Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What breaks when user access reviews rely on…
Governance, Ownership & Risk

What breaks when user access reviews rely on directory data alone?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 8, 2026 Domain: Governance, Ownership & Risk

Directory-only reviews miss apps and access paths that exist outside the identity provider, so the organisation certifies an incomplete estate. That creates false confidence, because the review is formally correct but operationally blind to shadow IT, direct SaaS use, and other live permissions that need governance.

Why directory-only reviews miss the control objective

Directory data is a useful starting point, but it is not the same thing as the full access estate. A review built only from the identity provider can confirm what the directory knows, yet still miss direct application accounts, vendor-managed access, local entitlements, and other live paths that were granted elsewhere. That makes the certification process look complete while leaving material access outside the review boundary.

In practice, the gap matters because access governance is supposed to validate actual effective access, not just records in one system of truth. A directory-only campaign can therefore produce a formally clean attestation that does not reflect how people really reach sensitive apps, data, and functions. Access Reviews and Certification Guide is a useful companion when the goal is to design reviews that catch real access rather than administrative snapshots.

Where the blind spots usually come from

The most common failure mode is fragmented entitlement data. Some permissions are created inside SaaS platforms, some are inherited through federated roles, some sit in legacy directories, and some are granted directly to service teams or third parties without a matching directory record. If the reviewer only inspects the directory, those permissions are invisible and never challenged.

This is why the review design has to match the actual control plane, not the preferred reporting source. A good identity process accounts for joiner-mover-leaver changes, role assignments, application-specific grants, and non-directory accounts as part of one entitlement picture. IAM and IGA Basics helps anchor that broader view, and IGA Buyer's Guide is relevant when the organisation needs connectors and coverage across disconnected applications.

What a complete certification should prove

A useful review proves that the organisation can enumerate access across the full estate, assign ownership for each access path, and decide whether the access is still justified. That usually means reconciling directory data with application inventories, privileged pathways, SaaS admin consoles, and any shadow IT discovered outside the central identity stack.

For complex estates, the practical test is whether the reviewer can explain every access item in terms of business need, owner, and revocation path. If an access right cannot be mapped back to an accountable owner and a removal mechanism, it is not really governed. Identity Visibility and Intelligence Platforms (IVIP) Guide is helpful when the core issue is finding the hidden access that a directory alone will not show.

Risk and Threat Considerations

Directory-only reviews create a false negative problem: the organisation believes access is clean because the sampled records look clean, while unmanaged permissions continue to exist elsewhere. That leaves shadow IT, direct SaaS use, stale entitlements, and excess privilege outside governance, which is exactly where attackers and insiders benefit from weak oversight.

Failure mechanism: The control scope is narrower than the real access surface, so review evidence is derived from incomplete inventory and misses active permissions that were created outside the identity provider.

Impact: The organisation certifies incomplete access, weakens least-privilege enforcement, and may fail to revoke high-risk access that remains exploitable after the review closes.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AU-6 — Audit Record Review, Analysis, and ReportingAccess reviews need complete evidence across systems, not a single directory.
IA-5 — Authenticator ManagementHidden access paths often persist through unmanaged credentials and account lifecycle gaps.
AC-2 — Account ManagementThe question concerns whether all active accounts and access paths are actually covered by review.
Recommendation — Correlate directory and application audit data before certifying access. Inventory and govern all authenticators that can sustain access outside the directory. Include non-directory accounts and application-native entitlements in account reviews.
CIS Controls v8CIS-5 — Account ManagementDirectory-only review gaps are account-management gaps across the broader estate.
Recommendation — Inventory and review accounts in applications, SaaS, and directories together.
ISO/IEC 27001:2022A.5.15 — Access controlThe issue is incomplete access governance because some access is outside the directory view.
Recommendation — Define review scope across all access paths, not only the identity provider.

Practitioner Guidance

What to verify: Verify that the access review source set includes application-native entitlements, federated and delegated access, privileged accounts, and any known shadow IT or direct SaaS paths. If those sources are absent, treat the review as partial, not complete.

Decision rule: If an application can grant or retain access independently of the directory, the review must consume that application’s entitlement data as well as directory records. If it cannot, you still need evidence that no parallel access path exists before you trust the certification.

What good looks like: A reviewer can trace each meaningful access path to an owner, a justification, and a revocation mechanism, and the review outcome changes when non-directory access is discovered rather than merely recording it.

Practitioner takeaway: Directory accuracy is necessary, but governance only works when the review covers every place access can actually live, otherwise the process certifies confidence instead of control.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org