Join our Newsletter — 33% off our NHI Course

Why do dormant and shared accounts create such a high risk in enterprise environments?

Dormant and shared accounts widen the attack surface because they often remain usable after business need has passed, and they are easier for attackers to abuse without immediate detection. If an account has not been used for a long time, it should be disabled or removed. Unique passwords and regular review reduce the chance of unauthorized access through stale credentials.

Why dormant and shared accounts are so dangerous

Dormant and shared accounts are high-risk because they weaken both control and accountability. A dormant account may still authenticate long after the original business need has ended, while a shared account makes it hard to tell who actually used it, when, and for what purpose. Together, they create easy abuse paths for intruders and slow down detection and response.

The practical problem is not just that these accounts exist, but that they often sit outside the normal life cycle of join, move, leave, and review. When that life cycle breaks, access can outlive ownership, and stale credentials can remain valid even when nobody is actively watching them. That is why these accounts often become “quiet” entry points in otherwise well-managed environments.

In enterprise settings, the risk increases when the account can reach production systems, administrative consoles, remote access paths, or sensitive data. A credential that is rarely used is often reviewed less often, and a credential that is used by multiple people is harder to rotate without business disruption. The result is a control gap where exposure is real, but visibility is poor.

How attackers turn stale or shared access into compromise

Attackers like dormant accounts because they often blend into normal noise. A long-unused account may have old passwords, weak MFA coverage, or permissive access that no one has revalidated. If the credential is guessed, phished, leaked, or reused, the attacker can get in with little immediate friction.

Shared accounts create a different problem: they erase attribution. If several people use the same login, security teams lose the ability to distinguish legitimate activity from abuse. That makes alert triage harder, slows incident investigation, and gives an intruder a better chance to act under the cover of ordinary use.

This is why identity governance and access review matter so much. NHIMG’s IAM and IGA Basics explains the control logic behind review, entitlement management, and least privilege, which are the main defences against stale access paths. The same principle appears in NHI Lifecycle Management Guide, where provisioning, rotation, and offboarding are treated as lifecycle events rather than one-time setup tasks.

What good control looks like in practice

Good practice starts with inventory and ownership. If an account cannot be tied to a named owner and a current business purpose, it should be treated as suspect until proven otherwise. Dormant access should be disabled quickly, and shared access should be replaced with individual accounts wherever possible so that activity is attributable and reviewable.

For accounts that genuinely must remain service-facing or operational, the control objective is not “let it stay shared”, but “make it governed.” That means unique credentials where possible, tight scope, frequent review, and rotation rules that match the sensitivity of the access. NHIMG’s Service Account Security Guide is useful here because it treats shared and non-interactive access as a governance problem, not just a password problem.

What many organisations underestimate is how quickly these accounts accumulate in remote access and legacy environments. Dormant VPNs, old integration logins, and forgotten admin accounts can persist long after the original workflow changes. NHIMG’s Remote Access Identity Guide is a good reminder that unused entry points should be retired, not merely monitored.

Risk and Threat Considerations

Dormant and shared accounts create a persistent exposure because they reduce the chance that an attacker will face an active owner, a timely review, or a clear audit trail. Once compromised, they often provide access that looks legitimate enough to avoid immediate scrutiny, especially if the account is old, broadly trusted, or used for routine operational tasks.

Failure mechanism: The control failure is usually stale access combined with weak attribution, which lets credentials survive past their intended use and lets multiple users hide behind one identity.

Impact: That combination increases the chance of unauthorized access, complicates incident investigation, and can widen blast radius if the account reaches privileged systems or sensitive data.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 IA-4 — Identifier Management Dormant and shared accounts require lifecycle control over identifiers and their continued validity.
IA-5 — Authenticator Management The risk centers on stale credentials that remain usable after business need ends.
AC-2 — Account Management Dormant and shared accounts are an account governance problem requiring periodic review and removal.
Recommendation — Remove unused identifiers promptly and keep account ownership tied to current business need. Rotate, revoke, and protect authenticators so old credentials cannot remain effective. Review accounts regularly and disable or delete those no longer required.
CIS Controls v8 CIS-5 — Account Management Account inventory, disabled stale accounts, and shared-account reduction are central to the issue.
Recommendation — Inventory accounts, remove inactive ones, and eliminate shared logins where possible.
ISO/IEC 27001:2022 A.5.16 — Identity management The question is fundamentally about controlling identity lifecycle and ownership in enterprise access.
Recommendation — Ensure identities are uniquely managed, owned, and retired when no longer needed.

Practitioner Guidance

What to prioritise: Start with accounts that have not been used recently but still have privileged or production access. Those are the highest-value cleanup candidates because they combine low visibility with high potential impact.

What to verify: For every shared or dormant account, verify the named owner, current purpose, last use date, MFA coverage, and whether the account still needs direct human access. If you cannot verify ownership, treat the account as a remediation item rather than a convenience account.

Common mistake: Teams often delay action because the account “might be needed later”. That is usually how stale access survives. If the account is business-critical, document the exception and add stronger controls; if it is not, disable it.

Practitioner takeaway: The real risk is not just old access, it is old access that no one can confidently explain, attribute, or retire. The safest enterprise posture is to eliminate unused accounts, replace shared logins with individual accountability, and keep any unavoidable exceptions tightly governed.