Join our Newsletter — 33% off our NHI Course

AI agent identities in IAM: are your controls keeping up?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20651
Topic starter  

TL;DR: AI agents are already accumulating permissions, roles, and group memberships inside Microsoft environments, but governance often treats them as isolated technical objects rather than accountable identities, according to Nexis. The real risk is cross-identity SoD failure, where human and agent access combine into conflicts that separate reviews never expose.

NHIMG editorial — based on content published by Nexis: IAM Your AI Agents Already Have Access. Is Your Governance Keeping Up?

Questions worth separating out

Q: What breaks when AI agents are reviewed like human users?

A: Human review assumes access is stable long enough to be observed, approved, and recertified.

Q: Why do AI agents create compliance risk even when policies exist on paper?

A: Policies do not satisfy auditors if the organisation cannot prove enforcement.

Q: How should teams govern AI agents that act inside customer accounts?

A: Treat them as delegated non-human identities, not as ordinary customer sessions.

Practitioner guidance

  • Inventory all AI agents in the tenant Build a dated register of every agent, its origin, its reachable applications, and the business process it supports.
  • Review combined human-plus-agent access Run segregation of duties checks across the employee and the agent they operate, not as separate populations.
  • Assign accountable ownership before expansion Require a named business and technical owner for every agent before permissions can be extended or retained.

What's in the full article

Nexis' full article covers the operational detail this post intentionally leaves for the source:

  • The exact four-step health check workflow for scoping, data import, analysis, and findings presentation.
  • The tenant-focused inventory method Nexis uses to identify agents, ownership gaps, and access concentration.
  • The benchmark comparison approach used to position results against anonymized peer data.
  • The practical distinctions between visible tenant agents and agent-like identities using service accounts or stored credentials.

👉 Read Nexis' article on governing AI agents already in your Microsoft tenant →

AI agent identities in IAM: are your controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 20242
 

AI agent governance is an identity problem before it is an AI problem. The article is right to treat agents as access-bearing entities with ownership, permissions, and accountability. Once an agent can enter group memberships or application roles, the governance question becomes familiar IAM, not novelty management. Practitioners should place AI agents inside the same identity governance framework they already use for privileged business access.

A few things that frame the scale:

  • 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems (39%), inappropriately sharing sensitive data (31%), and revealing access credentials (23%), according to AI Agents: The New Attack Surface report.
  • 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation.

A question worth separating out:

Q: What is the difference between agent inventory and agent governance?

A: Inventory tells you which agents exist and what they can reach. Governance adds ownership, accountability, access review, and segregation of duties so that the organisation can decide whether the access is appropriate and who can be held responsible for it.

👉 Read our full editorial: AI agent governance is lagging behind enterprise access sprawl



   
ReplyQuote
Share: