Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Invisible identities: what it means for IAM teams now


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15509
Topic starter  

TL;DR: Credential abuse remains the most common initial access vector, while orphaned and local accounts persist as hidden entry points because they sit outside central governance, according to Orchid Security’s analysis and Verizon’s 2025 DBIR. Identity programmes that only cover managed accounts will miss the identities attackers use first and most often.

NHIMG editorial — based on content published by Orchid Security: Invisible Threat: Orphan and Local Accounts

By the numbers:

Questions worth separating out

Q: How should security teams discover orphaned and local accounts across the application estate?

A: Start with continuous discovery, not periodic cleanup.

Q: Why do service accounts increase lateral movement risk in enterprise environments?

A: Service accounts often connect multiple systems, so they sit at the center of trust relationships that humans never see directly.

Q: What do security teams get wrong about identity threat detection and response?

A: They often treat ITDR as a substitute for IAM, when it is actually complementary.

Practitioner guidance

  • Extend discovery to unmanaged identity stores Inventory credentials embedded in applications, scripts, databases, and legacy systems so orphaned and local accounts are visible alongside directory-managed identities.
  • Bind every account to an accountable owner Require a named business or technical owner for each service, local, or orphaned account, and block renewal when ownership cannot be proven.
  • Eliminate cleartext and hardcoded credentials Search source code, configuration files, and CI/CD pipelines for stored credentials, then replace them with managed secrets and controlled access paths.

What's in the full report

Orchid Security's full whitepaper covers the operational detail this post intentionally leaves for the source:

  • The full account classification checklist for orphaned, local, and unmanaged identities across legacy and cloud systems.
  • The remediation workflow for hardcoded credentials, including where to look in code, configuration files, and CI/CD tooling.
  • The application-level control gaps behind cleartext storage, bypassed identity providers, and incomplete access enforcement.
  • The incident examples and research tables that show how hidden identities translate into breach and ransomware exposure.

👉 Read Orchid Security's whitepaper on orphaned and local account risk →

Invisible identities: what it means for IAM teams now?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 15094
 

Invisible identities are not an edge case. They are the identity model’s missing population. The article shows that orphaned and local accounts can exist outside central governance while still carrying access, persistence, and operational value. That means conventional IAM reporting can look healthy even as the real attack surface expands underneath it. Practitioners need to treat unmanaged accounts as a first-class identity domain, not an exception to the model.

A few things that frame the scale:

  • 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage, according to Ultimate Guide to NHIs.
  • Only 5.7% of organisations have full visibility into their service accounts, which shows how narrow the managed identity view still is.

A question worth separating out:

Q: Who is accountable when dormant access or orphaned accounts remain active?

A: Accountability should sit with the business owner of the identity, the system owner that issues access, and the governance team that monitors recertification and offboarding. If those roles are not explicit, access drift becomes everyone’s problem and no one’s responsibility. Clear ownership is the difference between governance and paperwork.

👉 Read our full editorial: Orphaned and local accounts expose the real identity blind spot



   
ReplyQuote
Share: