Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› Why are access reviews not enough for Microsoft…
Governance, Ownership & Risk

Why are access reviews not enough for Microsoft 365 data security?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 8, 2026 Domain: Governance, Ownership & Risk

Access reviews only evaluate permissions, and permissions are not the same as exposure. If reviewers do not know which sites, mailboxes or files contain sensitive data, they cannot judge whether a permission grant is high risk. DSPM gives that context, which makes recertification materially more accurate.

Why permissions alone miss the real Microsoft 365 exposure picture

Access reviews answer a narrow question: who has what permission. Microsoft 365 data security requires a broader one: which resources actually contain sensitive business or regulated data, how broadly that data is shared, and whether the granted access matches the data’s risk. Without exposure context, a clean-looking recertification can still leave the highest-risk content effectively open.

That gap matters because Microsoft 365 permissions are often inherited, indirect, or spread across sites, mailboxes, shared drives and collaboration spaces. A reviewer can approve or revoke an entitlement correctly and still miss the practical security issue if the underlying location is low sensitivity, or if a seemingly ordinary permission sits on top of data that should have tighter controls.

In practice, the security problem is not that access reviews are wrong, it is that they are incomplete as a control on their own. They verify entitlement hygiene, but they do not tell you whether a permission grant creates meaningful exposure, blast radius, or compliance impact. That is why exposure-aware context, often delivered through DSPM, changes the quality of the review.

What DSPM adds to access recertification

DSPM provides the missing data layer by identifying where sensitive information lives, how it is classified, and where risky sharing or oversharing exists. That lets a reviewer judge whether a permission is merely present or actually consequential. The same access grant can be low concern on a low-value collaboration site and high concern on a repository with customer data, financial records, or confidential internal material. For a broader governance view, compare that with Access Reviews and Certification Guide and IAM and IGA Basics, which show why access governance works best when entitlement data and context are evaluated together.

DSPM also improves prioritisation. Instead of recertifying every permission as if it carries equal risk, teams can focus on high-value locations, overly shared content, dormant but exposed repositories, and places where access is wider than the data warrants. That makes recertification more targeted and makes remediation easier to defend to auditors and data owners.

For Microsoft 365 specifically, this is especially important because collaboration is designed to be fluid. Sharing, guest access, group membership and inherited permissions can all be legitimate, but they can also create hidden exposure if no one tracks where sensitive content accumulates. The useful question becomes not only “should this person have access?”, but “should this sensitive content be accessible here at all?”

Where access reviews fail in Microsoft 365 governance

Access reviews break down when they are treated as a substitute for data discovery. If the reviewer cannot distinguish routine business content from sensitive material, the process can devolve into rubber-stamping. That is the classic failure mode: the entitlement appears reasonable in isolation, so it survives, even though the resource itself deserves stronger governance. This is why access governance and data visibility need to move together, not sequentially.

Another weakness is scale. Microsoft 365 estates often contain thousands of sites, shared mailboxes and files, and the review burden can push owners toward default approval. A DSPM-backed view reduces that fatigue by highlighting the items where a recertification decision is genuinely meaningful. It also helps separate ordinary access cleanup from real security work, such as reducing exposure on repositories that hold regulated or business-critical information. The same principle appears in Top 10 NHI Issues, where excessive access becomes materially worse when visibility is poor, and in Identity Visibility and Intelligence Platforms (IVIP) Guide, where visibility is the prerequisite for better governance decisions.

The practical takeaway is that access reviews are still useful, but only as one control in a larger governance loop. They answer who, while DSPM answers what and how sensitive. Without both, you can certify access accurately and still fail to protect the data that matters most.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, CIS Controls v8 and CSA Cloud Controls Matrix set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-2 — Account ManagementAccess reviews support periodic review of account and entitlement assignments.
AC-6 — Least PrivilegeThe answer hinges on whether access exceeds what the data exposure warrants.
AU-6 — Audit Review, Analysis, and ReportingExposure-aware recertification depends on reviewable evidence about where sensitive data lives.
Recommendation — Review account assignments on a recurring basis and remove unnecessary access. Limit permissions to the minimum needed for the data and role. Correlate access activity and data sensitivity to identify risky entitlements.
ISO/IEC 27001:2022A.5.15 — Access controlMicrosoft 365 recertification is an access-control governance practice that needs data context.
A.8.12 — Data leakage preventionDSPM strengthens review quality by revealing sensitive data exposure and oversharing.
A.8.15 — LoggingEffective recertification depends on traceability of access and exposure-relevant changes.
Recommendation — Define and enforce access rules based on sensitivity and business need. Identify and reduce accidental disclosure paths for sensitive information. Log access and sharing changes so reviewers can validate risky grants.
CIS Controls v8CIS-5 — Account ManagementThe question is about recertifying who can access M365 data and why that is incomplete alone.
Recommendation — Maintain and review accounts and access rights on a regular cycle.
CSA Cloud Controls MatrixIAM — Identity and Access ManagementCloud access governance for Microsoft 365 requires both entitlement control and context.
Recommendation — Tie access approvals to data sensitivity and business justification.

Practitioner Guidance

What to prioritise: Start with the Microsoft 365 locations most likely to contain sensitive or regulated data, then align review effort to those repositories first. Low-value content can be reviewed on a lighter cadence; high-exposure content needs deeper scrutiny.

What to verify: Before trusting a recertification campaign, verify that reviewers can see data classification, sharing scope and ownership for each site, mailbox or file set. If they cannot explain why a permission is acceptable in the context of the data, the review is not mature enough.

Common mistake: Treating “access approved” as equivalent to “data secure.” In Microsoft 365, the stronger control is the combination of entitlement review plus exposure visibility, because the risk is created by their intersection.

Practitioner takeaway: Use access reviews to govern permissions, but use DSPM to decide whether those permissions are actually risky. Recertification becomes materially better only when reviewers understand the sensitivity of what those permissions can reach.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org