Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› Should security teams rely on conditional access instead…
Governance, Ownership & Risk

Should security teams rely on conditional access instead of access reviews?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 8, 2026 Domain: Governance, Ownership & Risk

No. Conditional access helps enforce context at the point of access, but it does not remove permissions that should no longer exist. Access reviews are what catch stale rights and mismatched entitlements over time. The two controls solve different problems, so both are needed in a mature cloud IAM programme.

Why Conditional Access Cannot Replace Access Reviews

conditional access is a point-in-time enforcement control. It answers whether a sign-in or session should be allowed right now, based on signals such as user risk, device posture, location, or authentication strength. Access reviews are a lifecycle control. They answer whether the underlying entitlement should still exist at all, and they are the mechanism that removes stale or excessive access over time.

That distinction matters because the most common failure mode in mature IAM programmes is not only bad logins, but accumulated permissions. A user can pass conditional access and still retain roles, app assignments, group memberships, or delegated access that no longer match their job. To manage that longer-term drift, teams need access certification and related governance workflows such as Access Reviews and Certification Guide and IAM and IGA Basics.

In practice, conditional access can block unsafe sessions, but it does not prove that access is still appropriate, and it does not reclaim privileges that have outlived their business need. Access reviews are the control that surfaces orphaned, dormant, or mismatched entitlements, especially in environments with role changes, contractors, shared admin paths, and machine or workload identities. That is why lifecycle hygiene and review discipline belong together in the same access governance model, not as substitutes. NHI Lifecycle Management Guide reinforces the same principle for non-human identities, where stale permissions often persist longer than the workload that needed them.

Where Conditional Access Helps, and Where It Stops

Conditional access is strongest at the perimeter of an access decision. It can require stronger authentication, deny access from unmanaged devices, step up on risky sign-ins, or enforce location and network conditions. That makes it highly effective for reducing immediate exposure during a login event or token request. It is less effective as a governance control because it evaluates context, not entitlement correctness.

That limit is easy to miss in cloud estates because a modern user or service can have many simultaneous permissions across SaaS apps, cloud consoles, APIs, and delegated admin surfaces. A control that approves the current session can still leave excessive standing access in place. The broader identity programme therefore needs both event-driven enforcement and periodic governance, which is why practitioners often pair conditional access with a zero trust model and policy review workflows. The relationship is well aligned with Zero Trust Identity Guide and Identity Provider and SSO Security Guide.

For cloud IAM programmes, the key question is not whether access can be blocked at login, but whether the entitlement set is still justified. If you only rely on conditional access, you may reduce blast radius for some sessions while still carrying unnecessary standing access, hidden privilege chains, and review debt.

How to Use Both Controls Without Confusing Their Roles

The practical design pattern is straightforward: use conditional access to shape how access is granted, and use access reviews to decide whether access should remain granted. Conditional access should be treated as a runtime policy layer, while access reviews should be treated as a governance and recertification layer. Each control can inform the other, but neither replaces the other.

Teams get the best results when review scopes are risk-based. High-privilege roles, sensitive apps, long-lived external access, and service identities should be reviewed more frequently than low-risk standard access. Reviewers also need clean evidence, because rubber-stamping campaigns create a false sense of control. For that reason, governance content such as IGA Buyer's Guide and Privileged Access Management Guide is useful where reviews intersect with standing privilege and just-in-time access.

In a healthy programme, conditional access reduces exposure at the session boundary, while reviews remove rights that should not survive the next business cycle. If you are only measuring blocked sign-ins, you are missing entitlement drift. If you are only running reviews, you may still be allowing unsafe sessions. Mature cloud IAM needs both signals.

Risk and Threat Considerations

Relying on conditional access alone creates entitlement drift risk. Attackers do not need to defeat the access policy if excessive rights already exist, and insiders or compromised accounts can continue to use permissions that should have been removed. The control gap is especially visible when stale roles, dormant accounts, or overprivileged service identities remain active across multiple systems.

Failure mechanism: Conditional access evaluates the current access attempt, but it does not continuously remove obsolete roles, group memberships, or delegated permissions. That leaves accumulated privilege in place until a review or lifecycle event clears it.

Impact: Unneeded access persists, blast radius grows, and compromise recovery becomes harder because revocation starts later than it should. Over time, this increases both misuse potential and governance exposure.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CSA Cloud Controls Matrix, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
CSA Cloud Controls MatrixIAM — Identity & Access ManagementConditional access and access reviews are identity governance controls for cloud access decisions.
Recommendation — Use IAM controls to separate runtime access enforcement from periodic entitlement recertification.
NIST SP 800-53 Rev 5AC-2 — Account ManagementAccess reviews and stale entitlement removal map directly to account and entitlement lifecycle management.
IA-5 — Authenticator ManagementConditional access often depends on authentication signals and session posture, so authenticator lifecycle remains relevant.
Recommendation — Review and remove unnecessary accounts, roles, and memberships on a recurring schedule. Manage authenticators and related secrets so access decisions reflect current trust state.
ISO/IEC 27001:2022A.5.15 — Access controlThe question is about choosing the right access control and governance mechanisms in an ISMS.
Recommendation — Define access control policy so session enforcement and entitlement review work together.
CIS Controls v8CIS-6 — Access Control ManagementAccess reviews and conditional access both support disciplined access control management.
Recommendation — Establish and maintain access control processes that remove stale privileges and enforce policy.

Practitioner Guidance

What to prioritise: Treat access reviews as the control that cleans up standing entitlements, and conditional access as the control that gates each session. If one is missing, the programme is incomplete.

What to verify: Confirm that review campaigns actually remove access, not just collect attestations. The evidence that matters is revoked membership, deprovisioned entitlement, or a documented exception with expiry.

Common mistake: Using conditional access metrics as proof of access governance. They show enforcement quality, not whether the entitlement set is still right.

Practitioner takeaway: The decision is not conditional access versus access reviews. Conditional access limits unsafe entry, but access reviews are what keep the entitlement baseline from drifting beyond business need.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org