Hello Isha,
For MIS, the Application Identity / Machine Identity is mainly the governance container. In a Machine Accounts certification campaign, the reviewer is really reviewing the access tied to that application identity, mainly the entitlements coming from the correlated machine accounts.
So in the review screen, you select the Machine Identity/Application Identity and review the Entitlements tab. It is not a separate “machine identity object certification” in the same way we think of a normal identity certification.
For reviewer routing, the important part is the reviewer option selected when the campaign is created. For machine account campaigns, Account Owner is usually the right reviewer. If the machine account owner is not mapped, ISC falls back to the Source Owner. So I would make sure the Machine Account Owner mapping is populated correctly if you want the actual application/service owner to review the access.
The Application Identity Primary Owner and Additional Owners are more for ownership, accountability, and succession of the application identity. Additional owners help if the primary owner becomes inactive. I would not assume the Application Identity Primary Owner automatically becomes the certification reviewer unless your campaign/reviewer configuration is set up to route it that way.
For the user entitlements on the application identity, those are entitlements that grant human users access to that application identity. I would keep that separate from the entitlements assigned to the correlated machine accounts, which are the main access items reviewed in the machine account certification flow.
On self-certification, I would not call it self-certification just because the reviewer is the machine account owner. That is normally the expected ownership review model. Self-certification in ISC is more about a human identity reviewing their own access. If your audit requirement needs independent review, then route the campaign to Source Owner, Individual reviewer, or a Governance Group instead of the account owner.
So the clean setup I would suggest is:
Map Machine Account Owner properly → correlate machine accounts to the correct Application Identity → run Machine Accounts certification → use Account Owner for ownership review, or Source Owner/Governance Group where independent review is needed.