Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› When should access reviews include applications published through…
Governance, Ownership & Risk

When should access reviews include applications published through Azure AD Application Proxy?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 8, 2026 Domain: Governance, Ownership & Risk

Whenever the published app exposes business-critical workflows, regulated data, or separation-of-duties sensitive functions. A proxy does not reduce the need to certify access, because the underlying entitlements still determine who can reach the application and what they can do once inside. Include these apps in the same review cycle as other privileged access paths.

Why Azure AD Application Proxy apps still belong in access reviews

Azure AD application proxy changes the access path, not the access decision. If an application is reachable through the proxy, the underlying account, group, role, or entitlement model still governs who can use it and what they can do. That is why proxy-published apps should be certified with the same care as directly exposed apps, especially when the business impact of misuse is high.

In practice, the question is not whether the proxy is secure enough to avoid review. It is whether the application behind it carries business-critical, regulated, or segregation-sensitive access that merits periodic certification. If the answer is yes, the review belongs in scope regardless of how the traffic reaches the app.

Organizations often miss that the proxy can hide complexity from users while leaving privilege intact. A reviewer should still be able to answer whether the access is needed, whether the entitlement matches the person or role, and whether the app should be subject to a tighter review cadence because it touches finance, operations, customer data, or approval workflows.

What changes, and what does not, when the app is published through a proxy

The proxy mainly changes connectivity and publishing mechanics. It can simplify external access, reduce the need for inbound exposure, and centralize some network controls, but it does not erase the business risk of excessive access. The control question remains the same: who is entitled, who approved it, and does that access still match the user’s current job or function?

That is why access reviews should be driven by the sensitivity of the application and the entitlement model, not by the hosting path. A proxy-published app may still require role-based access review, separation-of-duties checks, and owner attestation if it is used to approve payments, manage production systems, administer records, or process regulated information.

Where proxy publication becomes especially important is in environments with a large number of externally reachable internal apps. The proxy can make inventory easier, but it can also encourage a false sense that the app is “already protected.” Certification is the place to test that assumption against actual business need and actual privilege.

Which apps deserve the highest review priority

Review frequency should rise with impact. Applications published through Azure AD Application Proxy belong in the regular review cycle when they expose regulated data, support critical operations, or contain functions where one user’s access could override another user’s control. That includes approval paths, finance workflows, HR systems, admin consoles, and any app where access directly affects confidentiality, integrity, or accountability.

Proxy-published apps with service or shared access deserve extra scrutiny because reviewers can otherwise assume the proxy layer is the main control. The real control is still the entitlement behind the app, so the review should confirm whether the access is individually assigned, role-based, time-bounded, or still carried through legacy group membership.

For identity and governance teams, the practical rule is to classify these apps by business function, then review them alongside other privileged access paths. That is consistent with broader access governance practice, and it is easier to defend in audit than a special exception that treats “published through a proxy” as a reason to review less often.

Risk and Threat Considerations

Proxy publication can reduce perimeter exposure, but it can also mask privilege drift if reviewers focus on the access method instead of the entitlement behind it. If a proxy-published app governs sensitive workflows or regulated data, stale or overbroad access can persist long after the business need has changed.

Failure mechanism: The reviewer sees a centrally published application and assumes the proxy layer is the main protection, while the underlying group, role, or account assignment remains unchecked. Excess entitlement, weak ownership, or missed recertification then leaves the app open to unauthorized use or separation-of-duties violations.

Impact: Unreviewed access can enable improper approvals, data exposure, fraud, audit findings, or downstream privilege abuse inside the application. In higher-risk environments, the proxy becomes only a transport detail, while the ungoverned entitlement remains the real control failure.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS-6 — Access Control ManagementProxy-published apps still require account and access review to remove unnecessary access.
Recommendation — Review and revoke unnecessary access to proxy-published applications on a recurring basis.
NIST SP 800-53 Rev 5AC-2 — Account ManagementAccess reviews depend on governing who has accounts and entitlements to the published app.
AC-6 — Least PrivilegePublished access paths should not expand privileges beyond what the app role requires.
Recommendation — Ensure account assignments for proxy-published apps are periodically reviewed and approved. Limit proxy-published application access to the minimum privileges needed for the role.
ISO/IEC 27001:2022A.5.18 — Access rightsAccess rights to published applications need periodic review and adjustment as business need changes.
A.8.2 — Privileged access rightsProxy-published admin or sensitive apps often involve privileged access that warrants tighter certification.
Recommendation — Periodically review and adjust access rights for proxy-published applications. Apply stricter review and approval to privileged access on proxy-published applications.

Practitioner Guidance

What to verify: Confirm that each proxy-published app has an owner, a business criticality label, and a clear entitlement model before it enters the review campaign. If the app supports sensitive workflows, require reviewers to evaluate the role or group assignment, not just the user list.

Decision rule: If the application can approve, modify, or expose regulated or high-impact business data, include it in the same access certification cycle as other privileged paths. If it is low impact and broadly used, you can review it less aggressively, but not because it is published through a proxy.

Common mistake: Treating the proxy as an access governance control in itself. It is a publishing pattern, not a substitute for entitlement review, ownership, or periodic recertification.

Practitioner takeaway: Review the application by business sensitivity and entitlement risk, not by how it is delivered. If the access would be hard to defend after an incident or audit, it belongs in scope.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org