Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Identity dark matter: what IAM teams miss outside SSO and vaults


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 13010
Topic starter  

TL;DR: Up to 80% of enterprise applications sit outside traditional SSO and remain largely invisible to security teams, according to Unixi, while password managers do little to enforce policy, prevent phishing, or offboard users cleanly. The deeper issue is identity sprawl beyond governed control, not simply weak user behaviour.

NHIMG editorial — based on content published by Unixi: Identity Dark Matter: The Security Risk Hidden Beneath SSO and Password Managers

By the numbers:

Questions worth separating out

Q: What breaks when organisations rely on SSO and password managers as their main identity controls?

A: The control model breaks when major parts of the application estate sit outside federation and the vault only stores secrets instead of enforcing policy.

Q: Why do unmanaged identities increase IAM risk even when SSO and MFA are deployed?

A: Because SSO and MFA only cover interactive human authentication, not the full set of service accounts, secrets, and delegated machine credentials that operate outside login flows.

Q: How do security teams know whether a password vault is actually reducing risk?

A: They should look for three signals: whether the vault is tied to application-level revocation, whether it supports audit evidence for access reviews, and whether users still possess alternate ways to authenticate.

Practitioner guidance

  • Map the unmanaged access estate Build an application and credential inventory that includes non-SAML portals, shared utility accounts, shadow SaaS, and AI tools used outside IT oversight.
  • Separate storage from enforcement Do not count a password manager as a control unless it is paired with application-level revocation, audit logging, and policy enforcement.
  • Extend lifecycle reviews to shared and delegated accounts Include service accounts, shared logins, and utility credentials in access reviews, ownership assignment, and offboarding workflows.

What's in the full article

Unixi's full blog post covers the operational detail this post intentionally leaves for the source:

  • The article's full comparison of password vault behaviour versus application-level access control for non-SAML apps
  • The specific examples of residual access, offboarding gaps, and shared account misuse that support the argument
  • The vendor's architecture claims around Universal SSO and decentralized key handling, which this analysis does not evaluate
  • The forensic-audit positioning for identifying unmanaged apps, missing MFA, and shadow SaaS profiles

👉 Read Unixi's analysis of identity dark matter, password managers, and unmanaged access →

Identity dark matter: what IAM teams miss outside SSO and vaults?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 12594
 

Identity dark matter is a governance failure, not a tooling gap: the real problem is that many enterprise access paths never enter the control plane at all. SSO, vaults, and recertification only work on the identities they can see. Once the application estate extends beyond those boundaries, the programme has no reliable basis for enforcement, evidence, or offboarding.

A few things that frame the scale:

  • 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, according to The State of Non-Human Identity Security.
  • Our research also found that only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, which shows how narrow the confidence gap really is.

A question worth separating out:

Q: Who is accountable when a shadow SaaS app creates access and cost risk?

A: Accountability should rest with the business owner who introduced the tool, the technical owner who governs access, and the platform or procurement team that approved spend. If those roles are not defined, the organisation cannot close the loop on offboarding, revocation, or renewal, which is how shadow IT becomes persistent.

👉 Read our full editorial: Identity dark matter shows why SSO and vaults miss core access risk



   
ReplyQuote
Share: