Risk driven certification

Risk driven certification reviews the users whose identity risk is highest, so that access recertification effort is focused where the exposure is greatest.

A risk driven campaign selects its population from the aggregate identity risk score: every identity at or above a configured threshold is pulled into the campaign. There is no longer a separate list of individual "risk event types" (title change, supervisor change, department change) to choose from — those discrete triggers have been retired in favor of the unified risk score.

Configuring risk driven certification

Open the certification's Risk tab to configure how risk drives the campaign:

SettingDescription
Risk score thresholdMinimum aggregate identity risk score (0–100). Identities whose risk score is at or above this value are included in the campaign. Setting a threshold is what makes a risk-driven campaign ready to preview and launch.
Auto-certify low-risk entitlementsWhen enabled, entitlements whose risk score is at or below the Auto-certify max score are certified automatically instead of being routed to a reviewer.
Auto-certify max scoreInclusive maximum entitlement risk score (0–100) eligible for auto-certification. Shown only when auto-certify is enabled.
Auto-certified item visibilityWhether auto-certified items are hidden from reviewers or shown as pre-approved. Shown only when auto-certify is enabled.

Technically, a risk driven review works the same way as any other review. The only difference is how users are selected for review: instead of an explicit target list, the campaign scope is resolved from the identity risk score threshold above. How the aggregate identity risk score itself is calculated is described in Risk factor configuration.

Once a threshold is set, the campaign can be previewed and launched exactly like a user or application certification. Preview shows the in-scope identities and their reviewable entitlements before you commit; see Campaign preview.

Note the number of risk-selected identities does not correlate with the number of access review items in the initiated campaign. The identities indicate whose access should be reviewed; the number of access review items is the total number of entitlements held by those in-scope identities.

Starting a campaign launches a review for the in-scope users, and each approver sees and reviews the entitlements assigned to them just as in any other campaign.

Note that SelfService count for records in tile view and entitlement view might be different from the count on manual calculation.

For example, SelfService shows 49 records in tile view and entitlement view, but on manual calculation, only 44 entitlements exist. Here, SelfService shows 49 records in the tile view and these records are not entitlements. These are access review items; namely, there might be one "AD member" role, but there are two users (A and B) having this role and participating in the certification, thus there are two access review items for this "AD member" role, where one item belongs to user A and another to user B.

In manual calculation, a user who appears to be the reviewer of the campaign is also part of the review with other users. Since the situations where a user can review their own access are avoided, those accessory items are automatically transferred to the user’s manager.