TL;DR: 38% dormant accounts, 8% orphaned identities, and 17:1 non-human-to-human identity ratios are expanding attack surface and obscuring real entitlement risk across modern enterprises, according to Veza’s 2026 State of Identity & Access Report. The lesson is that identity debt, not just access volume, is now the governance problem security teams must measure and reduce.
At a glance
What this is: This is a 2026 identity risk report showing that dormant accounts, orphaned identities, and NHI sprawl are materially expanding enterprise attack surface.
Why it matters: It matters because IAM, IGA, PAM, and NHI programmes now have to govern far more identities and entitlements than legacy review processes can reliably interpret.
By the numbers:
- 38% of dormant accounts and 8% of orphaned identities create a massive attack surface ripe for exploitation.
- Non-human identities outnumber human identities by a factor of 17:1 in modern enterprises.
👉 Read Veza's 2026 State of Identity & Access Report
Context
Identity debt is the growing gap between what an organisation believes it governs and the identities, entitlements, and credentials that actually remain active in the environment. In 2026 that gap is being widened by dormant accounts, orphaned identities, and the rapid growth of non-human identities and AI agents.
For identity teams, the issue is not just volume. Traditional access review, entitlement cataloguing, and privileged access controls were built for slower, more bounded identity populations, while today’s environments accumulate machine identities and permissions faster than teams can attest or retire them.
Veza’s report is best read as a measurement of where identity programmes are losing control. The starting position is increasingly typical for large enterprises, not an edge case, which is why identity security planning now has to account for both human and non-human populations together.
Key questions
Q: How should security teams reduce risk from dormant and orphaned identities?
A: Start by identifying identities with no active owner, no recent use, or no business dependency, then revoke access in order of privilege and exposure. The goal is to remove accounts that can still authenticate but no longer serve a legitimate function. Lifecycle offboarding is the control that prevents these identities from becoming persistent attack paths.
Q: Why do non-human identities complicate IAM governance?
A: Non-human identities complicate IAM governance because they do not behave like people. They authenticate without interactive sessions, persist across deployments, and can be shared or embedded in code. That means the controls that work for users, such as MFA and periodic review cadences, often miss the real NHI risk, which is secret exposure and privilege drift.
Q: What do security teams get wrong about platform permissions?
A: They often assume a well-organised interface means a well-governed access model. In practice, neat categories do not prevent over-privilege if API access, user access, and administrative functions are bundled together. The right test is whether each role maps to a narrow operational duty and a clear approval path.
Q: How should organisations measure whether identity governance is actually working?
A: Organisations should measure whether governance reduces incident cost, manual workload, and time to detect or contain risky access. If the only visible improvement is fewer tools, the programme may not be effective. Strong governance shows up in faster policy enforcement, clearer ownership, and fewer unreviewed access paths.
Technical breakdown
Dormant accounts and orphaned identities create persistent access paths
Dormant accounts are identities that still exist but are no longer actively used, while orphaned identities are accounts with no clear owner or business relationship. Both are dangerous because they often preserve valid credentials, entitlements, or trust relationships long after operational need has ended. In IAM terms, these accounts bypass the normal lifecycle assumptions that recertification and offboarding are supposed to enforce. Once they accumulate, they become low-noise footholds for attackers and high-friction cleanup work for defenders.
Practical implication: teams need lifecycle controls that identify identities with no current business owner or use case and remove their access before they become durable entry points.
Why a 17:1 NHI ratio changes governance economics
When non-human identities outnumber human identities by 17:1, the operating model for identity governance changes materially. Each service account, token, workload identity, or AI agent adds access paths, secrets, and entitlement relationships that must be tracked, rotated, and reviewed. The challenge is not simply scale, but asymmetry: NHIs are often created by applications, infrastructure teams, and automation pipelines faster than central IAM teams can inventory them. That is why traditional human-centric governance tools miss the largest part of the attack surface.
Practical implication: organisations should shift from periodic discovery to continuous NHI inventory and ownership mapping across every platform that creates credentials.
Ungoverned permissions sprawl hides real risk inside entitlement noise
Permissions sprawl occurs when identities accumulate far more access than they need, or when entitlements are granted broadly and never removed. At enterprise scale, the problem becomes entropy: billions of permissions make it hard to distinguish legitimate access from excessive or redundant access. This is where role design, entitlement normalization, and privileged access segmentation matter, because raw permission counts do not equal risk until they are tied back to actual usage and business context. Without that mapping, organisations cannot tell where meaningful exposure begins.
Practical implication: teams should prioritise entitlement clean-up by actual use and business-criticality rather than trying to review every permission equally.
Threat narrative
Attacker objective: The attacker objective is to turn unmanaged identity sprawl into durable access that can be used for theft, disruption, or ransomware operations.
- Entry begins with dormant or orphaned identities that still hold valid access and are often overlooked by routine governance processes.
- Escalation occurs when attackers combine weak credential protection with excessive entitlements or persistent non-human access to reach sensitive systems.
- Impact follows through account misuse, lateral movement, ransomware enablement, or unauthorised access that is difficult to attribute quickly.
Breaches seen in the wild
- McDonald's McHire AI Chatbot Default Credentials — Default credentials in McDonald's McHire AI recruitment chatbot expose 64 million job application records.
- Moltbook AI agent keys breach — Moltbook breach exposed 1.5M AI agent keys.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Identity debt is now a governance failure, not a housekeeping issue. The report shows that dormant accounts, orphaned identities, and permission sprawl are accumulating faster than organisations can certify or remove them. That means identity programmes are no longer failing only at the margins. They are losing track of the live access estate itself, which makes identity debt a board-level control problem rather than an operational clean-up task.
The 17:1 non-human-to-human ratio is the clearest proof that IAM has become a machine-scale discipline. Human-centric review cadences do not break because they are badly run; they break because they were never designed for a world where NHIs dominate the estate. That shift validates NHI governance as a separate control domain, with its own inventory, lifecycle, and entitlement rules. Practitioners should treat NHI sprawl as the primary scaling constraint in identity security.
Ungoverned permissions sprawl creates an identity blast radius that static reviews cannot see. Billions of permissions only become manageable when teams can distinguish use, ownership, and privilege context. The challenge is not the total count alone but the inability to separate business-required access from accumulated excess. Security teams should treat entitlement noise as a signal that their identity model no longer reflects operational reality.
Identity governance now has to span humans, NHIs, and AI-enabled access paths in one control plane. The article’s significance is not limited to one identity class. As automation increases, the same lifecycle assumptions that fail for orphaned human accounts also fail for service accounts and AI-driven access paths. The implication is that teams need a unified governance model, but one that still preserves actor-specific controls rather than forcing all identities into the same review pattern.
From our research:
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface, according to Ultimate Guide to NHIs.
- From our research: Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
- From our research: Use the 52 NHI Breaches Analysis to see how excessive privileges and weak lifecycle control translate into real compromise patterns.
What this signals
Identity debt will increasingly define whether IAM programmes can be trusted at all. The practical challenge is no longer just cleaning up old accounts. It is proving that ownership, revocation, and entitlement decisions still match the operating environment, especially as non-human identities multiply faster than review cycles can absorb. The Ultimate Guide to NHIs remains the clearest baseline for that work.
NHI governance needs to shift from periodic assurance to continuous control. When machine identities dominate the estate, static certification produces a false sense of coverage. Security teams should watch for gaps between account creation and ownership assignment, then use that gap as the earliest signal of governance decay. The 52 NHI Breaches Analysis shows how quickly those gaps become exploitable.
Identity blast radius is now the more useful metric than raw identity count. A smaller environment with high privilege concentration can be riskier than a larger one with disciplined entitlements. The next step for practitioners is to align PAM, IGA, and NHI governance so access is judged by exposure, not inventory size.
For practitioners
- Map and retire dormant identities Identify accounts with no recent business use, no current owner, or no active workflow dependency, then remove access in priority order based on privilege and network reach.
- Build a continuous NHI inventory Track every service account, token, certificate, workload identity, and AI-related credential across cloud, code, and infrastructure pipelines, with clear ownership and expiry data.
- Reduce entitlement noise before the next recertification cycle Normalize permissions into business-relevant roles and remove redundant grants so access reviews evaluate meaningful risk instead of raw permission volume.
- Separate human and non-human governance workflows Use different lifecycle checks for people, service accounts, and AI-enabled identities so review cadence, ownership, and revocation steps match the actor type.
Key takeaways
- Dormant, orphaned, and over-entitled identities are no longer a background issue. They are the attack surface.
- The 17:1 NHI-to-human ratio shows why human-centric governance alone cannot describe modern identity risk.
- Teams need continuous inventory, ownership, and entitlement reduction if they want identity programmes to stay credible in 2026.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | The report centres on unmanaged NHI growth and excessive privilege. |
| NIST CSF 2.0 | PR.AC-4 | Access permissions management is directly challenged by dormant and over-entitled identities. |
| NIST SP 800-53 Rev 5 | IA-5 | Authenticator management matters where dormant accounts and stale credentials persist. |
| NIST Zero Trust (SP 800-207) | 3.4 | Zero trust depends on continuous verification of identities and access relationships. |
Treat every identity as continuously evaluated, not permanently trusted after initial authentication.
Key terms
- Identity Debt: Identity debt is the accumulation of unowned, over-permissioned, or poorly governed non-human identities that security teams cannot cleanly inventory or retire. It usually grows when experimentation outruns access governance, leaving service accounts and tokens active long after their original purpose has passed.
- Dormant account: A dormant account is an identity that has not been used within a defined period but still retains active access. The risk is not only wasted licensing. Dormant access often becomes stale standing privilege, which makes offboarding, certification, and incident response harder to execute cleanly.
- Orphaned Identity: An orphaned identity is a service account, token, or other machine credential that no longer has a clear owner, purpose, or retirement path. These identities create compliance and security risk because they are easy to forget, difficult to review, and often remain active long after they should have been removed.
- Permission Sprawl: Permission sprawl is the accumulation of unnecessary or outdated access across identities over time. In cloud and NHI environments, it grows through automation, rapid deployment, and weak offboarding, leaving more standing privilege than the business actually needs.
What's in the full report
Veza's full report covers the operational detail this post intentionally leaves for the source:
- Role-by-role breakdowns of identity debt across human and non-human populations
- Source dataset context on entitlements, access patterns, and identity exposure trends
- Implementation details for measuring dormant accounts, orphaned identities, and permission sprawl
- Benchmarks that help teams compare their own identity posture against the report’s findings
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on August 25, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org