TL;DR: Just-in-time access reduces the lifetime of a credential, but it does not remove the trust assumptions behind the non-human identity requesting it, according to Entro Security. For IAM and NHI programmes, the real control problem is not expiration speed but whether the issuer, workload, or automation path can be trusted at request time.
At a glance
What this is: This is a blog analysis arguing that JIT access lowers credential lifetime but does not eliminate the standing trust behind the NHI that requests it.
Why it matters: IAM and NHI teams need to treat ephemeral access as a control layer, not a complete zero-trust model, because compromised issuers can still mint fresh privilege on demand.
Context
JIT access is a way to issue privileges only for a short period instead of keeping them permanently available. The problem is that shortening credential lifetime does not answer whether the non-human identity, broker, or automation path requesting access is trustworthy at the moment of issuance.
For NHI programmes, that gap matters because service accounts, CI/CD runners, token brokers, and cloud IAM policies can all become the true control point. If those request paths are compromised, ephemeral tokens still look legitimate and can blend into normal operations.
The article frames this as a governance problem, not just a secret-lifecycle problem. The central issue is standing trust in the identity that can mint access on demand, even when the access itself is short-lived.
Key questions
Q: When does just-in-time access fail as an NHI control?
A: Just-in-time access fails when the standing privilege underneath it remains broad, poorly owned, or rarely reviewed. In that case, JIT only shortens exposure time while leaving the real entitlement problem intact. It works best when the baseline identity is already tightly scoped and the temporary grant is the exception, not the cover for excess access.
Q: When does ephemeral access still create zero-trust risk for NHIs?
A: It creates risk whenever the organisation trusts the identity that mints the access more than the access itself. If the issuer can be compromised, then short-lived tokens only reduce the window of abuse, they do not remove the ability to reissue privilege repeatedly.
Q: What are the signs that JIT access is not being enforced effectively?
A: Common signs include over-reliance on visibility tools, manual triage for risky identities, and policies that can issue privilege but cannot safely deny it when behaviour changes. If a team can see the risk but cannot intervene without breaking production, the control is incomplete.
Q: Why do service accounts and automation paths matter for cloud cost control?
A: Because they decide what can be provisioned, how quickly resources appear, and whether accountability exists after creation. If automation can create clusters or storage without strong policy, waste becomes persistent and difficult to trace. Strong identity controls make cost governance enforceable instead of advisory.
Technical breakdown
Why JIT does not equal zero trust for NHIs
Just-in-time access changes duration, not trust. A JIT model issues privilege on demand, usually through a broker, workload identity system, pipeline runner, token service, or cloud IAM policy. That means the real control point is the issuer, because a compromised issuer can create fresh privileged access that appears normal. In practice, the attack surface shifts from theft of a static secret to abuse of the mechanism that mints the secret. The access request may look legitimate, but the trust decision was made before the request reached the resource.
Practical implication: govern the identity that mints access, not only the token that consumes it.
The factory, not the token, becomes the target
The article’s architectural point is that modern attackers go after the access factory. Instead of chasing a single short-lived token, they compromise the identity, workload, or automation path that can request new ones repeatedly. Once that path is trusted, the system keeps generating valid access and the attacker can operate through normal channels. This is why ephemeral access can still be abused at scale. The token expires, but the issuer remains a standing trust anchor unless it is independently evaluated each time it asks for privilege.
Practical implication: baseline issuer behaviour and treat abnormal access requests as the primary detection signal.
Behavior-based enforcement is the missing control layer
The article distinguishes visibility from enforcement. Many programmes can see risky NHIs or exposed secrets, but they cannot safely intervene when an identity starts behaving outside its normal pattern. The mechanism described is adaptive control based on baseline activity, consumer usage, and sensitive operations, with targeted deny decisions rather than broad revocation. That matters because machine access controls fail when they are too blunt to use operationally. JIT without contextual enforcement still leaves the organisation dependent on static assumptions about trust.
Practical implication: pair JIT issuance with context-aware deny logic that can block abnormal NHI behaviour without breaking production.
Threat narrative
Attacker objective: The attacker wants to turn a trusted issuance path into a repeatable way to obtain legitimate-looking privileged access inside production systems.
- Entry begins when an attacker compromises a trusted service account, workload, or automation path that is allowed to request new privileges.
- Escalation occurs when that identity mints fresh JIT access on demand, making the resulting token or session appear routine and legitimate.
- Impact follows as the attacker uses the valid ephemeral access to operate inside production paths while avoiding the limits that standing privilege removal was meant to create.
Breaches seen in the wild
- Dropbox Sign breach 2024: A compromised back-end service account gave attackers Dropbox Sign customer data, including API keys, OAuth tokens and MFA information.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Ephemeral access does not solve standing trust: JIT reduces exposure windows, but the governance problem remains whether the requesting NHI should be trusted at issuance time. That assumption was built for access requests that could be evaluated against a stable issuer state, not for identities that can be compromised and then mint access on demand. The implication is that NHI programmes must stop treating expiration as proof of trust reduction.
The JIT paradox is an access-factory problem: Security teams often optimise for the token they can see, not the identity that creates it. Once the issuer, broker, or automation path is compromised, the attacker no longer needs to steal every credential in sequence. The implication is that the control plane behind dynamic issuance deserves the same scrutiny as the resource being accessed.
Short-lived privilege still carries standing governance debt: Moving from long-lived secrets to ephemeral credentials is only a partial shift if issuance logic remains unexamined. This is especially true for service accounts and CI/CD runners, where operational legitimacy can mask abuse. The implication is that least privilege must be assessed at request time, not only at provisioning time.
Zero Trust for NHIs must include behavioural enforcement: The article is right to frame zero trust as an outcome rather than a slogan, but the decisive question is whether the programme can deny risky behaviour in context. Visibility alone cannot close the gap between known risk and safe enforcement. The implication is that trust evaluation and policy enforcement must happen before privilege becomes usable.
Standing trust is the new attack surface: The most useful concept in this article is that ephemeral credentials can hide persistent assumptions. A short-lived token is still a symptom of a long-lived trust decision if the issuer is never challenged. The implication is that identity governance now has to measure the trustworthiness of the requester, not just the lifetime of the access.
From our research library:
- 90% of IT leaders say properly managing NHIs is essential for a successful zero-trust implementation, according to the Ultimate Guide to NHIs.
- By 2029, 40% of enterprises that successfully implement zero trust within cloud service provider environments will rely on the advanced visibility and control capabilities offered by CNAPP solutions.
- Read next: Ultimate Guide to NHIs — Standards
What this signals
Standing trust is the control gap JIT does not remove: Programmes that focus only on token duration are still assuming the requester is reliable enough to mint access. That assumption is brittle for service accounts, CI/CD runners, and other NHIs that can be compromised and reused without obvious user-facing friction.
The practical shift is from secret lifetime to issuance governance. Teams need to ask whether their zero-trust model evaluates the identity that asks for access before the access is granted, because otherwise dynamic issuance simply automates old trust assumptions into shorter sessions.
For practitioners
- Audit access issuers, not just credentials Map every broker, workload identity system, CI/CD runner, token service, and cloud IAM policy that can mint JIT access. Treat each as a governed trust decision point and confirm who or what is allowed to request privilege on demand.
- Baseline requester behaviour for each NHI Define normal issuer activity, consumer usage, and sensitive operations for service accounts and automation paths. Use those baselines to flag request patterns that differ from established behaviour before access is granted.
- Add context-aware deny logic Use targeted enforcement that blocks risky NHI behaviour when an identity crosses a meaningful threshold, rather than relying on broad revocation or manual triage after the fact.
- Reassess zero trust at issuance time Check whether your JIT model evaluates trust when access is requested, or only after a token already exists. If the answer is the latter, the programme still depends on standing trust in the requester.
Key takeaways
- JIT reduces the time a credential can be abused, but it does not by itself remove the trust decision behind the identity that requests the credential.
- The article’s example of supply-chain compromise shows that trusted issuance paths can still generate legitimate-looking access for attackers.
- Teams need to evaluate access at issuance time and pair short-lived credentials with behavioural enforcement on the requester.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | The article focuses on dynamic privilege granted to NHIs through trusted issuance paths. |
| NHI-07 — Long-Lived Secrets | JIT is presented as a response to long-lived access, but not a complete replacement for trust controls. | |
| Recommendation — Review issuance paths for overprivileged NHIs and reduce standing trust in request-time access grants. Replace long-lived access patterns with ephemeral issuance while verifying the requester each time. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article is about how access permissions are issued and constrained for NHIs. |
| Recommendation — Apply entitlement controls to ensure JIT access is granted only after contextual authorization checks. | ||
| NIST Zero Trust (SP 800-207) | Access Control Policy — Access Control Policy | The article argues that zero trust must evaluate trust at access request time. |
| Recommendation — Enforce request-time verification so access decisions depend on current context, not standing assumptions. | ||
| MITRE ATT&CK | TA0006; TA0008 — Credential Access; Lateral Movement | The attack pattern described is compromise of trusted issuance paths followed by legitimate-looking movement. |
| Recommendation — Map compromised issuance paths to credential access and lateral movement techniques in your detections. | ||
Key terms
- Just-in-Time Access Request: Just-in-Time Access Request is a pattern that grants access only when it is needed and only for the duration required. It reduces standing privilege by making access temporary, policy driven, and task scoped. This approach is especially useful for contractors, sensitive systems, and short-lived operational work.
- Standing Trust: Persistent confidence in an identity, broker, or automation path to request privilege without sufficient ongoing verification. For NHIs, standing trust can remain even when credentials are short lived, which means the organisation has reduced exposure time but not necessarily reduced the chance of abuse.
- Access Issuance: Access issuance is the process that creates credentials, tokens, or short-lived privileges for a subject at the moment they are needed. For machine and autonomous actors, this is where trust should be evaluated because the decision to mint access can be abused even when the resulting credential expires quickly.
- Behavior Baseline: A record of normal activity for a non-human identity, including typical consumers, resources, and actions over time. Baselines help security teams detect when an identity is being used in an unusual way and provide the context needed to enforce least privilege safely in dynamic environments.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on May 10, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org