Join our Newsletter — 33% off our NHI Course

Keyless privileged access: what it changes for IAM teams

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: Passwords, SSH keys, API keys, and other static privileged credentials remain easy to reuse, share, and expose, which keeps escalation paths open even when rotation policies exist, according to SSH Communications Security. The real shift is away from maintaining secrets that should not persist at all, toward temporary, policy-driven access that removes standing privilege rather than preserving it.

Editorial analysis by NHI Mgmt Group, based on content published by SSH Communications Security: “How to break up with your password”.

Key questions

Q: What breaks when privileged access is managed with static keys instead of just-in-time access?

A: Static keys create standing access that is harder to govern, rotate, and revoke, especially in fast-moving production systems.

Q: Why do certificates create risk in cloud and automation environments?

A: Certificates create risk when they outlive the workloads, pipelines, or data paths they were meant to protect.

Q: How do teams know whether keyless privileged access is actually reducing risk?

A: They should look for a smaller population of persistent privileged credentials, fewer credentials embedded in automation, and more access granted only at request time.

Practitioner guidance

  • Reduce standing privileged credentials Inventory passwords, SSH keys, API keys, and other reusable authenticators that still grant elevated access.
  • Shift privileged access to policy-based issuance Require identity, context, and target-specific policy checks before granting elevated access, and make the session ephemeral so no reusable secret remains afterward.
  • Map credential sprawl across automation paths Trace where secrets are embedded in scripts, CI/CD pipelines, containers, and shared admin tooling, because those are the paths where long-lived access tends to persist unnoticed.

Bottom line: Static privileged credentials remain an access-governance problem even when organisations invest in rotation and vaulting.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 1 day ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Standing privileged credentials are the wrong primitive for modern access governance: passwords and static keys were built to persist, while modern privileged tasks are often ephemeral. That mismatch creates governance debt, because teams keep managing secrets that should have been eliminated from the path entirely. The practitioner conclusion is to treat standing privilege as the real issue, not just credential hygiene.

A few things that frame the scale:

  • 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface, according to the Ultimate Guide to NHIs.

A question worth separating out:

Q: Should organisations replace secret rotation with ephemeral privileged access?

A: Rotation still has value, but it should not be the main control if the organisation is still distributing static credentials. The better test is whether privileged access can be issued without leaving a reusable secret behind. If not, rotation is compensating for a design problem rather than solving it.

👉 Read our full editorial: Keyless privileged access is becoming the safer PAM model


This post was modified 1 day ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.