TL;DR: Identity migration is no longer a simple platform swap, because legacy authentication, standing privilege, fragmented policies, and emerging AI-agent access all have to be reconciled at once, according to Newcore. The real risk is copying old identity debt into a new stack, while access review assumptions and lifecycle controls fail to keep pace with machine-speed identity behaviour.
At a glance
What this is: This is an analysis of why identity migration now functions as a security redesign exercise, with AI agents, standing privilege, and fragmented identity estates shaping the risk.
Why it matters: It matters because IAM, IGA, PAM, and NHI teams have to modernize authentication and authorization together, or they will simply replatform the same governance weaknesses.
By the numbers:
- 2025 Data Breach Investigations Report.
- The ratio of non-human to human identities now reaches 25x to 50x in modern enterprises.
- Only 5.7% of organisations have full visibility into their service accounts.
👉 Read Newcore's analysis of identity migration and AI agent governance
Context
Identity migration is not just an infrastructure change. It is a governance reset for authentication, authorization, lifecycle control, and the growing set of non-human identities that now operate alongside people in enterprise systems. The primary keyword here is identity migration, and the hard part is no longer selecting a target platform but proving that the new state will not inherit the old one’s risk.
Legacy identity platforms were built for user sign-in, not for blended environments where employees, contractors, cloud workloads, and AI agents all depend on the same control plane. That is why migration becomes a moment of risk concentration: every policy, permission, and dependency is exposed at once, and any attempt to replicate the old model can preserve access creep instead of reducing it.
The governance question is whether modernization actually changes the security boundary or merely relocates it. For teams dealing with machine identity and emerging agent access, the migration window is one of the few times when discovery, cleanup, and control redesign can happen together rather than as separate programmes.
Key questions
Q: What breaks when identity migrations focus only on platform replacement?
A: Teams usually preserve the same weak lifecycle processes inside a newer stack. If entitlement cleanup, review cadence, and application onboarding were fragmented before the move, the migration simply relocates the problem and can make audit evidence harder to trust.
Q: Why do compromised identities remain such a persistent risk in identity security programs?
A: Compromised identities are persistent because access often outlives the original approval, especially for service accounts, API keys, and delegated privileges. When teams cannot continuously verify entitlement and usage, they keep trusting credentials that may already be exposed or misused. A strong program focuses on revocation, least privilege, and continuous monitoring.
Q: How do security teams know modernization is actually reducing risk?
A: They should look for fewer standing privileged accounts, higher MFA coverage, shorter patching cycles, and clearer inventory of human and non-human access. If those measures improve together, modernization is becoming operational control rather than a one-time project.
Q: What should organisations do with AI agent access during an identity migration?
A: They should classify agents as governed non-human identities, assign clear owners, define explicit action boundaries, and include them in lifecycle and access review processes. If an agent can act on behalf of people, its identity cannot be left outside the migration design.
Technical breakdown
Why identity migration exposes hidden access debt
Identity migrations surface the accumulated state of the environment: duplicated identity providers, stale groups, over-broad roles, legacy MFA paths, and application-specific exceptions. The technical problem is not the move itself, but the fact that years of authorisation decisions are often embedded in policy sprawl and undocumented dependencies. If teams lift and shift without re-evaluating those relationships, they preserve the same blast radius in a newer wrapper. For NHI and AI-driven workflows, that matters because access is often programmatic and persistent, which makes inherited privilege harder to see and harder to revoke.
Practical implication: inventory access relationships before cutover and treat privilege reduction as part of migration scope, not a post-migration cleanup.
Phishing-resistant authentication is now a migration baseline
When credential theft remains a primary initial access path, migration is the right point to retire reusable passwords and weak second factors. Phishing-resistant authentication changes the trust model by binding sign-in to stronger authenticators rather than shared secrets that can be replayed. That is especially important when modern identity estates include contractors, service accounts, and AI agents that may depend on federated access patterns. If the authentication layer is modernized without updating downstream session, policy, and recovery controls, the organisation can still end up with a weak perimeter around a stronger login method.
Practical implication: use the migration programme to replace vulnerable authentication paths before moving critical applications onto the new platform.
AI agents change migration from a human IAM project into a blended identity problem
AI agents are not just another workload class. They introduce decision-making that can act on behalf of people, which means the identity model must cover ownership, authorization scope, continuous evaluation, and lifecycle handling in ways that traditional human-centric IAM did not need. In practice, this blurs the line between NHI governance and human access governance because the agent’s actions often inherit human intent but execute through machine credentials. Migration plans that ignore this will understate who is accountable for access and how rapidly privileges can expand.
Practical implication: define agent ownership and authorization rules before the migration reaches production, or you will create unmanaged delegated access.
Threat narrative
Attacker objective: The attacker objective is to turn identity complexity and reused access into durable control over enterprise applications and cloud-connected systems.
- Entry begins with compromised credentials because attackers increasingly rely on login reuse rather than infrastructure exploitation.
- Escalation follows when standing privileges and inherited access let the intruder move through applications and policies that were never rightsized.
- Impact comes from preserved legacy complexity, which lets attackers persist longer and reach broader systems after migration gaps are exposed.
Breaches seen in the wild
- Meta AI Instagram Account Takeover — 20,225 Instagram accounts hijacked via compromised Meta AI support chatbot with overprivileged access.
- Replit AI Tool Database Deletion — Replit vibe coding AI assistant deletes live production database and creates 4,000 fake user records.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Identity migration has become a control redesign exercise, not a platform replacement exercise. The article is right to frame modernization as a journey, because the real risk sits in what gets copied forward. If access models, policy exceptions, and lifecycle gaps are simply reinstalled on the new platform, the organisation has modernized the interface but not the governance. The practitioner conclusion is clear: migration is the moment to reset identity design, not preserve historical debt.
Phishing-resistant authentication only solves part of the problem if authorisation remains unchanged. Replacing passwords does not neutralize standing privilege, fragmented administrative tools, or over-broad app entitlements. Identity security improves only when authentication, authorization, and governance move together. The practitioner conclusion is that MFA modernization without privilege rightsizing is incomplete by design.
AI agents force identity programmes to treat non-human access as a first-class governance domain. The article correctly places agents inside the identity model, because their access patterns are not just automated they are delegated. That means NHI controls, lifecycle processes, and ownership rules now intersect with human intent and machine execution. The practitioner conclusion is that agent access cannot remain a side project inside workload security.
Access creep is the migration debt most organisations underestimate. Years of entitlement growth create a hidden attack surface that becomes visible only when systems are mapped, tested, and staged. The article’s four-step transition model reflects an important truth: discovery and pre-flight validation are governance controls, not mere project tasks. The practitioner conclusion is to remove privilege bloat before activation, not after go-live.
Fragmented identity estates will continue to fail governance expectations until consolidation is paired with lifecycle discipline. Multiple identity providers and overlapping admin tools create ambiguity about ownership, offboarding, and policy enforcement. Consolidation can reduce complexity, but only if it also clarifies who owns each identity type and how access is reviewed. The practitioner conclusion is that architecture simplification without lifecycle governance just redistributes the problem.
From our research:
- Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
- Another 97% of NHIs carry excessive privileges, which is why migration programmes should treat rightsizing as a core control rather than a cleanup task.
- This broader identity problem is documented in the NHI Lifecycle Management Guide, which is the right next resource for provisioning, rotation, and offboarding discipline.
What this signals
Identity migration will increasingly be judged by governance outcomes, not cutover speed. Teams that preserve old policies in new tooling will still fail on visibility, offboarding, and privilege reduction. The practical bar is whether the new estate is easier to review, easier to decompose, and harder to abuse than the old one.
With 1.5 out of 10 organisations highly confident in securing NHIs according to Astrix Security and CSA, the blended identity model is already a programme risk, not a future one. Migration plans that do not explicitly cover machine and agent identities will leave the weakest part of the estate untouched.
In practice, the next wave of identity work will merge migration, lifecycle, and privilege governance into one operating model. That makes discovery and pre-flight validation essential controls, because they are the only points where teams can still see the full identity graph before it is reassembled.
For practitioners
- Map every identity dependency before cutover Build a complete inventory of identity providers, applications, groups, policies, authentication methods, and delegated access paths so the migration team can see where changes will propagate.
- Remove standing privilege as a migration workstream Use the transition window to rightsize roles, eliminate excess administrative access, and convert sensitive operations to just-in-time approval where possible.
- Treat AI agent access as governed delegation Assign explicit ownership for each agent, define its permitted actions, and require the same review discipline you would apply to other non-human identities.
- Stage and validate the future state before activation Pre-flight authentication flows, policy inheritance, rollback paths, and application dependencies in a controlled environment before production rollout begins.
Key takeaways
- Identity migration is really a decision about whether the organisation will carry old access debt into a new platform.
- Credential theft, standing privilege, and fragmented identity estates remain the main reasons modernization can fail to reduce risk.
- AI agents and service accounts must be included in migration scope, or the new identity foundation will be incomplete from day one.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207), NIST SP 800-53 Rev 5 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-03 | The article centers on legacy credentials, overprivilege, and NHI lifecycle gaps. |
| Recommendation: Review NHI credential scope and lifecycle controls before and during migration to reduce inherited risk. | ||
| NIST CSF 2.0 | PR.AC-1 | Identity migration hinges on managed access control and identity proofing outcomes. |
| Recommendation: Map migration work to access control outcomes and verify each identity path before activation. | ||
| NIST Zero Trust (SP 800-207) | The article's zero-trust implications center on continuous verification during identity transitions. | |
| Recommendation: Use zero-trust principles to revalidate identity trust assumptions before moving critical access paths. | ||
| NIST SP 800-53 Rev 5 | IA-2 | The authentication modernization section directly aligns to identity and authentication controls. |
| Recommendation: Strengthen authentication controls as part of migration rather than after the cutover. | ||
| NIST SP 800-53 Rev 5 | AC-6 | Access creep and standing privilege are explicit concerns in the article. |
| Recommendation: Apply least-privilege controls to remove excess entitlements before replatforming identities. | ||
Key terms
- Identity Migration: The planned movement of identity data, configuration, and control logic from one operating model to another. For cloud identity security, the hard part is usually preserving governance outcomes after the platform, release cadence, and support model change.
- Standing Privilege: Standing privilege is access that remains active even when no immediate task requires it. For NHI programmes, it is a common failure mode because long-lived credentials and persistent roles create unnecessary exposure. Reducing standing privilege usually means tighter expiry, on-demand access, and clearer review of who or what still needs access.
- Phishing-Resistant Authentication: Phishing-resistant authentication proves identity without relying on a user to approve a prompt or reveal a reusable secret. It typically binds access to a device, key, or cryptographic proof that an attacker cannot easily reuse or coerce. This approach reduces reliance on human judgment at login time.
- Mixed Workforce Identity: A mixed workforce identity environment includes employees, contractors, vendors and partners who all require access under different terms. The governance challenge is that each group has a distinct lifecycle, approval chain and revocation trigger, even when they use the same applications and data.
What's in the full article
Newcore's full article covers the operational detail this post intentionally leaves for the source:
- The step-by-step migration framework for discovery, planning, pre-flight testing, and controlled activation.
- The way Newcore says AI agents fit into the transition model for humans and machines.
- The practical rollout approach for reducing access risk without disrupting business continuity.
- The platform-specific mechanics behind authentication and authorization changes during modernization.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an identity programme, it is worth exploring.
Published by the NHIMG editorial team on September 5, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org