By NHI Mgmt Group Editorial TeamDomain: Governance & RiskSource: Orchid SecurityPublished January 4, 2026

TL;DR: 51% of identity implemented across European enterprises sits in an unmanaged layer it calls identity dark matter, while 48% of applications store credentials in cleartext and 44% bypass the corporate identity provider, according to Orchid Security. That gap means traditional IAM coverage, not just policy intent, now defines real exposure.


At a glance

What this is: This analysis argues that the real identity risk in large enterprises comes from unmanaged application-level controls, with identity dark matter hiding more than half of implemented identity across European environments.

Why it matters: It matters because IAM, IGA, PAM, and compliance programmes can look healthy on paper while critical authentication and authorisation paths remain outside central control.

By the numbers:

👉 Read Orchid Security's analysis of identity dark matter and application-level IAM gaps


Context

Identity dark matter is the unmanaged identity layer that lives inside applications rather than in central IAM records. The article's core point is that identity security is being decided at the application source, not by the control plane many programmes think they operate.

That matters for NHI, service accounts, and human access alike because hidden local credentials, bypass paths, and orphaned accounts can all sit outside governance. In a large application estate, the gap between documented policy and actual enforcement becomes the real attack surface.

The European context raises the stakes further because the same exposure pattern affects cyber risk, regulatory posture, and operating cost. The article argues that organisations are often measuring identity maturity by the strength of their tooling stack rather than by what actually exists inside applications.


Key questions

Q: How should security teams find the identities that traditional IAM tools miss?

A: Use continuous discovery across cloud, SaaS, on-premises, and directory sources, then correlate each identity with ownership, entitlements, and last activity. The goal is to expose dormant, orphaned, shadow, and service identities before they become access paths. If a control only reviews known accounts, it is not measuring the full identity attack surface.

Q: Why do unmanaged apps and machine identities increase identity risk?

A: Because they can authenticate to critical systems without going through the same lifecycle controls used for human users. That means access may persist after business need changes, monitoring may miss the true actor, and revocation can lag behind exposure. Once access falls outside the managed control plane, governance becomes partial by design.

Q: What do organisations get wrong about IAM maturity?

A: They often confuse tool adoption with control coverage. A strong IdP, PAM, or IGA stack does not guarantee that every application is enforcing the same controls. Maturity must be measured by real enforcement, continuous drift detection, and evidence that local identity paths are governed.

Q: Who is accountable when agent-based identity controls miss an application?

A: Accountability sits with the identity and application owners who approved the operating model, not with the agent alone. If an access path is outside coverage, the organisation still owns the governance gap. Frameworks such as NIST Cybersecurity Framework 2.0 help assign responsibility across identify, protect, and govern functions.


Technical breakdown

Application-level identity controls are the real source of truth

Identity is implemented inside each application, either natively or through integration with central IAM tools. That means the effective control state is determined by local authentication flows, authorization logic, and credential handling inside the app, not by policy documentation or directory design. In practice, one unmanaged application can negate assumptions made by an otherwise mature identity programme. This is why discovery must extend beyond registered SaaS and directory-linked systems into self-hosted, legacy, and acquired applications.

Practical implication: map identity controls at the application source, not just in the IAM platform, before you claim coverage.

Shadow authentication paths create identity dark matter

The article highlights alternate identity paths such as local logins, break-glass accounts, third-party access built directly into the application, and service accounts that never touch the primary identity provider. These paths are risky because they bypass central policy enforcement, logging consistency, and lifecycle governance. They also create fragmentation between what IAM records say and what the application actually permits. Once those paths exist, recertification and access review processes lose fidelity because the system of record is incomplete.

Practical implication: inventory non-IdP authentication and local credential stores as first-class identity assets.

Identity drift is an operational control problem, not just a compliance one

The article describes drift in permissions, policies, and application upgrades as a persistent source of exposure. Over time, controls that were once aligned can weaken through patching, mergers, local exceptions, or developer shortcuts. The important technical point is that identity posture changes continuously, so point-in-time audits miss the state that attackers actually exploit. Continuous telemetry is therefore more useful than periodic questionnaire-based assessments for finding stale access, over-permissioned roles, and control failure.

Practical implication: monitor identity drift continuously and tie remediation to evidence from the application, not self-attestation.


Threat narrative

Attacker objective: The attacker aims to exploit unmanaged identity paths to gain access that central IAM and compliance reviews never actually constrained.

  1. Entry occurs through credentials, local authentication paths, or third-party access that bypass central identity controls.
  2. Escalation follows when over-permissioned roles, dormant accounts, or service accounts provide broader access than intended.
  3. Impact is realised through credential abuse, unauthorized access, and delayed detection across applications that were never fully governed.
  • Cisco DevHub NHI breach — IntelBroker exploited exposed Cisco credentials, API tokens and keys in DevHub.
  • Coupang Signing Key Breach — Unrevoked signing key credentials expose 33.7 million records after employee offboarding failure at Coupang.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Identity dark matter is not an edge case. It is the operating reality of large application estates. The article's 51% figure shows that more than half of implemented identity can sit outside the governed control plane. That means programme maturity cannot be inferred from IdP coverage alone, because the decisive controls live inside applications. Practitioners should treat application-level identity discovery as a baseline requirement, not an advanced capability.

Application identity source-of-truth drift: when local authentication, third-party access, and break-glass accounts accumulate outside central governance, the IAM programme loses epistemic control. This is the failure mode the article describes. Policy still exists, but the programme can no longer prove what is actually enforced where access is used. The implication is that recertification, PAM, and IGA are only as strong as the application layer they can observe.

Europe's identity problem is governance fragmentation, not just tooling shortage. The article shows that organisations may own central IAM, PAM, and IGA tooling while still leaving broad identity exposure in application-specific implementations. That changes how we should read maturity scores. A mature-seeming stack can coexist with weak enforcement, so control validation has to move closer to the transaction and authentication point.

Identity risk now includes compliance false confidence. The same hidden control gaps that create breach exposure also undermine regulatory claims under NIS2, DORA, and GDPR because the organisation cannot evidence enforcement where it matters. This is not simply a technical hygiene issue. Security, audit, and legal teams need the same application-level evidence set, or the governance story remains incomplete.

From our research:

  • 51% of all identity implemented throughout European enterprises is unmanaged and often invisible, according to Ultimate Guide to NHIs.
  • Only 5.7% of organisations have full visibility into their service accounts, which shows how limited many identity programmes remain in practice.
  • That visibility gap is why the 52 NHI Breaches Analysis is useful when teams need to move from discovery to incident pattern recognition.

What this signals

Identity dark matter turns IAM into a verification problem, not a procurement problem. If 51% of implemented identity can sit outside visible control, then the next programme milestone is not another tool purchase but application-level evidence gathering. Teams should expect discovery, monitoring, and recertification to converge around the application source, especially in hybrid estates.

Service accounts and hidden authentication paths will keep surfacing as audit pain points until governance follows the app. The practical shift is to treat local credentials, bypass flows, and third-party access as assets that need lifecycle ownership. That is the point where the governance model stops assuming central completeness and starts proving it.

The next maturity step is to connect identity telemetry with remediation workflows so drift becomes actionable. That is where the Ultimate Guide to NHIs remains relevant, because visibility, rotation, and offboarding are the controls that expose whether an identity programme is real or merely documented.


For practitioners

  • Discover identity outside the control plane Build a catalogue of applications that authenticate locally, use alternate login paths, or store credentials outside the corporate identity provider. Include self-hosted, legacy, acquired, and shadow IT systems, then verify each one against actual authentication behaviour.
  • Measure control drift inside applications Continuously test for changes in permissions, protocol use, and access enforcement after patches, upgrades, or mergers. Use evidence from application telemetry and user activity rather than relying on policy documents or owner attestations.
  • Prioritise exposed credential stores and bypass paths Start remediation with cleartext credentials, weak hashing, and authentication flows that bypass the corporate Identity Provider. These are high-risk entry points that often sit entirely outside normal IAM dashboards.
  • Validate offboarding and dormant account cleanup Check whether orphaned, inactive, and service accounts are actually removed when users, vendors, or applications change state. If not, the identity programme is carrying hidden access that recertification will not catch.

Key takeaways

  • Identity exposure in modern enterprises often sits inside applications, not inside the IAM stack that leaders see most clearly.
  • Hidden authentication paths, cleartext credentials, and weak control enforcement explain why compliance success can coexist with real breach risk.
  • Practitioners need application-level discovery and continuous drift validation if they want to govern identity as it actually operates.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack surface, NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the technical controls, and ISO/IEC 27001:2022 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01Hidden credentials and unmanaged identities are the central risk pattern in this article.
NIST CSF 2.0ID.AM-1Asset inventory is essential when identity exists outside central IAM records.
NIST SP 800-53 Rev 5AC-2Account management breaks down when orphaned and local accounts persist outside governance.
NIST Zero Trust (SP 800-207)Zero Trust depends on continuous verification across all application access paths.
ISO/IEC 27001:2022A.5.15Access control policy must cover local application paths and shadow identities.

Validate that access control policies extend to application-level authentication and authorisation, not just central IAM.


Key terms

  • Identity Dark Matter: Identity dark matter is the hidden mass of old grants, unused credentials, and inherited access that exists in an environment but is not actively understood. In NHI programmes it becomes dangerous because autonomous systems can discover and reuse it at machine speed.
  • Shadow Identity: A shadow identity is a machine identity created outside central governance, often by developers or automation tooling. These identities are dangerous because they bypass normal provisioning and offboarding controls, making them hard to inventory, review, and revoke before attackers find them.
  • Application-Level Source of Truth: The application-level source of truth is the actual place where identity enforcement happens, including login logic, roles, tokens, and access decisions. In large estates, this matters more than policy documents because it reveals what is truly enforced for each application and account.

What's in the full report

Orchid Security's full article covers the operational detail this post intentionally leaves for the source:

  • The application-by-application discovery approach used to surface hidden authentication flows and local identity paths.
  • The full checklist of identity control questions for mapping coverage across thousands of applications.
  • The detailed breakdown of European identity dark matter findings, including cleartext credentials, IdP bypass, and access-control gaps.
  • The remediation workflow that follows discovery, including onboarding and resolution steps across hybrid estates.

👉 Orchid Security's full post includes the European snapshot, the control checklist, and the remediation workflow behind the findings.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an identity security programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 14, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org