Access Review
An access review is a process in which an organization examines who has access to its systems, data, and applications to confirm that each person still needs that access. It helps reduce the risk of unauthorized access by identifying and removing permissions that are outdated, excessive, or no longer appropriate. Reviews are often performed periodically and can support broader governance and compliance goals.
An access review is a structured security and governance process for monitoring, assessing, and validating user access privileges and entitlements across systems, groups, and applications. Reviewers, often resource owners, managers, or governance stakeholders, certify or revoke access to enforce least-privilege and to control group membership and application access. In platforms such as Microsoft Entra ID Governance, access reviews can be configured to review group members, application assignments, and guest user access, with reviewers certifying whether continued access is warranted. As a governance and risk-management control, access reviews support but do not by themselves guarantee compliance; their effectiveness depends on review scope, cadence, reviewer diligence, and the quality of underlying identity data. In a virtual CISO engagement, the vCISO typically advises on and helps design access review programs and policies, while operational execution and accountability for access decisions generally remain with the client organization and its resource owners.
Why it matters
Over time, the access rights granted to employees, contractors, and guest users tend to accumulate faster than they are removed. People change roles, projects end, and third-party relationships wind down, yet the permissions granted for those situations often persist. Access reviews exist to counter this drift by periodically confirming that every entitlement still corresponds to a legitimate business need. Without this discipline, organizations gradually build up excessive and outdated access that widens the attack surface and increases the impact of a compromised account.
Access reviews are a core control for enforcing least-privilege and for controlling group membership and application access. As Microsoft's guidance on Entra ID Governance notes, reviews can be used to certify guest user access to groups and to control group membership and application access in support of governance, risk management, and compliance goals. This matters both for internal risk reduction and for demonstrating to auditors and stakeholders that access is being actively governed rather than left to chance. However, an access review is a supporting control, not a guarantee: its value depends on the scope reviewed, the cadence, the diligence of the reviewers, and the quality of the underlying identity data.
It is worth emphasizing what access reviews do not do on their own. They do not prevent breaches by themselves, and a completed review does not certify that an organization is compliant with any given regulation or standard. A review that is rubber-stamped without genuine scrutiny, or that omits critical systems, can create a false sense of assurance. The control is only as strong as the accountability and follow-through behind it, and accountability for access decisions remains with the organization and its resource owners.
Who it's relevant to
Inside Access Review
Common questions
Answers to the questions practitioners most commonly ask about Access Review.