By NHI Mgmt Group Editorial TeamDomain: Governance & RiskSource: Orchid SecurityPublished September 15, 2026

TL;DR: 48% of applications store credentials in cleartext, 44% use authentication paths that bypass the corporate IdP, and 37% fail to enforce access controls consistently, according to Orchid Security, underscoring how legacy and acquired apps keep identity risk hidden. The real issue is not discovery alone but proving which application-level identity flows still sit outside governed IAM boundaries.


At a glance

What this is: This is an application identity posture analysis showing that cleartext credentials, IdP bypasses, and weak access controls remain common across discovered applications.

Why it matters: It matters because IAM, IGA, PAM, and NHI programmes can only govern what they can see, and application-level identity flows often sit outside that visibility.

By the numbers:

👉 Read Orchid Security's analysis of application identity posture gaps and missing controls


Context

Application identity posture is the state of how applications authenticate, authorise, store credentials, and connect to corporate identity controls. In large estates, that posture is fragmented by age, ownership changes, acquisitions, and inconsistent development practices, which leaves identity risk embedded inside the applications themselves rather than only in central IAM tooling.

The first problem is visibility. Traditional audits often miss hidden identity mechanisms, alternate authentication paths, and weak credential storage because they depend on documentation or app-owner input. For identity teams, that means the control surface is broader than the directory, the IdP, or the PAM vault.

This is especially relevant for organisations trying to govern NHI and application access together. When an application stores credentials in cleartext or bypasses federated controls, the governance gap is not theoretical. It is a practical failure of identity inventory, policy enforcement, and lifecycle oversight.


Key questions

Q: What breaks when applications bypass the corporate Identity Provider?

A: When applications bypass the corporate Identity Provider, central IAM policies stop being the enforcement point. MFA, conditional access, session controls, and revocation can all be weakened or skipped, which leaves the organisation dependent on local application logic that is often inconsistent and harder to govern. The result is fragmented trust and a larger attack surface.

Q: Why do cleartext credentials in applications create such a high breach risk?

A: Cleartext credentials turn application storage into usable access material. If an attacker reaches source code, configuration files, or a mismanaged support system, they may gain immediate authentication capability without needing to break encryption or guess passwords. That shortens the attack path and makes credential discovery a direct path to unauthorised access.

Q: How do teams know if identity security controls are actually working?

A: Identity security controls are working when teams can show a current view of high-risk entitlements, detect privilege drift quickly, and remove access before exposure spreads. A useful sign is reduced time between entitlement change and policy review. Another is fewer unresolved conflicts between approved access and actual production permissions.

Q: Should organisations prioritise legacy protocol remediation before application consolidation?

A: Yes, when legacy protocols are still carrying active access. Consolidation can reduce sprawl, but it does not remove identity risk if outdated authentication paths remain in production. Remediating the protocols that block federation, lockout, and modern policy enforcement usually delivers the faster security gain.


Technical breakdown

Why application identity flows escape central IAM controls

Applications often carry their own embedded authentication logic, credential stores, and authorisation checks. That means identity can be implemented in code, configuration, or middleware rather than in the corporate IdP. When teams only govern the central directory, they miss alternate login paths, hard-coded secrets, and stale protocols that still grant access. The result is a split identity plane in which policy exists centrally but enforcement happens locally, often inconsistently. Practical implication: map application-level authentication and authorisation paths as first-class identity assets, not just application dependencies.

Practical implication: map application-level authentication and authorisation paths as first-class identity assets, not just application dependencies.

How cleartext credentials and bypass paths create hidden access risk

Cleartext credentials and weak hashing expand the blast radius because anyone who reaches the code, config, or storage location can recover usable access material. Bypass paths are equally dangerous because they create parallel trust routes outside conditional access, MFA, and central policy enforcement. In both cases, the issue is not simply weak security hygiene. It is that the identity control plane has drifted away from the actual enforcement point. Practical implication: inventory every app that stores or validates credentials outside governed identity services and prioritise those paths for remediation.

Practical implication: inventory every app that stores or validates credentials outside governed identity services and prioritise those paths for remediation.

What outdated authentication protocols reveal about control debt

Outdated or non-standard authentication protocols usually survive because teams fear breaking legacy applications or inherited acquisitions. But every exception accumulates control debt: weaker session assurance, inconsistent lockout behaviour, and reduced compatibility with modern federation and policy enforcement. That debt matters because identity teams cannot effectively govern access when the protocol itself constrains what controls can be applied. Practical implication: treat protocol modernisation as an identity risk reduction programme, not a purely technical upgrade project.

Practical implication: treat protocol modernisation as an identity risk reduction programme, not a purely technical upgrade project.


Threat narrative

Attacker objective: The attacker aims to convert weak application identity controls into durable access to sensitive data and internal systems.

  1. Entry occurs when attackers obtain stolen credentials or discover exposed authentication material in applications that store secrets in cleartext or rely on bypass routes.
  2. Escalation follows when those credentials work against support portals, Jira, or other internal systems that lack strong federation, lockout, or MFA enforcement.
  3. Impact is achieved through unauthorised access to sensitive records or internal documents, which can then be exfiltrated or abused across the environment.
  • OneLogin API Key Vulnerability — Critical API key vulnerability in OneLogin exposes OIDC secrets and identity provider credentials.
  • Microsoft Entra ID Flaw — Critical Microsoft Entra ID flaw allows attackers to hijack any company tenant via identity provider vulnerability.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Application identity posture is now a first-order governance issue, not a code-quality side topic. The article shows that identity controls can fail inside applications even when the central IAM stack looks intact. That means IAM, IGA, and PAM teams must treat embedded authentication, credential storage, and protocol choice as part of the identity estate, not as separate engineering concerns. The practitioner conclusion is simple: if the application is the enforcement point, it is inside the governance boundary.

Hidden auth paths create an identity shadow layer. When an application can authenticate outside the corporate IdP, the organisation has more than a technical exception. It has an unauthorised trust path that standard policy reporting will often miss. That shadow layer is where old protocols, local account stores, and inherited exceptions keep privilege alive after central controls have moved on. Practitioners should assume the audit trail is incomplete until application flows are explicitly mapped.

Cleartext storage is a control failure, but bypass authentication is a governance failure. The first exposes credentials. The second bypasses the assurance model altogether. Together they show why identity security cannot be reduced to directory hygiene, because application logic can reintroduce risk even after the IAM programme has standardised the front door. The practitioner conclusion is to measure governance at the application boundary, not only at the identity provider.

Acquired and long-lived applications are where identity debt concentrates. The article's examples are consistent with environments that have grown by acquisition, decentralised development, and uneven remediation. That is typical, not exceptional, and it explains why posture programmes need discovery that works without tribal knowledge. The implication is that organisations must expect identity inconsistency until they continuously inspect the application estate.

From our research:

What this signals

Application identity posture is becoming the practical edge of IAM governance. When applications retain local authentication logic, security teams inherit a distributed trust model that central reporting rarely captures. The operational signal is clear: identity programmes need continuous application discovery tied to control verification, not just directory and policy review.

Visibility gaps will keep surfacing until identity teams model applications as identity actors. That means tracking how each app authenticates, where secrets live, and which control exceptions remain active after deployment or acquisition. The most useful next step is to connect posture findings to remediation ownership so application teams cannot defer identity debt indefinitely.

With 5.7% of organisations having full visibility into their service accounts, according to the Ultimate Guide to NHIs, the broader lesson is that invisibility is the default state of non-human access unless programmes actively hunt for it.


For practitioners

  • Inventory application authentication paths Identify every application that authenticates users or services outside the corporate IdP, including local accounts, legacy protocols, and alternate login routes. Rank those flows by privilege level and data sensitivity so remediation starts where control bypass creates the biggest blast radius.
  • Eliminate cleartext credential storage Search code, configuration, and supporting services for stored credentials, then replace them with managed secrets or federated identity patterns. Give priority to applications that also expose administrative or support functions because those paths are attractive entry points.
  • Modernise protocol exceptions Track every outdated or non-standard authentication protocol as identity control debt, not a temporary compatibility choice. Require an explicit retirement plan for protocols that prevent modern federation, lockout, or conditional access enforcement.
  • Tie application onboarding to identity controls Make application onboarding contingent on documented authentication, authorisation, and secret-handling patterns so new systems do not inherit hidden identity shortcuts. Use continuous discovery to catch exceptions introduced after deployment or through acquisition.

Key takeaways

  • Application identity risk persists when authentication logic lives inside the app rather than in governed IAM services.
  • Cleartext credentials, IdP bypasses, and outdated protocols combine into a hidden access layer that standard audits often miss.
  • Identity teams should govern the application boundary directly, because visibility without enforcement leaves the real risk untouched.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5, CIS Controls v8 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-4 — Access Permissions and AuthorisationsThe article centres on application access paths that bypass governed identity controls.
Recommendation — Map application authentication paths to PR.AC-4 and remove unauthorised access routes.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementCleartext credentials and protocol weaknesses are authenticator management failures.
Recommendation — Apply IA-5 to eliminate stored credentials and retire weak authentication methods.
CIS Controls v8CIS-5 — Account ManagementThe article highlights unmanaged application accounts and alternate identity paths.
Recommendation — Use CIS Control 5 to inventory application accounts and revoke unnecessary access.
OWASP Non-Human Identity Top 10NHI-03 — Secrets and Credential ManagementCredential storage and exposure inside applications is a core NHI governance concern.
Recommendation — Use NHI-03 to locate embedded credentials and move them into governed secret handling.
NIST Zero Trust (SP 800-207)Access Control — Access ControlBypass authentication paths directly undermine zero trust enforcement at the app layer.
Recommendation — Apply zero trust access controls so applications cannot create parallel trust paths.

Key terms

  • Application Identity Posture: The state of how an application authenticates, authorises, and stores credentials within its own implementation and surrounding services. In practice, it shows whether identity control lives in governed platforms or is embedded in code, configuration, and local exceptions that security teams must continually discover and manage.
  • IdP Bypass: An authentication path that allows an application or user to gain access without going through the corporate Identity Provider. This weakens central policy enforcement because MFA, conditional access, and revocation can be skipped, leaving the organisation dependent on local application logic instead of governed identity controls.
  • Identity control debt: Identity control debt is the accumulated operational burden that appears when legacy identity systems make governance harder to execute than it should be. It shows up as manual exceptions, brittle integrations, slow reviews, and poor evidence quality that eventually affect audit readiness and resilience.
  • Embedded Credential: A credential embedded in software, firmware, or automation that can be reused outside its intended context. In practice, it becomes a silent trust bridge between systems. For agents and connected devices, the risk is not the secret alone but the reach it grants if runtime controls are weak.

What's in the full article

Orchid Security's full article covers the operational detail this post intentionally leaves for the source:

  • Per-application findings on where cleartext credentials, bypass routes, and non-standard protocols were discovered
  • The checklist used to identify missing identity controls across discovered applications
  • The broader workflow for continuous discovery, gap analysis, and remediation tracking
  • Examples of how acquired or legacy applications can be folded into an identity posture programme

👉 The full Orchid Security article covers application discovery detail, checklist coverage, and remediation context.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on September 16, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org