By NHI Mgmt Group Editorial TeamBased on Axiad: “What you need to know about ‘Identity-first Security’: The rise of remote” (September 16, 2025)

TL;DR: Remote work shifted identity to the front line of enterprise security, with Axiad citing Gartner and Axiad survey data showing that 71% of remote-work threat concerns were phishing and 61% were malware, while 52% of tech leaders said employees had found policy workarounds. Identity-first security is now a governance requirement, not a usability slogan.


At a glance

What this is: This is an Axiad analysis arguing that remote work makes identity the main control plane for enterprise access, because distributed users, devices, and applications increase credential sprawl and policy bypass pressure.

Why it matters: IAM teams have to treat authentication, credential issuance, and user friction as one governance problem across human, machine, and remote-work access paths.

By the numbers:

  • Remote work rose from around 5% before the pandemic to 60% by spring 2020, according to The Economist research cited by Axiad.
  • Axiad’s Remote Work Survey found phishing threats at 71% and malware at 61% as the most significant new threat vectors in remote work environments.

Context

Identity-first security means treating identity verification, credential management, and access policy as the primary security boundary when users, devices, and applications operate outside a fixed office perimeter. In this article, the problem is not remote work itself but the way remote work expands authentication demand faster than governance and usability can keep pace.

Axiad’s analysis is rooted in Gartner’s view that identity-first security has moved from a preferred posture to a necessary one as organisations became fully or mostly remote. The governance issue is that more credentials, more endpoints, and more applications create more places for users to slip past policy when controls are cumbersome.

The article also shows that identity-first security is not a single product decision. It is an operational response to remote employees, extra machine identities, and increased pressure on IT teams that now spend more time issuing and tracking credentials than on higher-value security work.


Key questions

Q: How should IAM teams govern identity-first security for remote workers?

A: IAM teams should govern remote work as an identity lifecycle problem, not just an authentication choice. That means consistent credential issuance, strong proofing where needed, usable authentication methods, and clear offboarding for every access path. If the security process is harder than the work process, users will bypass it, so governance must be designed for daily use.

Q: Why do remote employees create more identity risk than office-based users?

A: Remote employees often authenticate from less controlled devices and networks, then depend on cloud and SaaS access that may be broader than their day-to-day task set. That combination increases the chance that phishing, malware, or a weak workaround becomes an enterprise access event. The risk comes from distributed trust, not remote work alone.

Q: What breaks when credential management is too complex for remote work?

A: When credential management is too complex, users look for shortcuts, IT spends time tracking exceptions, and security policy loses authority. The result is not only a usability issue but a governance issue, because controls that are routinely bypassed do not reduce risk in practice. Complexity becomes an attack enabler when it changes behaviour.

Q: What is the difference between identity-first security and perimeter-based security?

A: Identity-first security treats identity as the main trust anchor and evaluates every access request using identity, context, and risk. Perimeter-based security assumes the network boundary is the main control point and often trusts internal traffic too readily. In modern cloud and SaaS estates, identity-first security is more suitable because access follows the user or workload rather than the location.


Technical breakdown

Why remote work expands the identity attack surface

Remote work changes the shape of the access environment. Instead of a single office network with centrally managed endpoints, organisations must support home networks, personal devices, collaboration tools, and cloud applications that all depend on reliable identity proofing and authentication. That increases the number of credentials, trust decisions, and policy checkpoints in circulation. When those controls are fragmented, users and administrators compensate with shortcuts, which is where the attack surface grows. The article ties this to phishing, malware, and the growth of machine identities needed to keep business processes running.

Practical implication: model remote work as an identity expansion problem, not only a network access problem.

Credential sprawl and policy workarounds

As the number of credentials rises, so does the operational burden of issuing, tracking, onboarding, and offboarding them. That burden is not just administrative. When authentication is inconvenient or inconsistent across tools, users look for the shortest path to productivity, which can mean bypassing security policy. The article’s 52% figure on workarounds is a warning that identity controls fail when they are too hard to use at scale. In practice, the control weakness is not lack of policy language, but policy that is not usable enough to survive real work patterns.

Practical implication: treat user workarounds as a control failure signal, not a behaviour problem alone.

Single-pane credential management for distributed access

The article points toward consolidating multiple authentication methods into one management plane so IT can issue and govern credentials consistently across remote workers. That does not mean collapsing all identity methods into one factor. It means reducing fragmentation so Windows Hello for Business, hardware keys, smart cards, and mobile authenticators can be governed from a coherent workflow. The architectural goal is to keep identity decisions consistent while preserving enough flexibility for different risk levels and device contexts.

Practical implication: design credential management around consistent governance, not one-off authentication exceptions.


Threat narrative

Attacker objective: The attacker’s objective is to gain trusted access through remote-work identity channels and use that access to reach enterprise applications or data.

  1. Entry begins when remote users rely on internet-facing collaboration tools, home networks, and personal devices that broaden the number of identity entry points an attacker can target.
  2. Credential access follows phishing and malware activity that the article identifies as the dominant remote-work threat vectors, creating opportunities to capture login details or session access.
  3. Impact occurs when weakly governed credentials or user workarounds let attackers or insiders move through business systems that depend on remote authentication.
  4. Escalation is amplified by the growth in machine identities and applications, because more credentials create more opportunities for misuse, tracking gaps, and policy bypass.
  • Co-op cyber attack 2025: Attackers linked to Scattered Spider tricked their way into a Co-op employee account and stole personal data of all 6.5 million members.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Remote work turned identity into the primary security boundary. The article reflects a broader shift where access governance now sits ahead of network perimeter assumptions. That matters because identity controls have to absorb users, devices, and applications that no longer share a controlled office context. Practitioners should treat identity-first security as the default operating model for distributed work.

Credential friction is now a security variable, not just an inconvenience. The article’s workarounds finding shows that users bypass policy when authentication becomes too hard to use. That is a governance failure, because policy that cannot survive real user behaviour is not effective control. Teams should measure whether access design is reducing bypass incentives, not just adding authentication steps.

Machine identities rise alongside remote work and widen the governance surface. Remote operations do not only add people and laptops; they add application and device identities that also require lifecycle control. That expands the scope of identity governance beyond employee login events and into the full credential estate. Practitioners should manage human and non-human access as one governance continuum.

Identity-first security is really about operational coherence across access methods. The article points to a single management plane for multiple authentication methods, which is a sign that fragmented identity workflows are becoming unmanageable. When credentials are scattered across tools, IT spends more time on administration and less on risk reduction. The practitioner conclusion is simple: coherence in identity operations is now a security requirement.

Policy bypass is a symptom of governance that did not fit the work pattern. The strongest signal in the article is not the existence of remote work, but the fact that remote employees found ways around policy. That means access governance failed to match the speed, convenience, and diversity of modern work. Teams should view usability as part of security architecture, not a separate concern.

What this signals

Identity-first security is becoming the practical default for distributed work. Organisations cannot rely on office-centric trust assumptions when users operate from home networks, personal devices, and cloud applications. The programme implication is that access governance has to be designed around identity events, not location.

User friction is part of the threat model. When people find security policy too cumbersome, they create bypasses that undermine the entire control set. The right response is not to remove control, but to make identity workflows usable enough that compliance is the easiest path.

The remote-work problem spans human and non-human identities. As collaboration tools, devices, and applications proliferate, the governance task extends beyond employee login to the wider credential estate. Teams that still treat machine identities as a separate operational issue will miss a large part of the access surface.


For practitioners

  • Map remote-work identity touchpoints Inventory every place remote workers authenticate, including collaboration tools, device logins, and mobile authenticators, then identify where policy decisions are duplicated or inconsistent.
  • Reduce credential fragmentation Consolidate issuance and governance for passwords, hardware keys, smart cards, and mobile authenticators so IT can manage them through one policy workflow.
  • Track policy workarounds as control drift Treat reported user workarounds as evidence that identity controls are too burdensome or too slow, and review the exact step where users abandon them.
  • Extend lifecycle control to machine identities Include application and device credentials in onboarding and offboarding processes so remote work does not create unmanaged identities outside the employee lifecycle.

Key takeaways

  • Remote work increases the number of identity decisions security teams must govern, which makes authentication and credential management core control functions rather than support tasks.
  • The article’s most important warning is behavioural: when identity controls are cumbersome, users find workarounds that weaken policy enforcement.
  • IAM teams should unify credential governance across people, devices, and applications so remote access remains usable without becoming loosely controlled.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementThe article focuses on issuing, tracking, and managing many credentials across remote workers.
Recommendation — Apply authenticator management controls to standardise issuance, use, and lifecycle handling.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsRemote work changes how access permissions are granted and enforced across distributed users.
Recommendation — Map remote-access entitlements to PR.AA-05 and remove permissions that are no longer required.
MITRE ATT&CKTA0006 — Credential AccessThe article’s threat discussion centres on phishing and malware as credential-focused remote-work risks.
Recommendation — Prioritise detection and response for credential access attempts tied to remote-work phishing.

Key terms

  • Identity-first security: Identity-first security is an approach that treats identity as the primary control plane for managing risk. Instead of relying mainly on network or endpoint boundaries, it uses identity context to decide what can happen, when it can happen, and under what conditions. That model is especially relevant where privileges move across human, non-human, and agentic actors.
  • Credential Sprawl: Credential sprawl is the uncontrolled accumulation of machine secrets, keys, and tokens across systems, teams, and environments. It usually starts with a single use case and ends with overlapping permissions, unclear ownership, and a larger attack surface than the organisation expected.
  • Policy workaround: Any user action that bypasses the approved identity process in order to complete work faster. Workarounds often appear when controls are too slow or confusing, and they are a strong signal that usability and governance are out of balance in the access model.
  • Machine Identity: The digital identity of a machine, device, or workload, such as a server, container, or VM, used to authenticate it within a network. Sometimes used interchangeably with NHI, though NHI is the broader category.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 8, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org