By NHI Mgmt Group Editorial TeamBased on Veza: “The State of Identity & Access Report 2026” (December 11, 2025)

TL;DR: 38% dormant accounts, 8% orphaned identities, and 17:1 non-human-to-human identity ratios are expanding attack surface and obscuring real entitlement risk across modern enterprises, according to Veza’s 2026 State of Identity & Access Report. The lesson is that identity debt, not just access volume, is now the governance problem security teams must measure and reduce.


At a glance

What this is: Veza’s report describes how dormant accounts, orphaned identities, and NHI sprawl are compounding identity debt and obscuring real access risk.

Why it matters: It matters because IAM, IGA, PAM, and NHI teams need the same view of entitlement sprawl to reduce attack surface, not just count identities.

By the numbers:

  • 38% of dormant accounts and 8% of orphaned identities are creating a massive attack surface.
  • Non-human identities outnumber human identities by a factor of 17:1.

Context

Identity debt is the accumulation of stale accounts, orphaned identities, and excessive permissions that no longer match current business need. In this report, that debt is framed as an enterprise security problem because it broadens the attack surface while making it harder to see which identities can actually be abused.

The report ties that problem to both human IAM and NHI governance. As machine identities and AI agents proliferate, traditional entitlement review and access visibility models struggle to keep pace, which leaves security teams with more identities than governance processes can reliably classify or recertify.


Key questions

Q: How should teams reduce identity implementation debt in complex environments?

A: Start by identifying where lifecycle logic has been pushed into scripts, custom workflows, and external automations. Then move the highest-change decisions back into governed platform configuration so authorised admins can review and update them without developer dependency. The goal is not less logic, but more visible logic that can survive business change.

Q: Why do non-human identities make privileged access governance harder?

A: NHIs scale faster than human accounts and are often created for automation, integrations, and AI agents, which makes them easy to forget and hard to review. If they sit outside the main governance model, they can keep broad privileges long after the original use case changed. That creates hidden access risk.

Q: What breaks when access reviews ignore the data behind an entitlement?

A: What breaks is prioritisation. Teams end up treating low-impact and high-impact accounts the same, so the most dangerous access paths can sit behind routine certification cycles while less relevant entitlements consume attention. That creates a false sense of coverage and weakens least-privilege enforcement where it matters most.

Q: How should organisations measure whether identity governance is actually working?

A: Organisations should measure whether governance reduces incident cost, manual workload, and time to detect or contain risky access. If the only visible improvement is fewer tools, the programme may not be effective. Strong governance shows up in faster policy enforcement, clearer ownership, and fewer unreviewed access paths.


Technical breakdown

Why dormant identities become high-value entry points

Dormant accounts matter because they often retain valid authentication paths, stale entitlements, and inconsistent ownership even when they are no longer actively used. In practice, that means an attacker does not need a new account to gain leverage, only one that was forgotten but still trusted by downstream systems. The risk is not the account itself, but the persistence of privilege after business relevance has ended. When identity sprawl grows faster than lifecycle governance, dormant access becomes part of the attack surface rather than an administrative nuisance.

Practical implication: treat dormancy as an access-risk signal and not just a cleanup task.

How NHI sprawl changes entitlement governance

Non-human identities behave differently from human users because they are created, delegated, and consumed at machine speed. That shifts the governance problem from authentication alone to ownership, purpose, and entitlement scope across workloads, APIs, tokens, and service accounts. A 17:1 NHI-to-human ratio means most identity risk can sit outside traditional joiner-mover-leaver workflows and human recertification cadences. If those identities are not inventoried and scoped explicitly, the organisation will see growth in access volume without corresponding governance coverage.

Practical implication: extend inventory, ownership, and review processes to every NHI class, not just employee accounts.

Why entitlement noise hides the real risk

Billions of permissions create noise when access reviews are built around static lists instead of actual use, business context, and privilege concentration. The technical issue is not merely too many permissions, but too little signal about which ones are meaningful, inherited, or unused. In a noisy entitlement estate, teams can spend time certifying the obvious while missing the small set of permissions that create real blast radius. That is why identity debt becomes a measurement problem as much as a control problem.

Practical implication: prioritise privilege concentration, usage evidence, and ownership quality over raw entitlement counts.


Threat narrative

Attacker objective: The attacker aims to convert forgotten identity trust into privileged access that is hard to detect and easy to exploit at scale.

  1. Entry often begins with dormant or orphaned identities that still possess valid access and are less likely to be monitored.
  2. Escalation follows when excessive permissions or reused credentials let an attacker move from low-friction access to privileged resources.
  3. Impact comes from using that accumulated identity debt to widen blast radius, conceal abuse inside entitlement noise, or support ransomware activity.
  • McHire default password flaw 2025: A forgotten test admin account with the password 123456 and an API flaw exposed McDonald's McHire applicant records to researchers.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Identity debt is now a control failure, not an inventory issue. The report shows that dormant accounts, orphaned identities, and unused permissions are not abstract hygiene concerns. They create residual trust that adversaries can abuse long after business ownership has faded. The practitioner conclusion is simple: if identity governance cannot explain why access still exists, it has already lost control of the estate.

17:1 NHI sprawl changes the centre of gravity for identity governance. Once non-human identities outnumber human identities by that margin, human-centric recertification models stop representing the real attack surface. This is where OWASP-NHI thinking becomes operationally useful: the question is no longer whether identities exist, but whether machine identities have clear ownership, lifecycle, and scope. Practitioners need governance that is native to workload and service-account behaviour.

Identity debt: The article points to a governance premise that breaks when access volume grows faster than review capacity. Least privilege is designed for an environment where access can be understood, reviewed, and retired in a manageable lifecycle. That assumption fails when billions of permissions accumulate across humans and NHIs, because the review process no longer produces a reliable picture of effective privilege. The implication is that entitlement visibility must be treated as a prerequisite for governance, not as a reporting output.

Entitlement noise is becoming a measurement risk for security leadership. If the organisation can only count identities but cannot distinguish meaningful privilege from excess, it will misread both exposure and progress. That undermines access review programmes, PAM scoping, and NHI oversight at the same time. The practical conclusion is that identity security teams should re-centre on effective access, not raw identity counts.

The report validates a broader shift toward unified identity governance across human and non-human estates. Security leaders can no longer manage IAM, IGA, PAM, and NHI as separate operating models with separate visibility assumptions. The field is moving toward one lifecycle and privilege model with different actor types, because the attack surface now crosses them all. Practitioners should expect governance, not point tooling, to become the differentiator.

From our research library:

What this signals

Identity debt is becoming a programme-level risk signal. Security teams should expect stale access, orphaned identity ownership, and entitlement inflation to show up first as governance drift before they appear as incidents. The practical response is to make lifecycle ownership visible across human and non-human estates, then force every identity into a current business context.

Non-human identity sprawl changes what good looks like. A control set built only around employee access will miss the majority of machine-driven privilege in modern environments. The next operating model is one where service accounts, tokens, and workload identities are reviewed as first-class identities, not as exceptions that sit outside IAM.

Entitlement noise can hide the real exposure profile. When teams cannot separate useful access from stale privilege, they lose the ability to prioritise remediation. That is why identity governance increasingly depends on evidence of use, ownership, and blast radius rather than entitlement volume alone.


For practitioners

  • Inventory dormant and orphaned identities continuously Track accounts that are inactive, unowned, or detached from current business roles, then flag them for lifecycle review before they become latent access paths.
  • Extend governance to all non-human identities Map service accounts, API keys, tokens, certificates, and AI agents into the same ownership and review model used for human access, with explicit business purpose and expiry.
  • Reduce entitlement noise with privilege-based prioritisation Rank permissions by usage, inheritance, and blast radius so review teams focus on the small set of access rights that materially change exposure.
  • Reconcile identity ownership before recertification Require a named owner and a current business reason for every identity and entitlement before it enters the access review cycle.

Key takeaways

  • Dormant accounts and orphaned identities create residual access that attackers can use long after business ownership has lapsed.
  • The 17:1 imbalance between non-human and human identities shows that machine identity governance is now central to enterprise risk.
  • Security teams should focus on ownership, lifecycle, and effective privilege if they want identity governance to reduce real exposure.

Key terms

  • Identity Debt: Identity debt is the accumulation of unowned, over-permissioned, or poorly governed non-human identities that security teams cannot cleanly inventory or retire. It usually grows when experimentation outruns access governance, leaving service accounts and tokens active long after their original purpose has passed.
  • Orphaned Identity: An orphaned identity is a service account, token, or other machine credential that no longer has a clear owner, purpose, or retirement path. These identities create compliance and security risk because they are easy to forget, difficult to review, and often remain active long after they should have been removed.
  • Non-Human Identity (NHI): A digital identity assigned to a non-human entity such as a software application, service account, API key, bot, machine, or AI agent that enables it to authenticate and interact with systems without direct human involvement. NHIs now outnumber human identities in most enterprises by 25 to 50 times.
  • Entitlement Sprawl: The gradual accumulation of too many discrete permissions, often with overlapping access and unclear ownership. It makes access review noisy and offboarding fragile. Grouping entitlements into profiles is one way to reduce that sprawl, provided the groups are designed around real work patterns.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 25, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org