Scheduled campaigns
Run reviews on a cadence rather than as a fire drill before an audit, with progress visible while they are open.
Scheduled review campaigns, including orphan-account and full-identity reviews, decided in the console.
Access reviews fail when they are run on exported spreadsheets: the data is stale before it is circulated, the decisions are recorded in email, and nothing is enforced at the end. Certification campaigns run on live entitlement data, reviewers decide in the console, and the revocations they choose are carried out rather than noted.
The mechanics behind the capability — what the platform does, and where it does it.
Run reviews on a cadence rather than as a fire drill before an audit, with progress visible while they are open.
Target the accounts with no valid owner specifically, since those are the ones least likely to be caught by a manager review.
Review everything a person holds in one pass, which gives the reviewer the context to judge whether the combination is reasonable.
A revoke decision results in the entitlement actually being removed, rather than a note that someone must action later.
Who feels the difference once Access Certification is in place, and how.
Audit
The campaign record is the evidence, so preparing for an audit stops being a separate project.
Line managers
Seeing real entitlements in context produces better decisions than approving rows in a spreadsheet.
Security
Regular review is the mechanism that reverses privilege creep once it has happened.
Identity teams
Because decisions are enforced as they are made, nothing waits on a manual clean-up pass.
It works because the other capabilities share the same identity fabric. The quickest way to judge that is to watch it run against your own use cases.