TL;DR: A healthcare provider with more than 100,000 non-human identities, 50,000 certificates, 10,000 service accounts, and 133 unused service principals found in Azure showed how quickly hybrid environments outgrow manual NHI governance, according to Oasis Security. The lesson is that visibility, ownership, and rotation are now baseline identity controls, not optional clean-up work.
At a glance
What this is: This is a healthcare case study showing how a hybrid environment with more than 100,000 NHIs exposed gaps in visibility, ownership, rotation, and decommissioning.
Why it matters: It matters because IAM teams cannot govern machine identity estates with human-scale processes once service accounts, certificates, and secrets outgrow manual oversight.
Context
A healthcare organisation can have strong human IAM controls and still lose sight of the machine identities that actually hold operational privilege. In this case, the identity problem was not authentication for people, but governance across a hybrid estate of certificates, service accounts, API keys, and service principals spread across cloud and on-premises systems.
The provider had 8,500 human identities, a security team of 18, and an IT operations team of around 50, but the non-human footprint had already grown beyond what manual tracking could handle. That made ownership, rotation, and decommissioning the real control gaps, not the lack of another dashboard.
Key questions
Q: What breaks when manual governance is used for large NHI estates?
A: Manual governance breaks when the identity inventory is too large and fragmented for people to track consistently. Ownership becomes unclear, rotation slows down, dormant identities remain active, and the team loses confidence that it can tell which credentials are still in use. The result is not just inefficiency but a widening attack surface.
Q: Why do unowned service accounts create more security risk?
A: Unowned service accounts create more risk because no one is responsible for reviewing their permissions, rotating their credentials, or removing them when they are no longer needed. That makes privilege creep more likely and makes it harder for analysts to respond quickly when unusual activity appears.
Q: How do security teams know if NHI visibility is actually working?
A: Visibility is working only when discovery leads to ownership, review, and action. If teams can list machine identities but cannot say who owns them, when they were last reviewed, or whether their permissions are still justified, visibility is not governance. A usable programme turns inventory into an enforceable control surface.
Q: Should organisations prioritise NHI rotation or decommissioning first?
A: Prioritise decommissioning first when identities are clearly dormant or no longer needed, because removing unnecessary access reduces exposure immediately. Prioritise rotation first when the identity is still active but the secret is old, privileged, or poorly controlled. The right order depends on whether the bigger issue is unnecessary existence or unsafe persistence.
Technical breakdown
Why hybrid NHI estates break manual visibility
Hybrid identity estates fragment across cloud subscriptions, vaults, on-prem systems, and application-specific access paths. When service accounts, certificates, and API keys are managed in separate places, no single team can reliably answer basic governance questions such as who owns the identity, where it is used, or whether it still needs access. That breaks the operational assumption that administrators can keep a complete inventory through periodic review. In practice, stale objects and orphaned privileges accumulate faster than human remediation cycles can remove them.
Practical implication: build one authoritative NHI inventory before trying to tune rotation or decommissioning rules.
Why rotation and ownership are linked controls
Credential rotation is not just a hygiene task. It depends on knowing which identity is active, which system depends on it, and who can approve a change without breaking service. If ownership is unclear, rotation becomes either too slow or too risky, and both outcomes increase exposure. In this case, privileged secrets sat unrotated for months because manual processes could not safely absorb the volume of change across the estate. That is a governance problem as much as a technical one.
Practical implication: assign accountable owners before automating secret rotation so the workflow has a decision point.
How time-based decommissioning reduces standing NHI exposure
Automatic decommissioning uses usage thresholds to disable inactive identities instead of leaving them alive indefinitely. For NHIs, that matters because service accounts and service principals often persist long after the workload that created them has changed, and their entitlements remain available unless someone explicitly removes them. The control works best when tied to usage telemetry, entitlement scope, and alerting so deactivation becomes an observable governance event rather than a hidden breakage. That shifts NHI control from cleanup to lifecycle enforcement.
Practical implication: enforce inactivity thresholds and ticketed alerts for dormant privileged NHIs.
NHI Mgmt Group analysis
Manual governance breaks once the NHI estate becomes larger than the team operating it. A security team of 18 and an operations team of around 50 cannot reliably govern more than 100,000 NHIs with spreadsheets, periodic checks, and ad hoc remediation. The issue is not effort but scale mismatch. The practitioner conclusion is that NHI governance must become inventory-driven and lifecycle-aware before risk analysis can be trusted.
Identity ownership is the control boundary, not a reporting convenience. The article shows that on-prem ownership gaps were a core blocker because unclear accountability made every downstream action slower and less reliable. When no one owns the identity, no one can approve rotation, assess necessity, or retire it safely. The practitioner conclusion is that ownership is a prerequisite for enforceable machine identity governance.
Credential rotation is only effective when visibility and accountability already exist. Rotating a secret that no one can map to a workload or business owner creates operational uncertainty, not control. The article’s 46 privileged secrets that had not been rotated in months show how easily rotation becomes aspirational without an inventory and decision path. The practitioner conclusion is that rotation should be treated as a governed workflow, not a standalone task.
Time-based decommissioning is a practical answer to identity drift in hybrid estates. NHIs rarely disappear cleanly on their own, especially where cloud and on-prem access paths coexist. A usage threshold, automated disablement, and ticketed follow-up turn dormant identities into managed lifecycle events. The practitioner conclusion is that decommissioning rules should be tied to observed use, not assumptions about what still matters.
Ephemeral credential trust debt: the environment keeps trusting machine identities that have outlived the context in which they were created. That debt accumulates when certificates, service accounts, and service principals remain active after workloads change. The practitioner conclusion is that lifecycle controls must be designed to detect when trust has expired, not just when credentials expire.
From our research library:
- Only 5.7% of organisations have full visibility into their service accounts, according to the Ultimate Guide to NHIs.
- NHIs outnumber human identities by 25x to 50x in modern enterprises, according to the Ultimate Guide to NHIs.
- Read next: Ultimate Guide to NHIs — Key Challenges and Risks
What this signals
Ephemeral credential trust debt: hybrid environments accumulate machine identities faster than ownership and rotation workflows can keep up, so the real control failure is lifecycle drift, not just missing inventory. Teams should treat dormant service principals, stale accounts, and unrotated secrets as evidence that governance is lagging the estate.
When service accounts span cloud and on-premises systems, the meaningful question becomes whether decommissioning is observable. If a dormant identity can survive without a ticket, an alert, or an accountable owner, then the governance model is not enforcing lifecycle closure.
For practitioners
- Build a single NHI inventory Map certificates, service accounts, service principals, and API keys into one governed inventory so ownership and status are visible across cloud and on-premises systems.
- Tie every NHI to an accountable owner Require named ownership for each machine identity before it can be rotated, approved, or decommissioned, especially where on-prem and hybrid dependencies exist.
- Automate rotation for privileged secrets Move privileged secrets onto a repeatable rotation workflow with approval paths, dependency checks, and exception handling for workloads that cannot tolerate blind changes.
- Disable dormant identities on a usage threshold Use activity telemetry to disable inactive service accounts and service principals after a defined threshold, then create a ticket and alert for review.
- Prioritise remediation by exposure and privilege Sort stale accounts, unrotated secrets, and unused identities by privilege level and business criticality so the riskiest issues are handled first.
Key takeaways
- The case shows that large machine identity estates quickly outgrow manual governance when visibility is fragmented across cloud and on-premises systems.
- Scale evidence matters: the environment included more than 100,000 NHIs, 50,000 certificates, 10,000 service accounts, 133 unused service principals, and 46 privileged secrets not rotated in months.
- The control lesson is to unify inventory, ownership, rotation, and decommissioning so dormant privilege cannot linger unnoticed.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | Dormant service principals and unused identities show offboarding failure in a hybrid estate. |
| NHI-05 — Overprivileged NHI | Privileged secrets and service accounts remained active beyond their needed scope. | |
| NHI-07 — Long-Lived Secrets | The article explicitly cites unrotated privileged secrets persisting for months. | |
| Recommendation — Track inactive machine identities to NHI-01 and disable them when their business owner cannot be confirmed. Reduce standing access by mapping privileged machine identities to NHI-05 and trimming unnecessary entitlements. Apply NHI-07 to shorten secret lifetimes and enforce rotation for privileged machine credentials. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Secret rotation for machine identities maps directly to authenticator lifecycle control. |
| Recommendation — Use IA-5 to govern rotation, replacement, and retirement of service account credentials. | ||
| CIS Controls v8 | CIS-5 — Account Management | The core issue is lifecycle control over machine accounts and service principals. |
| Recommendation — Use CIS-5 to inventory, review, and disable unused machine accounts on a recurring basis. | ||
Key terms
- Non-Human Identity (NHI): A digital identity assigned to a non-human entity such as a software application, service account, API key, bot, machine, or AI agent that enables it to authenticate and interact with systems without direct human involvement. NHIs now outnumber human identities in most enterprises by 25 to 50 times.
- Service Principal: An application identity object in Microsoft Entra ID and Microsoft 365 that represents a specific app inside a tenant. It holds permissions, ownership, and configuration data that define what the application can do. In NHI governance, it is a high-value identity that should be reviewed like any other privileged account.
- Credential Rotation: The practice of regularly replacing secrets and credentials with new values to limit the window of exposure if a credential is compromised. Automated rotation, enforced by policy, is the security-optimal approach.
- Identity Lifecycle Governance: Identity lifecycle governance is the set of processes that create, change, review, rotate, and revoke access across human and non-human identities. It matters because access risk usually increases when lifecycle events are slow, incomplete, or disconnected from the systems that rely on them.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 6, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org