By NHI Mgmt Group Editorial TeamDomain: Governance & RiskSource: ExpelPublished May 22, 2026

TL;DR: Remote and hybrid work expand identity attack paths through phishing, VPN credential theft, SaaS OAuth abuse, and shadow IT, and Expel argues that ITDR closes those gaps with behavioral baselines, device fingerprinting, and continuous SaaS monitoring. The deeper issue is that perimeter-era controls still assume identity is stable enough to trust, while distributed work makes trust conditional and constantly testable.


At a glance

What this is: This is an analysis of why remote and hybrid work makes identity the primary attack surface, and how ITDR helps detect and contain identity-driven abuse.

Why it matters: It matters because IAM, PAM, and NHI programmes now have to verify identity continuously across users, workloads, and SaaS access instead of assuming a fixed network boundary.

👉 Read Expel's analysis of ITDR for remote and hybrid workforce identity risk


Context

Remote and hybrid work turn identity into the main control plane because users, devices, and SaaS access no longer stay inside a predictable perimeter. That changes the detection problem from watching a fixed network to understanding whether a specific identity is behaving normally across locations, devices, and applications.

The primary governance gap is not remote work itself, but the assumption that valid credentials prove valid intent. In distributed environments, phishing, VPN credential theft, OAuth abuse, and shadow IT all exploit that assumption, so IAM teams need continuous verification and stronger identity telemetry to keep trust decisions current.

For NHI and human identity programmes alike, the lesson is the same: access that is granted once is not inherently trustworthy for the rest of the session. Remote work simply makes that mismatch easier to exploit and harder to spot with legacy monitoring.


Key questions

Q: How should security teams reduce identity risk in remote workforce environments?

A: Security teams should reduce the number of resources each remote identity can reach, then align MFA, device posture, and access reviews with how people actually work. If users can bypass the control or delay it until later, the control is not protecting the session. The goal is to lower the blast radius of one compromised user account.

Q: Why does remote work make OAuth abuse more dangerous?

A: Remote work makes OAuth abuse more dangerous because SaaS access becomes the operational backbone, so a compromised grant can move laterally across business apps without a fresh login event. Attackers can remain inside the application layer even when traditional perimeter controls look clean. That makes consent review and scope control essential.

Q: What breaks when identity monitoring only looks at network location?

A: Network-only monitoring breaks because remote users no longer share a stable office perimeter, and attackers can authenticate from anywhere once credentials are stolen. A login from the right network says little about the legitimacy of the session. Effective monitoring has to combine device, behavior, and SaaS activity signals.

Q: Who is accountable when a non-human actor abuses delegated SaaS access?

A: Accountability should sit with the business owner of the integration, the platform team that approved the grant, and the security function that monitors its use. If no one owns the delegation lifecycle, then the organisation has created access that can persist without meaningful oversight.


Technical breakdown

Behavioral baselines for remote identity activity

ITDR starts by learning how a specific identity normally behaves, including login geography, time-of-day patterns, device traits, and application usage. This matters because aggregated anomaly thresholds are too blunt for distributed workforces, where legitimate travel, home networks, and BYOD all create variation. The control is not just anomaly detection, but context-aware comparison against the identity’s own history. That makes it possible to separate a routine remote login from a session that suddenly appears to originate from an implausible environment.

Practical implication: build identity baselines per user and role, not per network segment, so remote activity can be judged against actual behavior.

SaaS OAuth abuse and shadow IT monitoring

Remote organisations depend heavily on SaaS, which means OAuth grants and app-to-app permissions become a high-value abuse path. Once an attacker controls an identity with active grants, they can move across connected services without triggering a traditional login event. Shadow IT widens that risk because unapproved apps may request access directly through corporate identity infrastructure. ITDR therefore has to monitor consent events, permission changes, and suspicious app activity across the SaaS estate, not just authentication logs in the IdP.

Practical implication: review OAuth grants and unapproved app access as part of identity governance, because consent has become a de facto access pathway.

Impossible travel and device fingerprinting in distributed teams

Impossible travel detection and device fingerprinting work together to catch identity compromise that looks valid at first glance. If the same account authenticates from two far-apart locations in an implausible time window, or appears on an unregistered device with an unfamiliar fingerprint, the identity signal no longer matches the expected user pattern. For distributed teams, this is more useful than location alone because it accounts for the reality that remote employees and contractors often connect from many places, but not in physically impossible sequences.

Practical implication: tune detection to the workforce’s real mobility profile so you can flag compromise without drowning analysts in travel-related false positives.


Threat narrative

Attacker objective: The attacker wants to look like a legitimate remote user long enough to move through SaaS and identity systems without raising suspicion.

  1. Entry occurs through phishing, VPN credential theft, or abused OAuth consent, giving the attacker a valid identity foothold that looks legitimate in a remote-first environment.
  2. Escalation happens when the attacker uses that foothold to pivot across SaaS applications, harvest sessions, or operate through overpermissive grants that were never revisited.
  3. Impact is achieved through silent access to collaboration, file-sharing, finance, or admin workflows, often without a classic perimeter alert ever firing.
  • MITRE ATT&CK Enterprise Matrix — MITRE ATT&CK Enterprise — adversary tactics and techniques, threat detection, attack chain mapping, credential access, lateral movement, privilege escalation.
  • Cisco DevHub NHI breach — IntelBroker exploited exposed Cisco credentials, API tokens and keys in DevHub.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Continuous verification matters more than network location because remote work invalidates the old trust boundary. Security programmes that still rely on office IPs, managed subnets, or fixed access zones are already behind the operating model. Zero Trust Architecture only holds when identity signals are current enough to support every access decision, which is why ITDR belongs in the enforcement layer rather than the edge network. Practitioners should treat identity telemetry as a core control surface, not an optional detector.

SaaS consent has become a standing access path, not a one-time approval. Remote work makes OAuth grants, app integrations, and browser-based sessions function like machine-readable entitlements that outlive the task they were created for. That creates entitlement drift across human accounts and NHI-style service access alike, especially where approvals are rarely revisited. The practical conclusion is that consent governance now sits inside identity governance, not beside it.

Entitlement drift in distributed environments is a visibility problem before it is a privilege problem. The biggest failure mode is not that access was intentionally overgranted, but that it remained unnoticed after the working context changed. ITDR surfaces that drift through behavior, device, and SaaS activity signals, which is why it complements, rather than replaces, IGA and PAM. Teams should use it to find stale access that has become operationally invisible.

Remote work compresses the response window, so automated containment becomes part of identity governance. When attackers can move from a valid credential to SaaS abuse in minutes, manual triage is too slow for the first containment step. That shifts the governance question from whether access is authorised to whether suspicious access can be disrupted before it spreads. Practitioners should align identity response playbooks with the speed of modern credential abuse.

Identity behaviour is now the common control language across human, NHI, and emerging agentic access. The same distributed-work assumptions that break human monitoring also undermine service-account oversight when those identities reach SaaS and cloud tools. The named concept is identity trust drift: trust that persists after the context that created it has changed. That is the governance problem ITDR exposes, and teams need to manage it as a lifecycle issue, not just a detection issue.

From our research:

  • 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, according to The State of Non-Human Identity Security.
  • Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities.
  • Why NHI Security Matters Now frames why this visibility gap is widening as machine and SaaS access grows.

What this signals

Identity trust drift: remote and hybrid work creates access that remains technically valid after the context that justified it has disappeared. That is why the programme signal to watch is not only login success, but whether grants, devices, and sessions still match the business purpose that created them.

The practical implication is that IAM and ITDR teams need to work from the same telemetry set. If consent reviews, device trust, and behavioural baselines are split across tools, response becomes slower than attacker dwell time and the zero trust promise weakens.

For NHI and human identity governance alike, the next control maturity step is continuous context validation, not broader allowance. That shift matters most where SaaS and remote access overlap, because that is where stale trust survives longest.


For practitioners

  • Map remote identity trust assumptions to actual access paths Document where your programme still assumes users are on trusted networks, then compare that assumption with VPN, SaaS, and browser-based access patterns. Prioritise the paths that let valid credentials reach high-value systems without additional context.
  • Inventory OAuth grants and app consents across the SaaS estate Pull consent records from your identity provider and SaaS platforms, then identify apps with broad scopes, inactive owners, or no expiry review. Treat long-lived grants as access that needs lifecycle management, not a one-time approval event.
  • Tune behavioural baselines per user and role Separate frequent travellers, contractors, and fixed-location staff into different behavioural expectations so impossible travel, device changes, and login timing are judged in context. This reduces false positives while preserving sensitivity to real compromise.
  • Automate containment for suspicious remote sessions Predefine response actions for credential reset, OAuth revocation, session termination, and device quarantine so analysts are not waiting on manual approval during an active compromise. The objective is to shorten the time between detection and containment.
  • Extend identity governance to shadow IT and unapproved tools Monitor for applications and browser extensions that request identity access outside approved procurement and security review paths. If a tool can harvest tokens or request OAuth access, it belongs in identity governance even before it is formally sanctioned.

Key takeaways

  • Remote and hybrid work expose a trust problem, not just a monitoring problem, because valid credentials can outlive the context that made them safe.
  • OAuth grants, device signals, and behavioral baselines are now core identity controls for distributed teams, not optional detective layers.
  • ITDR gives zero trust an enforcement mechanism, but only if teams connect it to governance, consent review, and automated containment.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-4Least-privilege and access management are central to remote identity risk.
NIST Zero Trust (SP 800-207)The article frames ITDR as the enforcement layer for zero trust.
NIST SP 800-53 Rev 5AC-2Account management controls govern stale access and entitlement drift.
OWASP Non-Human Identity Top 10NHI-03OAuth grants and session tokens are part of the non-human identity attack surface.

Use zero trust principles to require continuous identity verification across remote access and SaaS sessions.


Key terms

  • Identity Threat Detection and Response: Identity threat detection and response is the practice of finding misuse of credentials, unusual access patterns, and compromised identities across human and machine actors. For NHIs, it relies on telemetry from code, vaults, cloud services, and pipelines to detect abuse early enough to contain it.
  • OAuth Grant: An OAuth grant is the delegated permission an application receives to act on a user's behalf without storing the user's password. In NHI governance, it should be treated as a standing identity relationship with scope, ownership, and revocation requirements, not as a one-time setup detail.
  • Impossible travel detection: A login-risk control that compares the time and location of two sign-ins from the same account to flag physically implausible movement. In practice, it is a heuristic for credential abuse, not proof of compromise, and it needs contextual signals to avoid excessive false positives.
  • Identity Trust Drift: The gap between the access model an organisation thinks it operates and the access reality created by constant change. It shows up when ownership, entitlements, and business context fall out of sync, leaving identity controls technically present but operationally stale.

What's in the full article

Expel's full article covers the operational detail this post intentionally leaves for the source:

  • Specific examples of how ITDR spots phishing, VPN theft, SaaS OAuth abuse, and shadow IT in remote environments.
  • Control-by-control comparison of behavioral baselines, impossible travel detection, device fingerprinting, and SaaS monitoring.
  • Practical guidance on what response actions can be automated when suspicious identity activity is detected.
  • Implementation considerations for organisations running Entra ID, Okta, or hybrid identity environments.

👉 The full Expel article covers the detection signals, response mechanics, and deployment considerations in more detail.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 18, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org