Risk driven certification
Risk driven certification reviews the users whose identity risk is highest, so that access recertification effort is focused where the exposure is greatest.
A risk driven campaign selects its population from the aggregate identity risk score: every identity at or above a configured threshold is pulled into the campaign. There is no longer a separate list of individual "risk event types" (title change, supervisor change, department change) to choose from — those discrete triggers have been retired in favor of the unified risk score.
Configuring risk driven certification
Open the certification's Risk tab to configure how risk drives the campaign:
| Setting | Description |
|---|---|
| Risk score threshold | Minimum aggregate identity risk score (0–100). Identities whose risk score is at or above this value are included in the campaign. Setting a threshold is what makes a risk-driven campaign ready to preview and launch. |
| Auto-certify low-risk entitlements | When enabled, entitlements whose risk score is at or below the Auto-certify max score are certified automatically instead of being routed to a reviewer. |
| Auto-certify max score | Inclusive maximum entitlement risk score (0–100) eligible for auto-certification. Shown only when auto-certify is enabled. |
| Auto-certified item visibility | Whether auto-certified items are hidden from reviewers or shown as pre-approved. Shown only when auto-certify is enabled. |
Technically, a risk driven review works the same way as any other review. The only difference is how users are selected for review: instead of an explicit target list, the campaign scope is resolved from the identity risk score threshold above. How the aggregate identity risk score itself is calculated is described in Risk factor configuration.
Once a threshold is set, the campaign can be previewed and launched exactly like a user or application certification. Preview shows the in-scope identities and their reviewable entitlements before you commit; see Campaign preview.
Starting a campaign launches a review for the in-scope users, and each approver sees and reviews the entitlements assigned to them just as in any other campaign.
For example, SelfService shows 49 records in tile view and entitlement view, but on manual calculation, only 44 entitlements exist. Here, SelfService shows 49 records in the tile view and these records are not entitlements. These are access review items; namely, there might be one "AD member" role, but there are two users (A and B) having this role and participating in the certification, thus there are two access review items for this "AD member" role, where one item belongs to user A and another to user B.
In manual calculation, a user who appears to be the reviewer of the campaign is also part of the review with other users. Since the situations where a user can review their own access are avoided, those accessory items are automatically transferred to the user’s manager.