Targeted review

Recertification in Identity Management

Confirm access rights regularly and deliberately

Recertification means that responsible owners actively confirm at defined intervals who should still belong to which group, with administrative groups reviewed more frequently and regular groups less often. The FirstWare IDM-Portal translates access rights into clear business language. This allows many checks to run automatically where rules are sufficient, while deliberate reviews take place where they matter.

Recertification in Identity Management with FirstWare IDM-Portal
Siegel Made in Germany

Made in Germany

firstware-dsgvo-nis2-konform

GDPR & NIS2 compliant

firstware-25-Jahre

25 Jahre IAM Experts

Vendor- & cloud-independent

Vendor- & cloud-independent

Quick Navi

Review cycles

To individual review cycles

Responsibility

To escalation & evidence

Automation

To automated workload reduction

Reality Check:
When no one reviews what was once approved

 

Access rights are granted for good reasons: new projects, department changes and special assignments. But they are rarely removed with the same consistency. Without a reliable, understandable review rhythm, the number of overprivileged accounts continues to grow.

Gradual accumulation of access rights

Department changes accumulate access rights while old ones are never removed.

Blanket approval instead of real review

Too many cryptic codes lead to reflexive “Everything OK” approvals.

Expired deadlines without consequences

Without escalation, reviews simply remain buried in the inbox.

No distinction between group types

Critical admin groups are reviewed just as rarely as non-critical standard groups.

Days of detective work during audits

Without a review cycle, every auditor question turns into an Excel search.

Recertification in IAM: overprivileged accounts grow without a review cycle

Your recertification with the IDM-Portal

FirstWare IDM-Portal: recertification with understandable access rights in plain language

Understandable access rights,
deliberately reviewed

Technology translated into plain language

Recertification means that responsible owners actively confirm at defined intervals who should still belong to which group, with critical admin groups reviewed more often and non-critical standard groups less often.

In many IGA solutions, recertification fails because attribute names are difficult to understand. The FirstWare IDM-Portal translates technical directory data into the language of your business departments.

Decision-makers immediately see in plain language who has which rights and can decide conveniently with one click via the web interface. You gain real control for your IT security.

Relief through
intelligent automation

Where rules apply, manual review is no longer needed

Not every group membership requires manual confirmation. When you control standard groups via attribute-based automation (RBAC/ABAC), for example by location or department, manual review effort is eliminated. If the attribute changes in the HR system, access is automatically cleaned up.

For recertification, only what truly requires a deliberate human decision remains, such as particularly sensitive group memberships or administrative permissions.

Automated recertification through attribute-based RBAC/ABAC rules in the IDM-Portal
Recertification: define flexible review cycles per group in the FirstWare IDM-Portal

Review cycles aligned with
actual risk

Individual intervals instead of a one-size-fits-all model

Not every permission needs the same review interval. In the IDM-Portal, you define flexibly per group or group type how often reviews take place (monthly, quarterly, semi-annually or annually) and who is responsible.

Assignment is handled easily using naming conventions, such as the prefix "ADM" for administrative groups, which are then automatically reviewed more frequently than regular teams. You invest review effort exactly where the risk is highest.

Deadlines and automatic escalation management

No review remains unnoticed

When a recertification is due, the responsible Group Owner is notified automatically. If they do not respond in time, automatic reminders follow, additionally sent to the responsible manager before IT security is involved as the final escalation level.

After the deadline expires, a final result report is sent, regardless of whether the review was completed or not.

Escalation management for missed recertification deadlines in the IDM-Portal
Tamper-proof log of all recertification decisions in the FirstWare IDM-Portal

Every decision is documented
automatically

Review evidence in seconds instead of hours

Every confirmation, every rejection and every access revocation is logged tamper-proof with timestamp and decision-maker ID.

When auditors request evidence under NIS2, ISO 27001, GDPR, TISAX or KRITIS, you can export the finished review report in seconds.

What is the FirstWare IDM-Portal?

Flexible IAM solution for Identity Governance & Administration

 

The FirstWare IDM-Portal is a user-friendly IAM solution for automated provisioning and lifecycle management of all identities and groups in complex, hybrid IT landscapes.

Powered by my-IAM – the underlying technology platform that enables seamless integration of any IT systems and cloud services.

Flexible IAM solution for Identity Governance & Administration

Audit-proof recertification independent of your system landscape

 
Whether cloud-native, hybrid or on-premises – access rights and group memberships can be recertified across systems from a single web interface:

N

HR integration

Personio, SAP SuccessFactors, SD Worx / Loga3

N

Identity Providers & Directories

Microsoft Entra ID, Active Directory, Keycloak

N

Specialized & industry software

Integration of databases, cloud SaaS and industry-specific software via API/CSV connectors with centralized logging.

No matter how individually your system landscape has grown, you get a single, consistent view of all identities, regardless of where the data originally comes from.

Your benefits

Icon: Plain language instead of blanket approval

Plain language instead of blanket approval

Icon: Less effort through automation

Less effort through automation

Icon: Risk-based review intervals

Risk-based review intervals

Icon: No more missed deadlines

No more missed deadlines

Icon: Audit-Nachweise auf Knopfdruck

Audit evidence at the push of a button

Icon: Made in Germany

Made in Germany

Frequently Asked Questions

Frequently asked questions about recertification, regular access reviews, transparent approval processes and secure control of access rights with the FirstWare IDM-Portal.

What is recertification (attestation) in the IAM context?

Recertification is the regular, active confirmation by a responsible person (for example a Group Owner or manager) that an employee still needs a specific permission. It prevents the gradual accumulation of access rights that are no longer required.

Does advanced IAM automation make recertification unnecessary?

No, but it drastically reduces the effort. Groups whose membership is controlled purely based on attributes (for example location = Munich) do not have to be reviewed manually. For sensitive special rights and manually assigned permissions, recertification remains essential and is explicitly required by auditors, for example for NIS2 and ISO 27001.

Why do recertifications in traditional systems so often fail in practice?

Because department managers are often confronted with unreadable database names and Active Directory codes. Overwhelmed by this, they often approve everything by default (“allow all”). The FirstWare IDM-Portal solves this problem by presenting access rights in understandable business language.

What happens if a responsible person ignores recertification?

The FirstWare IDM-Portal includes integrated deadline and escalation management. If the primary decision-maker does not respond in time, the review request is automatically escalated to the manager or IT security.

How does recertification differ from auditing & reporting?

Auditing & reporting chronologically documents what happened in the past, such as who changed what and when. Recertification is the forward-looking control step that checks whether the current status quo of access rights is still appropriate.

Let’s Talk

Make recertification stress-free at last

 

Let us show you in a short live demo how your key users can complete recertifications in just a few minutes and without frustration.

Call us at 0 8196 - 998 4330 or use our contact form.