TL;DR: IAM is no longer sufficient on its own as identity volumes, weak MFA patterns, and password exposure push credentials to the centre of access control, according to Axiad’s analysis. The shift to ICAM makes credential issuance, tracking, update, and revocation the governance work that now determines identity resilience.
At a glance
What this is: Axiad says IAM is being overtaken by ICAM as credentials, not passwords, become the practical control point for authentication and access governance.
Why it matters: That matters because IAM teams now have to govern credential issuance, tracking, update, and revocation across human and machine identities, not just manage login experience.
By the numbers:
- The U.S. IAM market was about $18 billion in 2023 and is forecast to reach $63 billion by 2032.
Context
Identity and access management no longer holds the centre of gravity on its own when password failures, weak MFA patterns, and identity sprawl keep shifting control to the credential itself. In practical terms, the question is not only who a user is, but whether the credential being presented is durable, revocable, and governable across its full lifecycle.
ICAM, or Identity, Credential and Access Management, reframes the access problem around the credential as the operational control point. That shift matters for NHI and human IAM alike, because enterprises now need to manage issuance, tracking, update, and revocation with the same discipline they once reserved for access policy.
Axiad's article presents that shift as a naming change with governance consequences: if credentials are the thing that now carries trust, then credential lifecycle becomes the control plane rather than a support function.
Key questions
Q: How should security teams govern credentials when IAM is no longer enough?
A: Security teams should treat credentials as governed identity assets with explicit lifecycle ownership. That means tracking issuance, usage, rotation, update, and revocation across human, machine, and service identities. The goal is not only stronger authentication, but reliable control over credential state so stale access does not survive beyond its intended use.
Q: Why do weak MFA implementations still leave organisations exposed even when passwords are reduced?
A: Weak MFA can still be bypassed when attackers exploit prompt bombing, social engineering, or fallback factors that remain in the flow. If the authentication method is not truly phishing resistant, the organisation still has a path for account compromise. The risk is highest when users can approve login prompts without strong device-bound verification.
Q: What breaks when credential inventory and revocation are incomplete?
A: Access governance becomes detached from the actual trust material in use, so stale or unknown credentials can keep working long after ownership has changed. That creates blind spots for both human accounts and machine identities, and it makes incident response slower because teams cannot revoke what they cannot reliably find.
Q: How should teams measure whether ICAM is actually working?
A: They should look for complete credential visibility, clear ownership, fast revocation, and low reliance on shared or reusable secrets. If credentials can be traced, updated, and retired without delay across human and non-human identities, the governance model is functioning; if not, access assurance is still fragile.
Technical breakdown
Why passwords stopped anchoring authentication
Authentication has always depended on factors of knowledge, possession, or inherence, but passwords have become the weakest and most widely abused knowledge factor. Large-scale password leaks and AI-assisted phishing reduce the practical value of shared or guessable secrets because the factor itself is no longer stable enough to anchor trust. When the same secret appears across multiple accounts or is easily replayed, it stops being an identity proof and becomes a liability. In ICAM terms, the centre of gravity moves away from what the user knows and toward what the user or workload possesses in a more durable form.
Practical implication: Prioritise possession-based credentials over passwords wherever a control can be made both unique and revocable.
What credential management adds to IAM
Credential management is the lifecycle discipline that issues, tracks, updates, and revokes credentials within a defined context. That matters because authentication strength is not only about the factor type, but about whether the credential can be governed after issuance. Certificates, hardware keys, passkeys, API keys, and TLS credentials all require inventory, ownership, renewal logic, and retirement paths. Without those lifecycle controls, access decisions become detached from the actual trust artifacts in use. ICAM is therefore not just a rename of IAM; it is a shift from identity-centric policy to credential-centric operational governance.
Practical implication: Treat credential inventory and revocation as first-class governance controls, not back-office maintenance.
Why machine identities sharpen the ICAM problem
The article's identity ratios show why credentials are now being asked to carry more of the security burden across both people and systems. Machine identities vastly outnumber human identities, which means the scale problem is no longer edge-case admin overhead. Every service account, certificate, API key, and machine credential becomes part of the trust fabric that access control depends on. Once those credentials proliferate, the main challenge is not whether authentication exists, but whether the organisation can continuously govern thousands of credential instances without losing visibility or revocation authority.
Practical implication: Design credential governance for scale, because machine identity growth makes manual oversight structurally unreliable.
Threat narrative
Attacker objective: The attacker seeks authenticated access that survives weak factor controls and opens a path to broader account or workload compromise.
- Entry begins when attackers exploit leaked passwords, weak MFA, or exposed credentials to obtain an initial authenticated foothold.
- Escalation follows when reused or poorly governed credentials let the attacker move from one identity to adjacent systems or accounts.
- Impact occurs when the compromised credential set enables broad access that bypasses the trust assumptions behind IAM controls.
Breaches seen in the wild
- Co-op cyber attack 2025: Attackers linked to Scattered Spider tricked their way into a Co-op employee account and stole personal data of all 6.5 million members.
- Sisense breach 2024: A credential in Sisense's GitLab reportedly opened S3 buckets of customer tokens, passwords and certificates; CISA urged a full reset.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
ICAM is the right name for what identity governance has become: the control point has shifted from static identity records to the credential artifacts that actually carry trust. When passwords and weak MFA variants fail at scale, access policy alone cannot absorb the gap. The practical implication is that identity programmes must be measured by credential governance depth, not by login coverage.
Credential lifecycle is now the operating model, not a supporting process: issue, track, update, and revoke describes the work that determines whether trust can be maintained after authentication. That work spans human and machine identities, because the same governance failure can expose users, service accounts, certificates, or API keys. Practitioners should treat lifecycle ownership as a control boundary, not a ticket queue.
Standing trust in a credential is more fragile than standing access in a role: the article shows that possession factors are replacing knowledge factors because the latter have become easy to steal or spray at scale. That changes the governance problem from who should have access to which trust artifacts are still valid. The implication is that revocation speed and inventory accuracy now define access resilience.
Identity sprawl turns credential management into a scale problem: once machine identities outnumber humans by large margins, manual review models stop being credible as the primary control. The security question is no longer whether teams can authenticate users, but whether they can keep ownership, expiry, and revocation aligned across thousands of credentials. Practitioners need a credential-led operating model, not a password-led one.
Weak MFA is a symptom, not the root problem: the deeper issue is that access assurance still depends on factors that can be cloned, replayed, or socially engineered faster than governance can respond. ICAM does not remove authentication risk, but it makes the credential itself the governed asset. Security teams should reframe access assurance around lifecycle integrity and factor durability.
What this signals
Credential-led governance is now the more accurate mental model: programmes that still treat authentication as a login problem will miss the operational controls that determine whether trust can be maintained after issuance. The shift to ICAM forces teams to manage credentials as governed objects, not incidental implementation details.
Human and non-human identities now fail for the same reason: the control plane breaks when a credential cannot be inventoried, updated, or revoked with confidence. That makes lifecycle governance the common discipline across workforce identity, service accounts, certificates, and API keys.
Possession factors create a new governance threshold: once the organisation replaces password dependence with stronger credentials, it also inherits the responsibility to keep those credentials unique, owned, and continuously current. The work moves from login policy to credential assurance.
For practitioners
- Govern credential lifecycle as a core control Assign ownership for issuing, tracking, updating, and revoking credentials across human and machine identities so that trust artifacts do not outlive their purpose.
- Inventory possession factors across the estate Build a complete inventory of certificates, passkeys, hardware keys, TLS credentials, and API keys so credential sprawl is visible before it becomes an access gap.
- Reduce reliance on password-based authentication Where possible, replace reusable knowledge factors with stronger possession factors that are unique, revocable, and easier to govern at scale.
- Align revocation speed with identity risk Set service-level expectations for credential revocation and renewal so compromised or stale credentials can be removed before they become persistent access paths.
- Map machine identity ownership clearly Tie each non-human credential to a business or technical owner so update and retirement decisions are not blocked by ambiguity when systems change.
Key takeaways
- IAM is no longer sufficient when the credential itself has become the practical control point for access.
- The risk is amplified by password exposure, incomplete MFA, and the scale of machine identities relative to human identities.
- The governance response is to treat credential issuance, tracking, update, and revocation as the core identity control discipline.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5, NIST CSF 2.0 and CSA Cloud Controls Matrix set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-07 — Long-Lived Secrets | The article centres on credentials becoming the control point and the need to manage their lifecycle. |
| NHI-04 — Insecure Authentication | The article discusses failing passwords, weak MFA, and stronger possession-based authentication. | |
| Recommendation — Audit credential lifecycle controls and shorten the time credentials remain valid without review. Replace weak authentication patterns with unique, revocable credentials that are harder to replay or spray. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Credential issue, tracking, update, and revocation map directly to authenticator lifecycle management. |
| Recommendation — Apply IA-5 to govern issuance, rotation, and revocation of all authenticators in scope. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article reframes access control around trustworthy credentials that support authorisation decisions. |
| Recommendation — Align entitlements to verifiable credential states rather than assuming passwords provide sufficient assurance. | ||
| CSA Cloud Controls Matrix | IAM — Identity and Access Management | The article is fundamentally about identity governance and access control at cloud scale. |
| Recommendation — Use IAM controls to keep credential ownership, issuance, and revocation aligned across the estate. | ||
Key terms
- Identity, Credential and Access Management: ICAM is an identity governance model that puts credentials at the centre of access assurance. It extends IAM by focusing on the full lifecycle of issuance, tracking, update, and revocation, which is especially important when machine identities and service credentials outnumber human users.
- Possession factor: An authentication factor that depends on control of a device or physical token. It is stronger when the secret cannot be exported or reused easily, because an attacker must obtain the item itself instead of only the stored credential value.
- Credential Lifecycle: Credential lifecycle is the process of issuing, rotating, expiring, and revoking secrets, certificates, and tokens across their usable life. For non-human identities, lifecycle discipline is the core control that separates temporary access from persistent exposure.
- Machine Identity: The digital identity of a machine, device, or workload, such as a server, container, or VM, used to authenticate it within a network. Sometimes used interchangeably with NHI, though NHI is the broader category.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 8, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org