that can activate privileged access.
ISO/IEC 27001:2022A.5.15 — Access controlAccess control policy must decide when privilege is granted, approved, and removed.
A.8.2 — Privileged access rightsThe topic directly concerns reducing exposure from privileged rights.
Recommendation — Define when access is eligible, time-bound, and revoked. Review and restrict privileged rights before expanding review cycles.
CIS Controls v8CIS-5 — Account ManagementStanding privilege, recertification, and JIT are account-management concerns.
CIS-6 — Access Control ManagementThe decision is about how access is granted, bounded, and revoked.
Recommendation — Inventory privileged accounts and remove unnecessary standing access. Enforce time-bound privileged access and verify revocation.

Practitioner Guidance

What to prioritise: If privileged roles are the main exposure, prioritise JIT for routine elevation before increasing recertification frequency. Use recertification to clean up residual entitlements, not to compensate for permanent privilege that should not exist.

What to verify: Confirm that elevated access is actually time-bound, approved, and revoked automatically. If a role is “eligible” in name but still behaves like standing access in practice, the risk reduction you expect from JIT is not real.

Common mistake: Treating review cadence as the main control when the real defect is entitlement design. Faster recertification can improve governance, but it rarely beats removing persistent privilege from the first place.

Practitioner takeaway: Use JIT to reduce exposure duration, then use recertification to keep the entitlement model honest. If you reverse that order, you usually spend more effort reviewing excess access instead of eliminating it.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 6, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org