TL;DR: A healthcare provider with more than 100,000 non-human identities, 50,000 certificates, 10,000 service accounts, and 133 unused service principals found in Azure showed how quickly hybrid environments outgrow manual NHI governance, according to Oasis Security. The lesson is that visibility, ownership, and rotation are now baseline identity controls, not optional clean-up work.
Editorial analysis by NHI Mgmt Group, based on content published by Oasis Security: “How a Healthcare provider gained comprehensive NHI visibility with Oasis”.
Key questions
Q: What breaks when manual governance is used for large NHI estates?
A: Manual governance breaks when the identity inventory is too large and fragmented for people to track consistently.
Q: Why do unowned service accounts create more security risk?
A: Unowned service accounts create more risk because no one is responsible for reviewing their permissions, rotating their credentials, or removing them when they are no longer needed.
Q: How do security teams know if NHI visibility is actually working?
A: Visibility is working only when discovery leads to ownership, review, and action.
Practitioner guidance
- Build a single NHI inventory Map certificates, service accounts, service principals, and API keys into one governed inventory so ownership and status are visible across cloud and on-premises systems.
- Tie every NHI to an accountable owner Require named ownership for each machine identity before it can be rotated, approved, or decommissioned, especially where on-prem and hybrid dependencies exist.
- Automate rotation for privileged secrets Move privileged secrets onto a repeatable rotation workflow with approval paths, dependency checks, and exception handling for workloads that cannot tolerate blind changes.
Bottom line: The case shows that large machine identity estates quickly outgrow manual governance when visibility is fragmented across cloud and on-premises systems.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Manual governance breaks once the NHI estate becomes larger than the team operating it. A security team of 18 and an operations team of around 50 cannot reliably govern more than 100,000 NHIs with spreadsheets, periodic checks, and ad hoc remediation. The issue is not effort but scale mismatch. The practitioner conclusion is that NHI governance must become inventory-driven and lifecycle-aware before risk analysis can be trusted.
A few things that frame the scale:
- Only 5.7% of organisations have full visibility into their service accounts, according to the Ultimate Guide to NHIs.
- NHIs outnumber human identities by 25x to 50x in modern enterprises, according to the Ultimate Guide to NHIs.
A question worth separating out:
Q: Should organisations prioritise NHI rotation or decommissioning first?
A: Prioritise decommissioning first when identities are clearly dormant or no longer needed, because removing unnecessary access reduces exposure immediately. Prioritise rotation first when the identity is still active but the secret is old, privileged, or poorly controlled. The right order depends on whether the bigger issue is unnecessary existence or unsafe persistence.
👉 Read our full editorial: Healthcare NHI visibility shows why manual governance breaks at scale