By NHI Mgmt Group Editorial TeamBased on Axiad: “Are You Doing Everything You Can to Mitigate Your Cyber Security Risks?” (September 16, 2025)

TL;DR: As more processes are automated and more devices, systems, and applications need digital identities, Axiad argues that cloud delivery reduces implementation complexity but does not remove the need for constant lifecycle attention and enablement across users and machines. The underlying risk is that identity programmes still have to inventory, verify, and govern a growing set of non-human and human access paths before productivity and security drift apart.


At a glance

What this is: This is an Axiad analysis arguing that cloud-based MFA and PKI simplify implementation but do not remove the ongoing work of managing expanding digital identity estates.

Why it matters: It matters because IAM and NHI programmes still need continuous inventory, verification, enablement, and lifecycle control as more users, devices, systems, and applications depend on digital identities.


Context

Digital identity sprawl is the growing spread of identities across users, machines, systems, and applications that all need governance. The article argues that cloud delivery lowers deployment friction, but it does not eliminate the operational burden of keeping identity, access, and trust aligned as the environment expands.

For IAM and NHI teams, the governance gap is not a single control failure. It is the cumulative drift that appears when inventory is incomplete, authentication paths are uneven, and enablement work is treated as a one-time rollout instead of a lifecycle discipline.


Key questions

Q: How should teams govern identity across multiple cloud platforms?

A: Teams should govern identity across multiple cloud platforms by standardising policy intent, mapping entitlements consistently, and checking that revocation works across every connected system. The goal is not one universal directory, but one governable model for access decisions, audits, and lifecycle actions across heterogeneous environments.

Q: When does a cloud identity platform create more governance risk than it reduces?

A: Risk rises when the platform is cloud-hosted but the team cannot explain tenancy, data residency, release drift, or operational ownership. In that case, the tool may improve workflow efficiency while weakening auditability. Governance fails when cloud convenience hides control ambiguity.

Q: What breaks when organisations do not have a complete inventory of applications and identities?

A: A partial inventory breaks governance before it breaks technology. Teams cannot consistently onboard apps, map access, detect violations, or prove who has access to what. That leads to shadow applications, stale privileges, weak remediation, and poor audit readiness. In practice, missing inventory means identity controls cover only the known environment while risk accumulates in the rest.

Q: How do security teams prevent identity enablement from becoming shadow IT?

A: Make enablement part of the control design. Use phased rollout, clear communication, and explicit checkpoints so users and systems move onto approved identity paths instead of creating workarounds. The key is to govern the transition itself, because that is where exceptions usually start.


Technical breakdown

Why cloud MFA and PKI still need lifecycle management

Cloud-based MFA and PKI reduce the implementation burden of on-premises deployments, but they do not remove the need to govern how identities are introduced, authenticated, and maintained over time. The article’s point is that delivery model and control model are different things: moving to SaaS can streamline rollout, yet the identity estate still expands across users, machines, and applications. That expansion creates more places where trust must be established, explained, and reviewed. In practice, the hard part shifts from installation to enablement and oversight.

Practical implication: treat cloud identity delivery as an operating model change, not as a signal that governance can become lighter.

Digital identity inventory is the control boundary

A growing number of devices, systems, and applications now host or interface with corporate assets, which makes inventory the first control boundary. Without knowing what exists and how each system authenticates, teams cannot verify whether access is appropriate or whether the identity path is even understood. That is especially true where machine identities, application identities, and user identities intersect in hybrid environments. The article highlights a familiar pattern: visibility is not just a reporting exercise, it is what makes secure enablement possible at all.

Practical implication: build and maintain an inventory that links each digital identity to its authentication method and business function.

Enablement is now the security work, not the afterthought

The article argues that professional services remain essential because enablement is where deployments succeed or fail. User transition, communication, milestone planning, and application onboarding are all part of security because poor enablement creates shadow workflows, friction, and ungoverned exceptions. In other words, the control surface is not just the authentication stack. It is the set of lifecycle activities that make sure people and systems can use the right identity path without bypassing policy. As automation grows, that enablement surface gets larger, not smaller.

Practical implication: design enablement as a governed lifecycle stream with checkpoints, not as a one-off rollout task.


NHI Mgmt Group analysis

Cloud delivery lowers implementation cost, not governance cost. The article correctly separates deployment simplicity from identity assurance maturity. Moving MFA and PKI into the cloud removes operational friction, but the organisation still owns inventory, verification, and lifecycle control across every identity type in the environment. The practitioner conclusion is that cloud adoption changes how work is delivered, not the need for disciplined governance.

Identity inventory is the new control plane for sprawl. Once devices, systems, applications, and users all rely on digital identities, the question is no longer whether the organisation has an identity programme. The question is whether it can enumerate what it governs and how each identity is authenticated. That aligns with NHI governance as much as human IAM, because unmanaged machine and application identities often become the least visible part of the estate. The practitioner conclusion is to treat inventory quality as a security control, not an administrative record.

Enablement failures create hidden security exceptions. The article shows that transition planning, communication, and phased rollout are security issues because bad enablement drives workarounds and unmanaged trust paths. When users or systems cannot adopt the intended identity method cleanly, teams inherit exceptions that outlive the project. The practitioner conclusion is that identity enablement must be governed like any other control change.

Digital identity sprawl is a lifecycle problem, not a deployment problem. More automation means more identities entering the environment over time, and each one needs onboarding, verification, monitoring, and eventual offboarding. That makes the lifecycle model the only durable way to keep pace with changing cloud and system topologies. The practitioner conclusion is to govern identity growth as a continuing operational discipline.

Identity assurance depends on knowing which identities are human, machine, and application-bound. The article’s core risk is not just scale, but the mix of identity types now touching corporate assets. Human authentication patterns, workload credentials, and application access paths fail differently, so a single governance model will miss important failure modes. The practitioner conclusion is to align controls to identity type rather than assuming one access model fits all.

What this signals

Digital identity sprawl changes the work of IAM teams from provisioning projects to continuous control of identity growth. Once the environment contains many more users, devices, applications, and systems than before, the programme needs a durable inventory model and a clearer view of which identities are human, machine, and application-bound.

Identity enablement debt: the hidden backlog created when deployment speed outpaces governance discipline. As organisations automate more work, they need to treat onboarding, verification, and offboarding as repeating control events, not as tasks that end when the project goes live.


For practitioners

  • Map the full digital identity estate Inventory every user, device, application, and system identity that touches corporate assets, then record how each one authenticates and what it can reach.
  • Treat enablement as a governed lifecycle Build rollout milestones, approval points, and communication steps into MFA and PKI transitions so adoption happens without bypassing the intended control path.
  • Separate identity types in governance Maintain different review and assurance paths for humans, machines, and applications because the authentication method, ownership model, and failure mode are not the same.
  • Recheck authentication after every environment change When new systems, processes, or automations are added, confirm that the associated digital identities still use approved trust paths and have not drifted into exceptions.

Key takeaways

  • Cloud identity delivery can reduce deployment friction, but it does not remove the governance burden that comes with a larger and more diverse identity estate.
  • The central operational risk is lack of visibility into what identities exist, how they authenticate, and who owns their lifecycle.
  • IAM teams should treat identity inventory and enablement as ongoing control functions, especially as automation increases the number of machine and application identities.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIThe article warns that expanding identity estates become risky when access is not continuously governed.
NHI-01 — Improper OffboardingLifecycle attention is central because identities and systems accumulate over time without clear end-of-life control.
Recommendation — Review NHI access scope continuously and remove entitlements that no longer match the identity's function. Tie offboarding to identity inventory so retired systems and accounts are revoked and removed from governance records.
NIST CSF 2.0ID.AM-01 — Physical devices and systems within the organization are inventoriedThe article's core problem is incomplete visibility into the devices and systems using digital identities.
PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article stresses verification of how identities authenticate and what access they hold.
Recommendation — Maintain an authoritative inventory of devices and systems that depends on identity access. Validate access permissions and entitlements whenever identities, systems, or applications change.
CIS Controls v8CIS-5 — Account ManagementThe article centers on ongoing account and identity governance as the environment expands.
Recommendation — Centralise account management so every digital identity has an owner and lifecycle state.

Key terms

  • Identity Data Sprawl: The uncontrolled spread of identity-related information across multiple applications, repositories, and workflows after it is captured. This creates overlapping copies, inconsistent access controls, and difficult audit trails, making it harder to prove who can use the data and for what purpose.
  • Identity Enablement: The training, certification, and support model that helps teams use identity tools correctly in day-to-day operations. In mature programmes, enablement reduces implementation variance, improves lifecycle discipline, and makes governance more repeatable across administrators, architects, and reviewers.
  • Lifecycle Governance: Lifecycle governance is the set of controls that cover creation, assignment, review, rotation, and retirement of identities and credentials. For NHIs, it is the difference between a temporary automation asset and a persistent access risk. Strong lifecycle governance keeps ownership and expiry tied to actual business use.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 8, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org