TL;DR: Opal Security argues that Palo Alto Networks’ $25B CyberArk acquisition reflects a market shift from login and vault control toward runtime authorization, especially as AI agents and machine identities expand the attack surface. Static roles, ticketed approvals, and periodic reviews are losing relevance where access is ephemeral and continuously changing.
At a glance
What this is: This is Opal Security’s analysis of Palo Alto Networks’ CyberArk acquisition and its central claim that authorization, not authentication, is now the identity battleground.
Why it matters: It matters because IAM, PAM, and NHI teams have to govern dynamic access decisions across humans, workloads, and agents instead of relying on static roles and periodic review cycles.
👉 Read Opal Security’s analysis of the Palo Alto Networks and CyberArk deal
Context
Palo Alto Networks’ planned $25B acquisition of CyberArk is a market-consolidation story, but the underlying governance issue is narrower and more practical: who decides what an identity can do after access is granted. That is an authorization problem, not an authentication problem, and it becomes harder as access grows more dynamic across cloud, SaaS, pipelines, and AI-driven workflows.
For IAM and PAM teams, the article’s key point is that authorization has become the control plane for both human and non-human access. Static roles, ticket-based approvals, and periodic reviews were built for slower access patterns, while modern environments now depend on ephemeral permissions, runtime context, and machine identities that request access continuously.
Key questions
Technical breakdown
Why static roles fail when access is dynamic
Static roles assume permissions can be assigned once and remain valid long enough for periodic review. That model breaks when access is short-lived, context-dependent, and generated at runtime by workloads, automation, or agents. In those environments, the actual risk is not just who has access, but what they can do in the moment and whether the decision reflects current context. Authorization has to move closer to execution time because standing policy snapshots cannot keep pace with changing identity state, environment posture, or business task.
Practical implication: shift critical access decisions from pre-granted entitlements to real-time authorization checks tied to current context.
How identity drift expands blast radius
Identity drift is the accumulation of unused, overbroad, or poorly understood entitlements across human and non-human identities. It grows quietly because access is often added for convenience, inherited through groups, or never removed after a workflow changes. Over time, the problem is not just excess access but incomplete visibility into why permissions exist, who owns them, and whether they still match the workload or user task. That is why drift increases blast radius even when authentication controls are strong.
Practical implication: continuously reconcile entitlement ownership and usage so stale access does not compound into hidden privilege.
Why machine identities expose legacy PAM assumptions
Machine identities do not behave like employees with stable job roles and predictable sessions. They call APIs, spin up containers, exchange tokens, and request ephemeral access as part of an execution chain. Legacy PAM models were designed around durable privileged sessions, human approval points, and discrete administrative workflows. When the subject is a service account, container, or agent, those assumptions become too slow and too coarse to govern actual access behaviour. The result is a control gap between policy intent and runtime action.
Practical implication: extend governance to machine identities at the moment access is requested, not only after a session begins.
Threat narrative
Attacker objective: The objective is to turn hidden entitlement sprawl into broad control over systems, data, or administrative workflows.
- Entry occurs when excess privilege, nested group membership, or stale machine access gives an identity more reach than its current task requires.
- Escalation follows when an attacker or rogue workflow uses standing access to move from ordinary permissions into higher-value actions without needing a new login.
- Impact emerges when overbroad authorization lets the actor modify data, pivot into adjacent systems, or widen the blast radius across cloud and SaaS estates.
Breaches seen in the wild
- Azure Key Vault Contributor escalation 2024: Datadog found Azure Key Vault Contributor could add itself to access policies and read every secret, key and certificate in a vault.
- BeyondTrust breach 2024: A stolen BeyondTrust Remote Support API key let a China state-sponsored actor reset accounts and reach US Treasury workstations in 2024.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Authorization, not authentication, is now the governance battleground. Login controls have matured faster than the controls that decide what an identity can do after access is granted. That gap matters because modern environments distribute privilege across humans, workloads, and agents, each with different timing and context requirements. Practitioners should treat authorization as the primary control plane for identity security, not a downstream policy layer.
Identity drift is the hidden failure mode behind platform sprawl. The article correctly points to sprawl in entitlements, machine accounts, and policies as the condition that widens blast radius. The governance problem is not only excess access, but the absence of durable ownership and lifecycle visibility across changing systems. This is where entitlement review alone is insufficient, because review without runtime context arrives after the risk has already been exercised.
Machine identities force PAM to confront its own assumptions. PAM was built around human administrators, durable sessions, and coarse-grained elevation events. That assumption weakens when the actor is a service account, container, or agent that requests access repeatedly and briefly in the course of execution. The field now needs controls that govern entity behaviour at runtime, not just privileged credentials at issuance.
Runtime-native authorization is becoming the decisive control pattern. The article’s strongest contribution is its emphasis on context, timing, and entity-agnostic policy rather than static entitlements. That aligns with how AI workflows and ephemeral infrastructure actually operate. The practical implication is that identity governance must move from periodic certification to continuous decisioning over who or what is allowed to act right now.
Platform consolidation will not remove governance complexity. Folding more identity and security functions into one stack may simplify procurement, but it does not simplify authorization semantics. If anything, it increases the need to distinguish identity proofing, privileged access, and runtime decisioning as separate control problems. Practitioners should judge consolidation by governance clarity, not by the size of the bundle.
From our research library:
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface, according to the Ultimate Guide to NHIs.
- Read next: Just-in-Time Access and Zero Standing Privilege Guide
What this signals
Authorization-first governance will matter more as access becomes ephemeral. The operational question is no longer how many identities exist, but whether the organisation can make and revoke access decisions at the moment of action. That means entitlement review, PAM, and workload governance need to be evaluated together instead of as separate control programmes.
Machine identities are now part of the governance surface, not an adjacent technical issue. Once service accounts, containers, and agents can request access continuously, the old human-centric access model becomes a partial view. Teams should expect their control framework to distinguish between identity proofing, privilege assignment, and runtime decisioning.
Identity drift will remain the practical early warning signal. Excess privilege, stale ownership, and dormant accounts are the clearest indicators that access governance is not keeping pace with operational reality. A control set that cannot explain why access exists today will not reliably contain tomorrow’s blast radius.
For practitioners
- Map authorization decisions to runtime context Review where access is still granted through static roles, ticket approvals, or durable sessions and identify the systems that need context-aware decisions at execution time.
- Inventory machine identities separately from human accounts Create a distinct inventory for service accounts, containers, API-driven workflows, and agents so ownership, purpose, and access scope are visible outside the human IAM model.
- Reduce standing privilege in privileged workflows Replace persistent administrative access with just-in-time elevation and short-lived permissions for tasks that do not require continuous privilege.
- Reconcile entitlement ownership with actual usage Tie each privileged entitlement to a named owner and an observed business or technical purpose, then retire access that no longer matches live usage patterns.
- Evaluate whether consolidation changes control boundaries If your identity stack is becoming more platform-consolidated, test whether authorization, PAM, and machine identity governance still remain independently enforceable.
Key takeaways
- Authorization has become the main identity control problem because modern access is dynamic, contextual, and increasingly machine-driven.
- Identity drift widens blast radius when entitlement ownership and runtime use are not continuously reconciled.
- Practitioners need runtime decisioning, machine-identity governance, and reduced standing privilege to keep pace with current access patterns.
Key terms
- Authority Drift: Authority drift occurs when different systems hold conflicting versions of identity data and no clear owner resolves the mismatch. It is a governance failure that leads to duplicate work, stale entitlements, and access decisions based on partial or inconsistent records.
- Identity Drift: Identity drift is the gap between the access path originally approved and the behavior that exists later. For browser extensions, drift can appear through updates, remote configuration, publisher changes, or permission expansion, turning a trusted integration into a materially different risk.
- Runtime Authorisation: Runtime authorisation is the practice of deciding access while a task is in progress, rather than only at provisioning time. It matters for NHIs because credentials and entitlements can change risk mid-session, especially when automation or AI agents interact with sensitive systems.
- Machine Identity: The digital identity of a machine, device, or workload, such as a server, container, or VM, used to authenticate it within a network. Sometimes used interchangeably with NHI, though NHI is the broader category.
What's in the full analysis
Opal Security's full analysis covers the operational detail this post intentionally leaves for the source:
- How the vendor frames runtime authorization across humans, machines, and AI agents
- The specific cases it cites to illustrate identity drift, standing privilege, and authorization gaps
- Details on its policy-as-code, xBAC, and just-in-time access model
- The acquisition and platformization arguments behind the broader market interpretation
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 23, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org