TL;DR: Most organisations still cannot tell how many service accounts they have, what those accounts do, or when one has been compromised, and the article argues that AI agents are now entering the environment as non-human identities with privileges and autonomous action, according to Netwrix. The security problem is no longer just hidden machine accounts, but a broader identity blind spot that spans legacy service accounts and agentic identities.
At a glance
What this is: This is an on-demand webinar about how service account blind spots and agentic identities are expanding the non-human identity risk surface.
Why it matters: It matters because IAM and security teams now have to govern both legacy service accounts and AI-driven non-human identities as one overlapping identity problem.
Context
Most service account programmes still begin with inventory, ownership, and credential lifecycle basics, but those controls are already strained when teams cannot answer how many accounts exist or what they are doing. That governance gap becomes more serious when AI systems enter the directory as non-human identities with privileges and the ability to act.
The article frames Microsoft Entra Agent IDs as evidence that agentic identities are becoming first-class identities inside enterprise directories. That changes the problem from hidden machine accounts alone to a broader identity estate where service accounts, tokens, and AI agents all require explicit governance rather than inherited trust.
Key questions
Q: What breaks when organisations cannot inventory tokens and service accounts in SaaS apps?
A: Containment breaks first, because responders cannot tell which identities are still valid, where they are used, or which integrations inherit their access. Detection also weakens because malicious activity blends into normal automation. Without ownership and inventory, legitimate access becomes hidden persistence.
Q: How should teams govern non-human identities in AI-heavy environments?
A: Teams should govern non-human identities the same way they govern other privileged assets: assign ownership, minimise scope, rotate credentials regularly, and monitor for abnormal use. The key difference is speed. AI-driven workflows can exploit exposed access quickly, so detection and revocation must be automated and tied to lifecycle controls.
Q: What are the signs that non-human identity governance is starting to slip?
A: Warning signs include reliance on manual upgrade paths, ad hoc secret handling, and fragmented access management across tools and environments. The article mentions caveats, dispatch limits, SSO support, and automated update channels, all of which point to the need for controlled operational discipline. When teams cannot explain how identities are provisioned, updated, and constrained, governance is already weaker than it should be.
Q: Why do service accounts and AI agents need different controls from human users?
A: Service accounts and AI agents authenticate and act without the predictable patterns that human identity systems expect. They can operate across runtimes, scale quickly, and carry permissions into automated workflows. That means access decisions should consider workload context, runtime behaviour, and time-bound authority rather than relying only on user-centric IAM patterns.
Background and context
Why service account inventory fails before security even starts
Service account security breaks down when organisations do not know what exists, who owns it, or which systems depend on it. That leaves access reviews, offboarding, and privilege scoping operating on partial data. In practice, unmanaged service accounts become durable trust anchors because no one can verify whether they still support a live workload or an abandoned integration.
Practical implication: build authoritative inventory and ownership records before attempting privilege rationalisation or review cycles.
How agentic identities change the non-human identity model
An agentic identity is not just another workload account. The article describes AI agents as non-human identities with privileges, access, and autonomous action, which means they can initiate behaviour rather than only respond to pre-scripted requests. That matters because directory objects that behave like first-class identities create new questions about authorisation scope, lifecycle control, and separation between human intent and machine execution.
Practical implication: classify AI agents explicitly as governed identities, not as generic application users or automation artifacts.
Why directory formalisation increases both visibility and exposure
When a platform formalises AI agents as identities in the directory, it improves recognisability but also enlarges the identity attack surface. Security teams gain a place to attach policy, yet they also create more objects that can be over-privileged, unowned, or left active beyond their intended use. The governance challenge is not the directory object itself, but whether lifecycle and privilege controls are strong enough to match its autonomy.
Practical implication: attach lifecycle, ownership, and access-scoping controls to agent IDs at creation time, not after deployment.
NHI Mgmt Group analysis
Service account invisibility is now a governance failure, not just an inventory problem: If an organisation cannot say how many service accounts it has or what they do, it cannot govern privilege, ownership, or offboarding with confidence. That blind spot has always weakened NHI control, but it becomes more dangerous as more business processes depend on machine identities. The practitioner conclusion is simple: identity governance for NHIs begins with knowing what exists.
Agentic identities collapse the old assumption that non-human identities only execute fixed workflows: The article describes AI agents as non-human identities with privileges and the ability to act autonomously. That means the security model must account for runtime action, not just credential possession. The implication is that access governance can no longer assume deterministic use of an identity at provisioning time.
Identity blast radius: When service accounts and AI agents coexist in the same directory, privilege sprawl becomes cumulative rather than isolated. A poorly governed service account and a newly formalised agent ID both widen the same attack surface, even if they arise from different operational teams. The practitioner conclusion is that identity risk now has to be measured across the full non-human estate, not by account type in isolation.
NHI governance must treat directory formalisation as an accountability event: Putting agent IDs into the directory improves manageability only if ownership, purpose, and expiry are attached to every identity at the moment it is created. Otherwise the directory simply scales the problem faster. The implication is that lifecycle governance has to be built into the identity object, not layered on as a later review exercise.
From our research library:
- Only 5.7% of organisations have full visibility into their service accounts, according to the Ultimate Guide to NHIs.
- 59% of organisations say they lack viable alternatives to standing privileged access for NHIs and AI agents, according to Delinea research.
- Read next: Service Account Security Guide
What this signals
Service account blindness is now the baseline risk signal: When organisations cannot enumerate or explain their service accounts, every downstream control becomes weaker because access review depends on a trustworthy inventory. That is why the first governance task is not remediation but visibility.
Identity directories are becoming the control point for agentic access: Formalising AI agents as directory identities creates a place to govern them, but it also makes the directory part of the attack surface. Security teams should expect the same lifecycle discipline they apply to other non-human identities, with stronger ownership and expiry rules.
The governance problem is no longer limited to one identity class. Service accounts, tokens, and agent IDs now share the same blast radius, so programme teams need one operating model for ownership, privilege scope, and retirement.
For practitioners
- Establish a full service account inventory Map every service account to an owner, purpose, dependency, and last-known use so hidden identities can be reviewed and retired safely.
- Classify AI agents as governed identities Create a distinct process for agent IDs that records purpose, authority, and operational owner instead of treating them as generic application accounts.
- Apply lifecycle expiry to non-human identities Set review and expiry rules for service accounts, tokens, and agent identities so unused access does not persist indefinitely.
- Scope privileges to observed use cases Limit each non-human identity to the minimum actions required by its workload and remove inherited access that is not directly justified.
- Track directory-created exposure growth Monitor how each newly formalised identity changes the size of the attack surface, especially when agent IDs are added to existing directory structures.
Key takeaways
- The central problem is a non-human identity blind spot that combines legacy service account opacity with the rise of agentic identities.
- The article says most organisations still cannot account for their service accounts, which means inventory and ownership remain weak.
- The control that matters most is lifecycle governance across all non-human identities, including new AI agent identities formalised in the directory.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-53 Rev 5 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | The article centres on hidden service accounts and agent IDs that outlive their governance. |
| NHI-05 — Overprivileged NHI | The webinar warns that AI agents and service accounts carry privileges that may exceed their real need. | |
| NHI-10 — Human Use of NHI | The article implies humans must deliberately govern agent IDs instead of treating them as generic automation. | |
| Recommendation — Map each non-human identity to an owner and retirement path before it becomes an orphaned access path. Review NHI privileges against actual workload requirements and remove inherited access that is not justified. Separate human-run workflows from non-human identity authority and require explicit ownership for each identity. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Service accounts and agent identities rely on credentials that need lifecycle control and rotation governance. |
| Recommendation — Enforce authenticator lifecycle controls so service account and agent credentials are issued, reviewed, and retired on schedule. | ||
| MITRE ATT&CK | TA0006;TA0008 — Credential Access; Lateral Movement | Hidden service accounts can enable credential access and move laterally once compromised. |
| Recommendation — Map service account exposure to credential-access and lateral-movement tactics in detection and response planning. | ||
Key terms
- Service Account Blind Spot: A service account blind spot is the inability to reliably identify, attribute, and monitor machine accounts across the environment. In practice, it means governance decisions are made with incomplete inventory, unclear ownership, and limited evidence of what each account can still access.
- Agentic Identity: An agentic identity is a non-human identity used by an autonomous system that can act, call tools, and access data with execution authority. It needs the same governance discipline as other privileged identities, plus runtime context, ownership mapping, and revocation paths.
- Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
- Directory Formalisation: Directory formalisation is the act of representing a machine or AI actor as a first-class identity object in an enterprise directory. It improves policy attachment and visibility, but it only reduces risk when ownership, purpose, expiry, and privilege scope are defined at creation time.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM or identity security programme, it is worth exploring.
Published by the NHIMG editorial team on June 23, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org