By NHI Mgmt Group Editorial TeamBased on StrongDM: “3 Reasons Why Least Privilege Has Failed” (June 26, 2025)

TL;DR: Weak visibility leaves least privilege unenforceable in practice: analysis of 225 companies found 85% of privileged credentials, nearly 1 in 3 users with access, and 15% of accessible resources went unused over 90 days, according to StrongDM. The governance problem is no longer whether least privilege is sound, but whether identity teams can measure real usage fast enough to remove standing risk.


At a glance

What this is: This analysis argues that least privilege becomes unenforceable when organisations cannot measure real access usage across credentials, users, and resources.

Why it matters: IAM, IGA, and PAM teams need usage visibility to remove standing access, reduce attack surface, and avoid leaving dormant privilege in place.

By the numbers:

  • 85% of credentials with privileges have not been used in the last 90 days.
  • Nearly 1 in 3 users with access to systems have not used that access in the last 90 days.
  • 15% of resources available have not been accessed in the last 90 days.

Context

Least privilege is supposed to constrain access to what is necessary, but that model depends on knowing what is actually used in production. When visibility into access usage is weak, entitlement review turns into guesswork and dormant privilege stays in place.

For IAM, IGA, and PAM programmes, the governance problem is not policy intent. It is operational proof: if teams cannot observe real usage across identities and assets, they cannot confidently remove excess access or justify the controls they keep.

The article frames this as a visibility gap across users, privileges, and resources, which means the attack surface is larger than entitlement lists suggest. In practice, that shifts least privilege from a provisioning principle to an ongoing measurement problem.


Key questions

Q: What breaks when least privilege is based on entitlement lists instead of real usage?

A: Least privilege becomes hard to enforce because the team is optimising for what was granted, not what is still needed. Dormant credentials and unused access remain available, so excess privilege persists as attack surface even when no one is actively using it.

Q: Why do unused privileged credentials still matter to IAM teams?

A: Unused privileged credentials matter because privilege is the risk, not activity alone. A credential that has not been used for months can still be stolen, abused, or reactivated, so inactivity does not equal safety when the permission remains in place.

Q: How do security teams know whether least privilege is actually working?

A: Least privilege is working when identities have narrowly scoped permissions, unused credentials are removed or quarantined, and repeated access reviews consistently shrink entitlements. A good signal is whether a compromised identity would be unable to move beyond one bounded workflow. If broad resource reach still exists, the control is not effective.

Q: What should organisations do with resources that are never accessed?

A: They should treat never-accessed resources as candidates for retirement, isolation, or stricter containment. Unused assets still expand the reachable environment, so reducing them lowers both exposure and the work required to govern access properly.


Technical breakdown

Why unused privileges become standing risk

Privileges that are assigned but rarely exercised are difficult to defend because their true necessity is unknown. In practice, unused entitlements persist due to provisioning friction, incomplete telemetry, and the assumption that access granted once will still be required later. That creates a standing risk window where credentials remain available even though business need has faded. The article ties this directly to privileged credentials that have not been used in 90 days, which is a strong indicator that entitlement governance is lagging operational reality. Practical implication: treat low-usage privileged access as a review trigger, not as proof of harmlessness.

Practical implication: treat low-usage privileged access as a review trigger, not as proof of harmlessness.

How over-provisioning hides in identity sprawl

Modern environments spread access across systems, cloud services, and teams, which makes it easy to grant broader access than users actually consume. Over-provisioning is not only a rights-management issue; it is a visibility issue because teams often cannot trace which permissions were exercised, when, and for what purpose. The article’s finding that nearly 1 in 3 users had access they did not use shows how quickly “temporary convenience” becomes persistent excess. Practical implication: entitlement decisions should be tied to observed usage rather than assumed role need alone.

Practical implication: entitlement decisions should be tied to observed usage rather than assumed role need alone.

Why unused resources matter to least privilege

Least privilege is usually discussed as a user and credential problem, but the article extends the logic to resources. Databases, servers, and cloud assets that are never accessed still expand the potential blast radius if a credential can reach them. That means governance has to cover both sides of the access equation: who can reach an asset and whether the asset should remain reachable at all. The reported 15% of resources unused over 90 days shows that access governance and asset rationalisation are now linked. Practical implication: retire or isolate dormant resources before they become unnecessary exposure.

Practical implication: retire or isolate dormant resources before they become unnecessary exposure.


Threat narrative

Attacker objective: The attacker wants to exploit dormant entitlement and over-provisioned access to reach sensitive systems with less resistance.

  1. Entry occurs through credentials that already have privilege but have gone unused long enough to evade routine scrutiny.
  2. Escalation follows when over-provisioned access grants broader reach than the identity actually needs, widening the set of sensitive systems exposed to misuse.
  3. Impact is realised when dormant credentials or resources remain available for theft, abuse, or opportunistic compromise, expanding the organisation's attack surface.
  • Azure Key Vault Contributor escalation 2024: Datadog found Azure Key Vault Contributor could add itself to access policies and read every secret, key and certificate in a vault.
  • BeyondTrust breach 2024: A stolen BeyondTrust Remote Support API key let a China state-sponsored actor reset accounts and reach US Treasury workstations in 2024.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Visibility debt is now an access-control problem, not just a reporting problem: least privilege cannot be enforced from entitlement records alone when teams cannot observe actual usage. That gap leaves organisations with policy on paper but no proof that access is still needed. The practitioner conclusion is that usage visibility has become part of the control, not merely evidence for the control.

Unused privilege is not benign privilege: the article shows that a large share of privileged access, user access, and resources remains untouched over 90 days. In identity governance terms, that means dormant access is still part of the attack surface until it is removed or revalidated. The practitioner conclusion is that absence of usage should be treated as a governance signal, not a comfort signal.

Least privilege has become a lifecycle issue across users, credentials, and assets: the strongest finding in the article is not the size of the excess but the persistence of it across multiple access layers. That persistence is what turns a provisioning decision into a lifecycle failure. The practitioner conclusion is that entitlement cleanup must be tied to ongoing use, not annual review.

Zero standing privilege depends on knowing what stands still: the article points toward zero standing privilege as the logical endpoint, but standing access cannot be eliminated if dormant privilege is invisible. This is where the control model breaks down in practice, because teams cannot remove what they cannot see. The practitioner conclusion is that standing access and standing observability have to be addressed together.

Unused resources are part of the identity blast radius: access governance often stops at who can log in, but unused databases, servers, and cloud resources still increase the blast radius of any compromised credential. That makes resource inventory and access usage inseparable governance concerns. The practitioner conclusion is that least privilege has to extend beyond identities to the assets they can reach.

From our research library:

What this signals

Usage visibility is becoming the real least privilege control: entitlement reviews cannot keep pace with modern access sprawl unless teams can see what is actually used. That is why dormant privilege, not just excess assignment, should drive removal workflows.

Access governance needs a measurement layer: in practice, least privilege fails when organisations cannot tell whether access is dead, temporarily idle, or genuinely required. The control becomes far more defensible once usage telemetry is part of entitlement decisions.

Unused resources widen the identity blast radius: databases, servers, and cloud resources that sit untouched still matter because credentials can often reach them. The operational signal is simple: if an asset has no recent use, it still needs an explicit governance decision.


For practitioners

  • Audit privileged access by last-use date Build review workflows around credentials and roles that have not been exercised in 90 days. Prioritise the accounts with elevated permissions first, because those are the most likely to remain dangerous while appearing dormant.
  • Separate granted access from actual usage Track which users and systems are granted access, then compare that to real authentication or query activity. Use the gap to drive deprovisioning, not just documentation updates.
  • Remove unnecessary privileged credentials Deprovision credentials that have no current business justification, especially where the same systems can be reached through a narrower role or a different workflow.
  • Rationalise unused resources Identify databases, servers, and cloud resources that have not been accessed in 90 days and decide whether they should be retired, isolated, or moved into a lower-risk state.

Key takeaways

  • The core problem is not whether least privilege is valid, but whether teams can prove which access is still needed.
  • The article cites large volumes of unused privileged access, unused user access, and unused resources, which indicates persistent governance drift.
  • Least privilege programmes need usage telemetry and deprovisioning discipline or they will keep carrying dormant risk.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0, CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIThe article focuses on excess access and unused privilege across credentials and resources.
NHI-07 — Long-Lived SecretsDormant privileged credentials remain exposed for long periods without active use.
Recommendation — Review and remove excess privileges from NHI accounts that no longer need broad access. Shorten credential lifespan and revoke long-idle NHI secrets before they become standing risk.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is fundamentally about entitlement governance and whether access matches need.
Recommendation — Continuously validate permissions against actual use and remove access that is no longer justified.
CIS Controls v8CIS-5 — Account ManagementUnused users and credentials point to account lifecycle control gaps.
Recommendation — Reconcile accounts regularly and disable access that has no recent business use.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeLeast privilege is the main control principle being challenged by the article's findings.
Recommendation — Limit each account to the minimum permissions needed and revalidate that scope from usage data.

Key terms

  • Least Privilege: A security principle requiring that every identity, human or non-human, is granted only the minimum permissions necessary to perform its function. Least privilege is the single most effective control for reducing NHI blast radius.
  • Standing Access: Standing access is persistent privilege that remains available without fresh approval or contextual checks. In NHI environments, standing access usually appears as long-lived tokens, reusable service accounts, or broad roles attached to automation. It is convenient operationally, but it expands risk when conditions change or secrets leak.
  • Access Visibility: Access visibility is the ability to see, in one place, which identities can reach which data, applications, and services. For IAM and data security teams, it is the difference between reviewing isolated permissions and understanding real blast radius across environments.
  • Over-provisioning: The condition where an identity has more access than it actually needs to do its work. In practice, this creates unnecessary blast radius, increases misuse potential, and makes access reviews look compliant even when the live environment is carrying excess privilege.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 8, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org