They fail because the review set is incomplete. If contractors, direct app accounts, shadow IT, shared credentials, and OAuth grants are outside the identity provider, certification only validates a partial environment. That creates formal approvals without full governance, which is why discovery must precede review scope.
Why identity-provider data alone misses the real review population
User access reviews fail when the identity provider is treated as the full system of record for access. The IdP often captures workforce login paths, but not every account, grant, or credential that can reach business systems. That means reviewers may approve what they can see while missing actual access paths that live elsewhere in the stack.
The practical issue is scope, not just data quality. If access exists through IAM and IGA basics, but the review only inspects the IdP record, the certification becomes a partial attestation rather than a governance control.
What stays outside the IdP and breaks certification completeness
Several high-value access paths are commonly omitted from an IdP-only review set: contractor identities managed in separate systems, direct application accounts, shared accounts, OAuth grants, legacy accounts, and shadow IT services. A good review program has to discover those sources first, then reconcile them into the certification scope. That discovery step is what turns access review from an administrative exercise into true entitlement governance.
This is why lifecycle visibility matters. A review model that ignores off-IdP accounts will also miss stale credentials, orphaned access, and unowned access paths, so it should be paired with Access Reviews and Certification Guide and lifecycle controls such as NHI Lifecycle Management Guide where non-human access is part of the environment.
Why formal approval without discovery creates a governance gap
Certification can look successful even when the underlying environment is not. If the review set only includes the IdP, managers can sign off on a clean report while the organisation still has standing access through direct app logins, service credentials, or delegated grants. The result is a governance gap: the process produces approvals, but not confidence that access has been fully examined.
That gap is easiest to miss when the review cadence is fixed and the access landscape changes faster than the source data. In practice, the organisation ends up certifying yesterday’s directory state instead of today’s effective access state.
Risk and Threat Considerations
When access review scope stops at the IdP, undiscovered accounts and grants can persist with no effective oversight. That creates residual privilege, weakens accountability, and leaves attack paths intact even after a review cycle appears to have closed them.
Failure mechanism: Access exists in systems that are not represented in the review source, so reviewers approve an incomplete population and dangerous access survives untouched.
Impact: Excess access can remain active, hidden accounts can be abused, and the organisation may believe it has completed governance when it has only certified part of the environment.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Accounts and grants outside the IdP require complete account inventory and review scope. |
| AC-6 — Least Privilege | Incomplete reviews leave excess access and standing privilege unchallenged. | |
| AU-6 — Audit Review, Analysis, and Reporting | Reviews need evidence that the population and approvals were complete and actionable. | |
| Recommendation — Inventory all account types and certify access against the full population, not the IdP export. Remove unneeded access paths once discovery shows they are no longer required. Correlate review evidence with system logs and entitlement data to validate completeness. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Access review scope must cover all access paths, not only IdP records. |
| A.5.16 — Identity management | Identity governance must include identities managed outside a single directory. | |
| Recommendation — Define access control scope so every active access path is subject to review. Maintain a complete identity inventory across directory, application, and delegated access sources. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | Certification failures arise when access control governance excludes non-IdP accounts and grants. |
| CIS-5 — Account Management | Off-IdP accounts and shared credentials are account-management gaps that reviews must catch. | |
| Recommendation — Centralise access governance enough to review every authoritative access source. Identify and review all active accounts, including direct app and shared accounts. | ||
Practitioner Guidance
What to verify: Confirm the review population from the entitlement source outward, not from the IdP inward. The review set should include direct application accounts, third-party access, shared credentials, and delegated grants, plus a way to prove those sources were enumerated before the campaign began.
Decision rule: If an account or grant can authenticate or authorize access without passing through the IdP, treat it as in scope for certification and do not rely on directory export alone. If you cannot enumerate it, the review is not ready for sign-off.
Practitioner takeaway: Access reviews are only as strong as their discovery boundary, so the real control question is not “who is in the IdP?” but “what can actually reach production and who owns it?”
Related resources from NHI Mgmt Group
- How often should security teams run user access reviews in environments with sensitive data and multiple identity types?
- How should security teams run access reviews for non-human identities?
- Why do user access reviews fail when they are used alone?
- How should security teams reduce stale identity data in access reviews?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org