TL;DR: Identity sprawl across multi-cloud, SaaS, and hybrid estates is pushing IAM and IGA together, while overprivileged service accounts remain a major cloud risk and cloud governance increasingly depends on continuous visibility, lifecycle enforcement, and least-privilege drift control, according to Bravura Security.
At a glance
What this is: This article argues that IAM and IGA are converging because hybrid identity sprawl, machine identities, and cloud entitlement drift now demand unified governance.
Why it matters: It matters because IAM, IGA, and PAM teams need a shared model for human and non-human identities across cloud and SaaS environments before access drift turns into breach exposure.
By the numbers:
- Overprivileged service accounts triggered 46.4% of cloud security alerts in H2 2024.
- Overprivileged service accounts enabled 62.2% of lateral movement incidents.
Context
IAM and IGA are converging because hybrid identity sprawl now stretches across cloud, SaaS, and on-premises systems rather than stopping at the corporate perimeter. In that model, the governance problem is not simply who can log in, but who, or what, can keep access as environments change.
The article frames modern identity as a mixed estate of human users, service accounts, APIs, workloads, and connected devices. That matters for identity governance because lifecycle controls, access reviews, and least-privilege enforcement have to cover both people and non-human identities in the same operational model.
Key questions
Q: What breaks when identity governance is built only for human users?
A: Access review, joiner-mover-leaver processes, and periodic certification break down when the identity is a service account or autonomous agent. Those controls assume a visible human lifecycle and a stable review window. Machine identities and agents can outlive those assumptions, leaving access active after the programme believes it has been governed.
Q: Why do overprivileged service accounts create such persistent cloud risk?
A: Overprivileged service accounts create persistent risk because they combine standing access, weak ownership, and broad lateral movement potential. When those accounts are not tightly reviewed, an attacker or insider can move from a small foothold to broader cloud access. The issue is not only permission size, but how long that privilege remains valid.
Q: How should IAM teams measure whether IGA is actually working?
A: They should measure whether IGA reduces risky access conditions, not just whether reviews are completed on time. Strong signals include fewer toxic role combinations, shorter exception lifetimes, lower stale entitlement counts, and faster removal of access that is no longer justified by business need.
Q: Should organisations prioritise access review or lifecycle automation first?
A: Organisations should prioritise lifecycle automation first when review cycles cannot keep pace with change. Reviews can confirm policy, but automation removes stale access when the underlying event occurs. For high-volume NHIs, that is usually the only practical way to keep entitlements current enough to matter.
Technical breakdown
Why hybrid identity sprawl breaks perimeter-based IAM
Hybrid identity sprawl occurs when access is distributed across multiple cloud platforms, SaaS applications, and on-premises directories without a single governance view. In that environment, IAM stops being just authentication and entitlement assignment, because the real risk is fragmented visibility across AWS, Azure, Google Cloud, and third-party applications. ZTA makes that fragmentation more visible by assuming no implicit trust and requiring continuous validation. The technical issue is not that each platform lacks identity controls, but that the combined estate creates inconsistent enforcement, orphaned accounts, and policy drift between systems.
Practical implication: map where identities are created, granted, and removed across every major platform before adding more access controls.
How machine identities change IAM and IGA scope
Machine identities are non-human identities such as service accounts, APIs, workloads, and operational devices that authenticate and act without a person at the keyboard. They are governed differently from human users because ownership, endpoint permissions, environment context, and lifecycle state matter more than interactive sign-in behaviour. The article’s core point is that IGA cannot stay people-centric if service accounts and workloads can accumulate excess privilege faster than they are reviewed. Once machine identities are in scope, IAM and IGA must track who owns the identity, what it can reach, and whether its access still matches the workload it supports.
Practical implication: put machine identity inventory and ownership into the same governance process as human access certification.
Why access reviews fail when entitlement drift is continuous
Access reviews are control checks that confirm whether current permissions still match job function, business need, and risk appetite. In a hybrid environment, those reviews can fail if entitlements change faster than the review cadence or if automation does not revoke stale access when roles, projects, or vendors change. The article links IGA to lifecycle automation because provisioning and deprovisioning are only effective when revocation is reliable across SaaS and on-premises systems. Without that, orphaned accounts and excess entitlements survive long enough to become material attack paths.
Practical implication: treat revocation and access certification as one control loop, not two separate governance activities.
Threat narrative
Attacker objective: The objective is to turn fragmented identity governance into broad cloud and SaaS access that can be used for lateral movement and data compromise.
- Entry occurs through identity sprawl, where unmanaged SaaS apps, fragmented cloud entitlements, or exposed machine identities expand the accessible surface.
- Credential or privilege abuse follows when overprivileged service accounts or stale entitlements provide access beyond the original business need.
- Escalation and movement occur as attackers use excessive permissions to move laterally across cloud and hybrid resources.
- Impact is realised through broader compromise of cloud workloads, data stores, or linked SaaS environments that were never meant to share that level of trust.
Breaches seen in the wild
- Salesloft OAuth token breach: hackers stole OAuth tokens to access Salesforce data via Salesloft.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
IAM and IGA are no longer separable disciplines in hybrid estates: the article correctly shows that cloud, SaaS, and on-premises identity sprawl collapses the old boundary between access control and governance. IAM without IGA leaves entitlement drift unchecked, while IGA without IAM cannot enforce lifecycle outcomes at the access layer. The practical conclusion is that identity programmes now need one operating model for grant, review, and revocation across all identity types.
Overprivileged service accounts are a governance failure, not just a cloud misconfiguration: when non-human identities can accumulate standing access, the issue is lifecycle discipline, not only technical hardening. The Google Cloud figures cited in the article show why this matters: the same identity type is associated with both alerts and lateral movement. Practitioners should treat service-account privilege as a governed asset class rather than a background configuration detail.
Hybrid identity sprawl creates an identity blast radius that traditional IAM summaries hide: once access is distributed across AWS, Azure, Google Cloud, and SaaS, the real risk becomes how far one mis-scoped identity can move across connected systems. That is where IGA has to serve as the control plane for cross-domain entitlement visibility. The implication is that organisations need a single view of inherited trust, not separate reports from each platform.
Continuous verification changes what least privilege means in practice: ZTA turns least privilege from a provisioning rule into a runtime governance expectation. If access is granted dynamically but never fully reconciled against lifecycle changes, the policy exists only on paper. The practical implication is that identity teams must measure whether revocation and certification keep pace with the speed of cloud change.
Identity governance has become the bridge between human and machine access models: the article is strongest when it treats service accounts, APIs, and workloads as first-class identities alongside employees and contractors. That alignment is where many programmes still break, because they govern people well and machines loosely. The conclusion for practitioners is to unify identity lifecycle, access review, and audit evidence across every identity class.
From our research library:
- Over 70% of organisations lack automated access risk analysis, user access reviews and provisioning and deprovisioning, according to Pathlock's 2025 Digital Transformation and Access Risk Report.
- Read next: Access Reviews and Certification Guide
What this signals
Identity blast radius: hybrid estates turn small entitlement errors into cross-platform exposure because access, ownership, and revocation are no longer contained within one directory. The practical shift for IAM teams is to govern identity as a routed dependency chain, not as isolated platform admin.
Access reviews only work when the underlying lifecycle system is already trustworthy. If provisioning, mover events, and deprovisioning remain fragmented, certification becomes a retrospective audit exercise instead of a control that reduces standing risk.
For practitioners
- Unify human and machine identity inventories Build one authoritative inventory for employees, contractors, service accounts, APIs, workloads, and third-party identities so access can be reviewed in context rather than in separate silos.
- Review overprivileged service accounts first Prioritise the identities most likely to support lateral movement, especially long-lived service accounts with broad cloud permissions and weak ownership metadata.
- Tie lifecycle events to automatic revocation Make joiner, mover, and leaver changes trigger deprovisioning across SaaS, cloud, and on-premises resources so stale access does not survive the business reason for it.
- Use access reviews to validate automation Treat certification as a check on whether provisioning and revocation workflows are actually working, especially where automation spans multiple platforms and identity types.
Key takeaways
- Hybrid identity sprawl is pushing IAM and IGA into a shared governance role because cloud, SaaS, and on-premises access can no longer be managed as separate problems.
- Machine identities, especially overprivileged service accounts, are central to the risk profile because they can enable lateral movement and persist outside normal human review cycles.
- The practical response is tighter lifecycle automation, cross-domain inventory, and access certification that verifies whether revocation is actually keeping pace with change.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while CIS Controls v8, NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | The article centers on excessive permissions for service accounts and other non-human identities. |
| NHI-07 — Long-Lived Secrets | Hybrid identity risk persists when service-account credentials and access paths live longer than needed. | |
| Recommendation — Audit non-human identities for excess permissions and reduce standing access to the minimum required. Shorten the lifetime of NHI credentials and remove any secret that outlives its workload. | ||
| CIS Controls v8 | CIS-5 — Account Management | The article is fundamentally about controlling identities, entitlements, and revocation across hybrid systems. |
| Recommendation — Centralise account management and continuously remove stale or orphaned identities across environments. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article focuses on entitlement drift and access governance across cloud and SaaS platforms. |
| Recommendation — Apply entitlement governance to validate that permissions match current business need across all platforms. | ||
| NIST Zero Trust (SP 800-207) | Continuous Verification — Continuous Verification | Zero Trust is a central lens in the article's discussion of dynamic access and least privilege. |
| Recommendation — Use continuous verification to recheck access decisions as context and risk change. | ||
Key terms
- Hybrid Identity Sprawl: Hybrid identity sprawl is the spread of identities, entitlements, and account types across cloud, SaaS, and on-premises systems without unified governance. It creates fragmented visibility, inconsistent revocation, and more places for access drift to hide.
- Service Account: A special-purpose account used by applications, automated tools, or services rather than a human user to interact with systems, APIs, and infrastructure. Service accounts are a primary category of NHI and one of the most frequently exploited attack vectors.
- Access Certification: Access certification is the periodic review of whether an identity still needs its current entitlements. For NHIs, certification is only reliable when reviewers know the identity's owner, purpose, and expiry, otherwise stale machine access can persist long after the original use case has ended.
- Entitlement Drift: Entitlement drift is the slow accumulation of permissions that no longer match the original purpose, role, or workload. In cloud-native and NHI-heavy environments, it usually happens because access changes faster than review cycles, leaving organizations with more privilege than they intended.
Deepen your knowledge
NHI governance, IAM, human identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or programme maturity, it is worth exploring.
Published by the NHIMG editorial team on June 8, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org