<?xml version="1.0" encoding="UTF-8"?>        <rss version="2.0"
             xmlns:atom="http://www.w3.org/2005/Atom"
             xmlns:dc="http://purl.org/dc/elements/1.1/"
             xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
             xmlns:admin="http://webns.net/mvcb/"
             xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
             xmlns:content="http://purl.org/rss/1.0/modules/content/">
        <channel>
            <title>
									NHIMG Forum - Recent Topics				            </title>
            <link>https://nhimg.org/community/</link>
            <description>NHIMG Discussion Board</description>
            <language>en-US</language>
            <lastBuildDate>Tue, 09 Jun 2026 00:56:36 +0000</lastBuildDate>
            <generator>wpForo</generator>
            <ttl>60</ttl>
							                    <item>
                        <title>AI agent credentials and NHI sprawl: what IAM teams need now</title>
                        <link>https://nhimg.org/community/agentic-ai-and-nhis/ai-agent-credentials-and-nhi-sprawl-what-iam-teams-need-now/</link>
                        <pubDate>Mon, 08 Jun 2026 17:09:49 +0000</pubDate>
                        <description><![CDATA[TL;DR: AI agents are turning single-purpose non-human identities into multi-identity access chains that expand permissions, blur ownership, and raise the risk of living-off-the-land abuse, a...]]></description>
                        <content:encoded><![CDATA[<blockquote>
<p><strong>TL;DR:</strong> AI agents are turning single-purpose non-human identities into multi-identity access chains that expand permissions, blur ownership, and raise the risk of living-off-the-land abuse, according to Astrix Security's analysis. The governance problem is no longer just credential hygiene, but proving which actor owns which access path when AI behavior becomes nondeterministic.</p>
</blockquote>
<p><em>NHIMG editorial — based on content published by Astrix Security: AI agent identity risk and the rise of multi-NHI access</em></p>
<p><strong>By the numbers:</strong></p>
<ul>
<li><a href="https://astrix.security/learn/blog/astrix-research-presents-touchpoints-between-ai-and-non-human-identities/?utm_source=nhimg&amp;utm_medium=NHIForum">1:100.</a>, ption could drastically increase this ratio, potentially reaching 1:100.</li>
<li>Organizations currently exhibit a <a href="https://astrix.security/learn/blog/astrix-research-presents-touchpoints-between-ai-and-non-human-identities/?utm_source=nhimg&amp;utm_medium=NHIForum">1:40 human-to-NHI ratio</a>.</li>
</ul>
<h2>Questions worth separating out</h2>
<p><strong>Q: <a href="https://nhimg.org/faq/how-should-security-teams-govern-ai-agents-and-non-human-identities-in-iga/?utm_source=nhimg&amp;utm_medium=NHIForum">How should security teams govern AI agents that rely on multiple non-human identities?</a></strong></p>
<p><strong>A:</strong> Treat the agent and its linked identities as one access graph.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/why-do-ai-agents-increase-non-human-identity-risk/?utm_source=nhimg&amp;utm_medium=NHIForum">Why do AI agents increase non-human identity risk in enterprises?</a></strong></p>
<p><strong>A:</strong> AI agents increase risk because they often need broader cross-system access than a single workload or script, and they can accumulate several identities to do that work.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/what-breaks-when-ai-associated-nhis-are-treated-like-ordinary-automation/?utm_source=nhimg&amp;utm_medium=NHIForum">What breaks when AI-associated NHIs are treated like ordinary automation?</a></strong></p>
<p><strong>A:</strong> Visibility and accountability break first.</p>
<h2>Practitioner guidance</h2>
<ul>
<li><strong>Inventory every identity attached to each AI agent</strong> Map each agent to its OAuth apps, API keys, service accounts, session tokens, and webhooks so the <a href="https://nhimg.org/the-ultimate-guide-to-non-human-identities?utm_source=nhimg&amp;utm_medium=NHIForum">full access chain</a> is visible in one record.</li>
<li><strong>Separate administrative access from routine agent access</strong> Classify any agent that can write, administer, or cross systems as <a href="https://nhimg.org/the-ultimate-guide-to-non-human-identities?utm_source=nhimg&amp;utm_medium=NHIForum">high-risk and subject</a> it to stronger approvals, logging, and review than ordinary automation.</li>
<li><strong>Tie agent creation to explicit ownership and offboarding</strong> Require a named owner, <a href="https://nhimg.org/complete-guide-to-the-2026-owasp-top-10-risks-for-agentic-applications?utm_source=nhimg&amp;utm_medium=NHIForum">expected usage timeframe</a>, and decommission trigger for every AI-related NHI so the identity can be revoked when the task ends.</li>
</ul>
<h2>What's in the full article</h2>
<p>Astrix Security's full article covers the operational detail this post intentionally leaves for the source:</p>
<ul>
<li>Category-by-category breakdown of AI systems and the specific NHIs they use across chatbots, RAG, cloud models, and browser agents</li>
<li>Operational examples of provisioning, visibility, and posture controls for AI-linked NHIs in enterprise environments</li>
<li>The article's discussion of living-off-the-land attack paths and why they are difficult to distinguish from normal agent behaviour</li>
<li>Practical recommendations for baselining, monitoring, and automated response around AI-associated identities</li>
</ul>
<p>&#x1f449; <strong><a href="https://astrix.security/learn/blog/astrix-research-presents-touchpoints-between-ai-and-non-human-identities/?utm_source=nhimg&amp;utm_medium=NHIForum">Read Astrix Security's analysis of AI agent identity risk and NHI sprawl →</a></strong></p>
<p><em>AI agent credentials and NHI sprawl: what IAM teams need now?</em></p>
<blockquote>
<p><strong>Explore further</strong></p>
<p><a href="/community/?utm_source=nhimg&amp;utm_medium=NHIForum">View Full Forum →</a>  |  <a href="/nhi-training/?utm_source=nhimg&amp;utm_medium=NHIForum">NHI Foundation Course →</a>  |  <a href="/services/?utm_source=nhimg&amp;utm_medium=NHIForum">Our Services →</a></p>
</blockquote>]]></content:encoded>
						                            <category domain="https://nhimg.org/community/"></category>                        <dc:creator>Astrix Security</dc:creator>
                        <guid isPermaLink="true">https://nhimg.org/community/agentic-ai-and-nhis/ai-agent-credentials-and-nhi-sprawl-what-iam-teams-need-now/</guid>
                    </item>
				                    <item>
                        <title>AI agent identity and accountability: what changes for IAM teams?</title>
                        <link>https://nhimg.org/community/agentic-ai-and-nhis/ai-agent-identity-and-accountability-what-changes-for-iam-teams/</link>
                        <pubDate>Mon, 08 Jun 2026 17:09:38 +0000</pubDate>
                        <description><![CDATA[TL;DR: AI agents now make decisions, execute tasks, and adapt in runtime, which means identity controls must track delegation, auditability, and scope as first-class requirements, according ...]]></description>
                        <content:encoded><![CDATA[<blockquote>
<p><strong>TL;DR:</strong> AI agents now make decisions, execute tasks, and adapt in runtime, which means identity controls must track delegation, auditability, and scope as first-class requirements, according to Strata Identity. The old assumption that access can be reviewed after the fact breaks when agents act and re-act within a session, leaving accountability gaps that human-centric IAM cannot close.</p>
</blockquote>
<p><em>NHIMG editorial — based on content published by Strata Identity: AI agent identity and accountability in the enterprise identity model</em></p>
<p><strong>By the numbers:</strong></p>
<ul>
<li>With <a href="https://www.strata.io/blog/agentic-identity/why-agentic-identities-matter-1b/?utm_source=nhimg&amp;utm_medium=NHIForum">80x more agents than human users</a> in coming years, identity for agents is not optional.</li>
<li><a href="https://www.strata.io/blog/agentic-identity/why-agentic-identities-matter-1b/?utm_source=nhimg&amp;utm_medium=NHIForum">80% of organisations report</a> their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems, inappropriately sharing sensitive data, and revealing access credentials.</li>
</ul>
<h2>Questions worth separating out</h2>
<p><strong>Q: <a href="https://nhimg.org/faq/how-should-security-teams-govern-ai-agents-that-can-access-enterprise-systems/?utm_source=nhimg&amp;utm_medium=NHIForum">How should security teams govern AI agents that act on behalf of users?</a></strong></p>
<p><strong>A:</strong> Security teams should govern AI agents as delegated identities, not as ordinary service accounts.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/why-do-ai-agents-create-a-governance-problem-for-iam-teams/?utm_source=nhimg&amp;utm_medium=NHIForum">Why do AI agents create accountability problems for IAM programmes?</a></strong></p>
<p><strong>A:</strong> AI agents create accountability problems because they can make runtime decisions, chain actions, and adapt scope without a human pause point.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/what-breaks-when-organisations-audit-ai-agents-like-service-accounts/?utm_source=nhimg&amp;utm_medium=NHIForum">What breaks when organisations treat AI agents like normal service accounts?</a></strong></p>
<p><strong>A:</strong> What breaks is the governance model.</p>
<h2>Practitioner guidance</h2>
<ul>
<li><strong>Classify agent identities by delegated authority</strong> Inventory every AI agent, copilot, and automated workflow by <a href="https://nhimg.org/complete-guide-to-the-2026-owasp-top-10-risks-for-agentic-applications?utm_source=nhimg&amp;utm_medium=NHIForum">who or what it acts for</a>, what tools it can call, and whether it can change scope mid-session.</li>
<li><strong>Require end-to-end delegation traceability</strong> Log originator, agent identity, downstream API calls, and scope changes in a single chain that survives incident review.</li>
<li><strong>Define JIT registration and expiry for agents</strong> <a href="https://nhimg.org/nhi-lifecycle-management-guide?utm_source=nhimg&amp;utm_medium=NHIForum">Register agents only when the task</a> or workflow begins, bind them to a named owner, and expire them when the task ends.</li>
</ul>
<h2>What's in the full article</h2>
<p>Strata Identity's full article covers the operational detail this post intentionally leaves for the source:</p>
<ul>
<li>A practical breakdown of the Six A's and how each one maps to agent authentication, authorisation, and audit logging.</li>
<li>Examples of agentic identity flows such as OAuth OBO, PKCE, SPIFFE/SVID, and DPoP in runtime workflows.</li>
<li>The sandbox and hands-on lab material for testing delegated policies and traceability across agent actions.</li>
</ul>
<p>&#x1f449; <strong><a href="https://www.strata.io/blog/agentic-identity/why-agentic-identities-matter-1b/?utm_source=nhimg&amp;utm_medium=NHIForum">Read Strata Identity's analysis of AI agent identity and accountability →</a></strong></p>
<p><em>AI agent identity and accountability: what changes for IAM teams?</em></p>
<blockquote>
<p><strong>Explore further</strong></p>
<p><a href="/community/?utm_source=nhimg&amp;utm_medium=NHIForum">View Full Forum →</a>  |  <a href="/nhi-training/?utm_source=nhimg&amp;utm_medium=NHIForum">NHI Foundation Course →</a></p>
</blockquote>]]></content:encoded>
						                            <category domain="https://nhimg.org/community/"></category>                        <dc:creator>NHI Mgmt Group</dc:creator>
                        <guid isPermaLink="true">https://nhimg.org/community/agentic-ai-and-nhis/ai-agent-identity-and-accountability-what-changes-for-iam-teams/</guid>
                    </item>
				                    <item>
                        <title>External IAM for APIs and AI agents: what this recognition signals</title>
                        <link>https://nhimg.org/community/nhi-breaches/external-iam-for-apis-and-ai-agents-what-this-recognition-signals/</link>
                        <pubDate>Mon, 08 Jun 2026 17:09:28 +0000</pubDate>
                        <description><![CDATA[TL;DR: The repeat inclusion in Redpoint’s InfraRed 100 sits alongside the claim that hundreds of organisations use the platform to manage external identities across end users, partners, APIs...]]></description>
                        <content:encoded><![CDATA[<blockquote>
<p><strong>TL;DR:</strong> The repeat inclusion in Redpoint’s InfraRed 100 sits alongside the claim that hundreds of organisations use the platform to manage external identities across end users, partners, APIs, and AI agents, highlighting how external IAM is expanding beyond customer login flows, according to Descope. The real governance issue is that identity boundaries are now spanning humans, machines, and agentic workflows at the same time.</p>
</blockquote>
<p><em>NHIMG editorial — based on content published by Descope: Descope named to Redpoint’s InfraRed 100</em></p>
<h2>Questions worth separating out</h2>
<p><strong>Q: <a href="https://nhimg.org/faq/how-should-security-teams-govern-external-identities-across-customers-partners-a/?utm_source=nhimg&amp;utm_medium=NHIForum">How should security teams govern external identities across customers, partners, APIs, and AI agents?</a></strong></p>
<p><strong>A:</strong> Security teams should classify external identities by actor type, then assign separate authentication, authorisation, and revocation rules for each class.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/why-do-ai-agents-create-more-iam-risk-than-ordinary-developer-tools/?utm_source=nhimg&amp;utm_medium=NHIForum">Why do APIs and AI agents create more external IAM risk than human users?</a></strong></p>
<p><strong>A:</strong> APIs and AI agents often run continuously, use credentials programmatically, and operate at machine speed, which makes scope creep harder to notice.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/what-breaks-when-external-identity-lifecycles-are-not-defined-clearly/?utm_source=nhimg&amp;utm_medium=NHIForum">What breaks when external identity lifecycles are not defined clearly?</a></strong></p>
<p><strong>A:</strong> When external lifecycles are unclear, access can outlive the business relationship that justified it.</p>
<h2>Practitioner guidance</h2>
<ul>
<li><strong>Inventory external identity classes</strong> Classify every external actor your programme touches, including customers, partners, APIs, service identities, and AI agents.</li>
<li><strong>Separate human and non-human policy paths</strong> Do not rely on one shared policy model for all external access.</li>
<li><strong>Build lifecycle offboarding into external access design</strong> Make revocation a first-class requirement for partner apps, APIs, and agent identities.</li>
</ul>
<h2>What's in the full analysis</h2>
<p>Descope's full article covers the company-specific context and recognition details this post intentionally leaves aside:</p>
<ul>
<li>The InfraRed 100 recognition context and why Redpoint included the company again</li>
<li>Descope's own explanation of its external IAM positioning across end users, partners, APIs, and AI agents</li>
<li>The company examples it cites, including how customers use the platform in practice</li>
<li>The broader business background around funding, growth, and market visibility</li>
</ul>
<p>&#x1f449; <strong><a href="https://www.descope.com/press-release/redpoint-infrared-100-2025?utm_source=nhimg&amp;utm_medium=NHIForum">Read Descope's InfraRed 100 recognition note and external IAM context →</a></strong></p>
<p><em>External IAM for APIs and AI agents: what this recognition signals?</em></p>
<blockquote>
<p><strong>Explore further</strong></p>
<p><a href="/community/?utm_source=nhimg&amp;utm_medium=NHIForum">View Full Forum →</a>  |  <a href="/nhi-training/?utm_source=nhimg&amp;utm_medium=NHIForum">NHI Foundation Course →</a></p>
</blockquote>]]></content:encoded>
						                            <category domain="https://nhimg.org/community/"></category>                        <dc:creator>NHI Mgmt Group</dc:creator>
                        <guid isPermaLink="true">https://nhimg.org/community/nhi-breaches/external-iam-for-apis-and-ai-agents-what-this-recognition-signals/</guid>
                    </item>
				                    <item>
                        <title>Context chaining for AI tools: what changes for knowledge teams?</title>
                        <link>https://nhimg.org/community/nhi-best-practices/context-chaining-for-ai-tools-what-changes-for-knowledge-teams/</link>
                        <pubDate>Mon, 08 Jun 2026 17:09:19 +0000</pubDate>
                        <description><![CDATA[TL;DR: Professional knowledge workers get better AI results by building one deep context thread and reusing it across code, tests, docs, and communications, rather than restarting from scrat...]]></description>
                        <content:encoded><![CDATA[<blockquote>
<p><strong>TL;DR:</strong> Professional knowledge workers get better AI results by building one deep context thread and reusing it across code, tests, docs, and communications, rather than restarting from scratch each time, according to WorkOS. The governance lesson is that output quality now depends on context stewardship, not just model access.</p>
</blockquote>
<p><em>NHIMG editorial — based on content published by WorkOS: AI isn't magic. Context chaining is</em></p>
<h2>Questions worth separating out</h2>
<p><strong>Q: <a href="https://nhimg.org/faq/how-should-security-teams-govern-ai-assistants-that-reuse-context-across-tasks/?utm_source=nhimg&amp;utm_medium=NHIForum">How should security teams govern AI assistants that reuse context across tasks?</a></strong></p>
<p><strong>A:</strong> Security teams should treat reusable context as a governed access path, not a harmless productivity feature.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/why-do-context-rich-ai-workflows-create-new-access-risks/?utm_source=nhimg&amp;utm_medium=NHIForum">Why do context-rich AI workflows create new access risks?</a></strong></p>
<p><strong>A:</strong> Context-rich workflows create risk because the model can accumulate and reuse sensitive facts across deliverables without a human re-authorising each reuse.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/what-breaks-when-teams-use-separate-ai-prompts-for-each-deliverable/?utm_source=nhimg&amp;utm_medium=NHIForum">What breaks when teams use separate AI prompts for each deliverable?</a></strong></p>
<p><strong>A:</strong> When teams split work into isolated prompts, they lose continuity and force the model to relearn the project from scratch.</p>
<h2>Practitioner guidance</h2>
<ul>
<li><strong>Define context boundaries for AI assistants</strong> Map which repositories, chats, docs, and workspaces an AI assistant can read, reuse, and retain across tasks.</li>
<li><strong>Review high-value prompts as governance artefacts</strong> Treat the first prompt thread as a durable project record when it contains architecture, code, or policy decisions.</li>
<li><strong>Limit context reuse across sensitive workstreams</strong> Separate product, engineering, support, and customer data threads where the same assistant is used.</li>
</ul>
<h2>What's in the full article</h2>
<p>WorkOS's full article covers the workflow detail this post intentionally leaves at the governance level:</p>
<ul>
<li>A step-by-step account of how one conversation thread was reused across code, testing, internal documentation, and external messaging.</li>
<li>The specific prompt patterns the author used to preserve technical context while generating different deliverables.</li>
<li>Operational examples of how the WorkOS MCP docs server was spun up and verified inside the same workflow.</li>
<li>The practical workflow details behind keeping context alive across multiple AI tools and workspaces.</li>
</ul>
<p>&#x1f449; <strong><a href="https://workos.com/blog/context-chaining?utm_source=nhimg&amp;utm_medium=NHIForum">Read WorkOS's article on context chaining in AI workflows →</a></strong></p>
<p><em>Context chaining for AI tools: what changes for knowledge teams?</em></p>
<blockquote>
<p><strong>Explore further</strong></p>
<p><a href="/community/?utm_source=nhimg&amp;utm_medium=NHIForum">View Full Forum →</a>  |  <a href="/nhi-training/?utm_source=nhimg&amp;utm_medium=NHIForum">NHI Foundation Course →</a></p>
</blockquote>]]></content:encoded>
						                            <category domain="https://nhimg.org/community/"></category>                        <dc:creator>NHI Mgmt Group</dc:creator>
                        <guid isPermaLink="true">https://nhimg.org/community/nhi-best-practices/context-chaining-for-ai-tools-what-changes-for-knowledge-teams/</guid>
                    </item>
				                    <item>
                        <title>NHI risk in 2025: what changes when agents join the mix?</title>
                        <link>https://nhimg.org/community/nhi-support-guidance-forum/nhi-risk-in-2025-what-changes-when-agents-join-the-mix/</link>
                        <pubDate>Mon, 08 Jun 2026 17:09:08 +0000</pubDate>
                        <description><![CDATA[TL;DR: Non-human identity risk is now urgent for 93% of respondents in ConductorOne’s 2025 Future of Identity Security Report, while 42% say NHI security outranks human user security and 78%...]]></description>
                        <content:encoded><![CDATA[<blockquote>
<p><strong>TL;DR:</strong> Non-human identity risk is now urgent for 93% of respondents in ConductorOne’s 2025 Future of Identity Security Report, while 42% say NHI security outranks human user security and 78% claim high or full visibility despite persistent privilege and rotation issues. The governance gap is no longer visibility alone, but control of access scope and lifecycle at machine scale.</p>
</blockquote>
<p><em>NHIMG editorial — based on content published by ConductorOne: Managing Non-Human Identity Risk in 2025</em></p>
<p><strong>By the numbers:</strong></p>
<ul>
<li>A staggering <a href="https://www.c1.ai/blog/managing-nhis-in-2025?utm_source=nhimg&amp;utm_medium=NHIForum">93% of respondents</a> in the report said the risks associated with NHIs are urgent, with 24% calling them extremely urgent and in need of immediate action.</li>
<li><a href="https://www.c1.ai/blog/managing-nhis-in-2025?utm_source=nhimg&amp;utm_medium=NHIForum">42% of respondents</a> say NHI security is now a higher priority than securing human users.</li>
<li><a href="https://www.c1.ai/blog/managing-nhis-in-2025?utm_source=nhimg&amp;utm_medium=NHIForum">78% of respondents</a> said they have high or full visibility into NHIs across their environment, and 30% say they already have total visibility.</li>
</ul>
<h2>Questions worth separating out</h2>
<p><strong>Q: <a href="https://nhimg.org/faq/how-should-security-teams-govern-non-human-identities-at-scale/?utm_source=nhimg&amp;utm_medium=NHIForum">How should security teams govern non-human identities at scale?</a></strong></p>
<p><strong>A:</strong> Security teams should govern non-human identities by assigning ownership, limiting scope, and enforcing lifecycle controls for every service account, token, and API key.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/why-do-nhis-create-more-governance-risk-than-human-accounts/?utm_source=nhimg&amp;utm_medium=NHIForum">Why do NHIs create more governance risk than many human accounts?</a></strong></p>
<p><strong>A:</strong> NHIs create more governance risk because they are easier to over-provision, harder to review, and less likely to trigger lifecycle events that remove access.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/how-do-security-teams-know-if-nhi-visibility-is-actually-working/?utm_source=nhimg&amp;utm_medium=NHIForum">How do security teams know if NHI visibility is actually working?</a></strong></p>
<p><strong>A:</strong> Visibility is working only when discovery leads to ownership, review, and action.</p>
<h2>Practitioner guidance</h2>
<ul>
<li><strong>Build an authoritative NHI inventory</strong> Map every service account, token, API key, certificate, and AI agent to an <a href="https://nhimg.org/top-10-non-human-identity-issues?utm_source=nhimg&amp;utm_medium=NHIForum">owner, purpose, and expiry</a> so discovery turns into accountable governance.</li>
<li><strong>Tighten default privilege at creation time</strong> Start each machine identity with the <a href="https://nhimg.org/the-ultimate-guide-to-non-human-identities?utm_source=nhimg&amp;utm_medium=NHIForum">minimum access needed</a> for the workload, then expand entitlements only after documented justification and review.</li>
<li><strong>Operationalise credential rotation and revocation</strong> Treat rotation as a <a href="https://nhimg.org/nhi-lifecycle-management-guide?utm_source=nhimg&amp;utm_medium=NHIForum">planned lifecycle control</a> for embedded secrets, third-party integrations, and long-lived service accounts, not as an emergency-only task.</li>
</ul>
<h2>What's in the full article</h2>
<p>ConductorOne's full blog covers the operational detail this post intentionally leaves for the source:</p>
<ul>
<li>Survey framing and respondent mix behind the 2025 Future of Identity Security Report</li>
<li>Breakdowns of where teams struggle most with over-provisioning, rotation, and third-party NHI risk</li>
<li>The article's narrative examples for why agentic AI changes the machine identity picture</li>
<li>ConductorOne's explanation of the controls it recommends for machine identity governance</li>
</ul>
<p>&#x1f449; <strong><a href="https://www.c1.ai/blog/managing-nhis-in-2025?utm_source=nhimg&amp;utm_medium=NHIForum">Read ConductorOne's analysis of managing non-human identity risk in 2025 →</a></strong></p>
<p><em>NHI risk in 2025: what changes when agents join the mix?</em></p>
<blockquote>
<p><strong>Explore further</strong></p>
<p><a href="/community/?utm_source=nhimg&amp;utm_medium=NHIForum">View Full Forum →</a>  |  <a href="/nhi-training/?utm_source=nhimg&amp;utm_medium=NHIForum">NHI Foundation Course →</a></p>
</blockquote>]]></content:encoded>
						                            <category domain="https://nhimg.org/community/"></category>                        <dc:creator>NHI Mgmt Group</dc:creator>
                        <guid isPermaLink="true">https://nhimg.org/community/nhi-support-guidance-forum/nhi-risk-in-2025-what-changes-when-agents-join-the-mix/</guid>
                    </item>
				                    <item>
                        <title>Agent fabric and AI agent identity governance: are your controls ready?</title>
                        <link>https://nhimg.org/community/agentic-ai-and-nhis/agent-fabric-and-ai-agent-identity-governance-are-your-controls-ready/</link>
                        <pubDate>Mon, 08 Jun 2026 17:08:58 +0000</pubDate>
                        <description><![CDATA[TL;DR: Agent fabric is an identity control plane for AI agents that dynamically discovers them, maps scopes and risk, and ties runtime behavior back to verifiable identities across clouds an...]]></description>
                        <content:encoded><![CDATA[<blockquote>
<p><strong>TL;DR:</strong> Agent fabric is an identity control plane for AI agents that dynamically discovers them, maps scopes and risk, and ties runtime behavior back to verifiable identities across clouds and runtimes, according to Strata Identity. The core governance assumption breaks when agents are ephemeral, distributed, and capable of acting on behalf of users without a stable review window.</p>
</blockquote>
<p><em>NHIMG editorial — based on content published by Strata Identity: agent fabric and AI agent identity governance</em></p>
<p><strong>By the numbers:</strong></p>
<ul>
<li>Enterprises will see <a href="https://www.strata.io/blog/agentic-identity/agent-fabrics-registries-central-2b/?utm_source=nhimg&amp;utm_medium=NHIForum">80x more agents than human users</a> within two years.</li>
</ul>
<h2>Questions worth separating out</h2>
<p><strong>Q: <a href="https://nhimg.org/faq/how-should-enterprises-govern-ai-agents-across-multiple-clouds-and-saas-platform/?utm_source=nhimg&amp;utm_medium=NHIForum">How should security teams govern AI agents across multiple clouds and runtimes?</a></strong></p>
<p><strong>A:</strong> Security teams should govern AI agents through a central identity registry that binds each agent to scopes, purpose, owner, TTL, and revocation state, then enforce policy consistently across every runtime.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/what-breaks-when-ai-agents-are-deployed-without-a-registry/?utm_source=nhimg&amp;utm_medium=NHIForum">What breaks when AI agents are deployed without a registry?</a></strong></p>
<p><strong>A:</strong> Without a registry, teams lose the ability to tie runtime behavior to a verifiable identity, which means scopes, audit trails, and revocation become fragmented or invisible.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/how-do-organisations-know-if-ai-agent-governance-is-actually-working/?utm_source=nhimg&amp;utm_medium=NHIForum">How do you know if AI agent access governance is actually working?</a></strong></p>
<p><strong>A:</strong> It is working when every agent has an owner, a verifiable identity binding, a limited scope, a clear TTL, and a revocation path that is enforced across environments.</p>
<h2>Practitioner guidance</h2>
<ul>
<li><strong>Build an agent registry before scaling deployments</strong> Record each AI <a href="https://nhimg.org/the-ultimate-guide-to-non-human-identities?utm_source=nhimg&amp;utm_medium=NHIForum">agent's identity binding</a>, declared function, scopes, TTL, revocation state, and owner before allowing production access.</li>
<li><strong>Audit OAuth scopes against declared agent purpose</strong> Compare each agent's granted scopes with its intended function and business unit, then remove permissions that are broader than the runtime task requires.</li>
<li><strong>Federate policy across runtimes and IDPs</strong> Map how agent identity is asserted and verified across Entra, Okta, AWS, on-premises workloads, and CI/CD pipelines so <a href="https://nhimg.org/top-10-non-human-identity-issues?utm_source=nhimg&amp;utm_medium=NHIForum">policy, logging, and revocation</a> remain consistent at every boundary.</li>
</ul>
<h2>What's in the full article</h2>
<p>Strata Identity's full article covers the operational detail this post intentionally leaves for the source:</p>
<ul>
<li>A deeper explanation of the registry fields that matter for agent governance, including bindings, risk levels, and revocation data</li>
<li>Examples of how the agent fabric fits alongside identity fabric and app fabric in a real architecture</li>
<li>Discussion of private versus public registry patterns for regulated and distributed environments</li>
</ul>
<p>&#x1f449; <strong><a href="https://www.strata.io/blog/agentic-identity/agent-fabrics-registries-central-2b/?utm_source=nhimg&amp;utm_medium=NHIForum">Read Strata Identity's analysis of agent fabric for AI agent identity governance →</a></strong></p>
<p><em>Agent fabric and AI agent identity governance: are your controls ready?</em></p>
<blockquote>
<p><strong>Explore further</strong></p>
<p><a href="/community/?utm_source=nhimg&amp;utm_medium=NHIForum">View Full Forum →</a>  |  <a href="/nhi-training/?utm_source=nhimg&amp;utm_medium=NHIForum">NHI Foundation Course →</a></p>
</blockquote>]]></content:encoded>
						                            <category domain="https://nhimg.org/community/"></category>                        <dc:creator>NHI Mgmt Group</dc:creator>
                        <guid isPermaLink="true">https://nhimg.org/community/agentic-ai-and-nhis/agent-fabric-and-ai-agent-identity-governance-are-your-controls-ready/</guid>
                    </item>
				                    <item>
                        <title>AI-native data security funding: what it means for IAM teams</title>
                        <link>https://nhimg.org/community/nhi-breaches/ai-native-data-security-funding-what-it-means-for-iam-teams/</link>
                        <pubDate>Mon, 08 Jun 2026 17:08:47 +0000</pubDate>
                        <description><![CDATA[TL;DR: AI adoption is pushing data security and governance closer together, and blind spots around sensitive data now carry identity and access consequences as well as data risk, according t...]]></description>
                        <content:encoded><![CDATA[<blockquote>
<p><strong>TL;DR:</strong> AI adoption is pushing data security and governance closer together, and blind spots around sensitive data now carry identity and access consequences as well as data risk, according to Cyera, which says it raised $540 million in Series E funding, lifted total funding above $1.3 billion, and reached a $6 billion valuation in six months, while also reporting 353% year-over-year growth among F500 customers and operations in 10 countries.</p>
</blockquote>
<p><em>NHIMG editorial — based on content published by Cyera: Cyera doubles customer base in six months, reaching a $6 billion valuation</em></p>
<p><strong>By the numbers:</strong></p>
<ul>
<li>Cyera says it raised <a href="https://www.cyera.com/press-releases/ai-native-security-leader-cyera-doubles-customer-base-in-six-months-reaching-6-billion-valuation?utm_source=nhimg&amp;utm_medium=NHIForum">$540 million in Series E funding</a>, bringing total funding to over $1.3 billion and valuation to $6 billion.</li>
<li>Cyera reports <a href="https://www.cyera.com/press-releases/ai-native-security-leader-cyera-doubles-customer-base-in-six-months-reaching-6-billion-valuation?utm_source=nhimg&amp;utm_medium=NHIForum">353% year-over-year growth among F500 customers</a> over the past 18 months.</li>
<li>Cyera says it expanded <a href="https://www.cyera.com/press-releases/ai-native-security-leader-cyera-doubles-customer-base-in-six-months-reaching-6-billion-valuation?utm_source=nhimg&amp;utm_medium=NHIForum">operations to 10 countries</a> and has nearly 800 employees worldwide.</li>
</ul>
<h2>Questions worth separating out</h2>
<p><strong>Q: <a href="https://nhimg.org/faq/how-should-security-teams-govern-sensitive-data-used-by-ai-systems/?utm_source=nhimg&amp;utm_medium=NHIForum">How should security teams govern sensitive data used by AI systems?</a></strong></p>
<p><strong>A:</strong> Security teams should connect data classification, identity visibility, and entitlement review before data enters AI workflows.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/why-does-ai-visibility-matter-for-nhi-governance/?utm_source=nhimg&amp;utm_medium=NHIForum">Why do AI projects increase the importance of NHI governance?</a></strong></p>
<p><strong>A:</strong> AI projects often rely on service accounts, API keys, and delegated application access to move data into tools and models.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/what-breaks-when-data-classification-does-not-follow-the-workflow/?utm_source=nhimg&amp;utm_medium=NHIForum">What breaks when data classification does not follow the workflow?</a></strong></p>
<p><strong>A:</strong> When classification stops at the repository, security teams lose track of how sensitive data is transformed, copied, and reused in SaaS or AI systems.</p>
<h2>Practitioner guidance</h2>
<ul>
<li><strong>Map AI data paths to identity paths</strong> Inventory which human users, <a href="https://nhimg.org/the-ultimate-guide-to-non-human-identities?utm_source=nhimg&amp;utm_medium=NHIForum">service accounts, API keys, and application tokens</a> can reach sensitive datasets before they enter AI workflows.</li>
<li><strong>Prioritise identity-aware DLP policy</strong> Configure data loss prevention controls to evaluate <a href="https://nhimg.org/the-ultimate-guide-to-non-human-identities?utm_source=nhimg&amp;utm_medium=NHIForum">requester context, application context, and data sensitivity</a> together.</li>
<li><strong>Reconcile classification with access certification</strong> Use classification results to <a href="https://nhimg.org/the-ultimate-guide-to-non-human-identities?utm_source=nhimg&amp;utm_medium=NHIForum#key-challenges-and-risks">drive access reviews</a> for workloads and humans, especially where AI systems consume or redistribute regulated information.</li>
</ul>
<h2>What's in the full analysis</h2>
<p>Cyera's full article covers the operational detail this post intentionally leaves for the source:</p>
<ul>
<li>The funding and valuation context behind Cyera’s growth, including investor participation and timing</li>
<li>Cyera’s product scope across discovery, classification, DLP, and AI-adjacent data protection</li>
<li>The company’s own explanation of why enterprises need AI-native data security at scale</li>
<li>The expansion and hiring details that explain how the platform is being positioned operationally</li>
</ul>
<p>&#x1f449; <strong><a href="https://www.cyera.com/press-releases/ai-native-security-leader-cyera-doubles-customer-base-in-six-months-reaching-6-billion-valuation?utm_source=nhimg&amp;utm_medium=NHIForum">Read Cyera's funding announcement and AI-native data security outlook →</a></strong></p>
<p><em>AI-native data security funding: what it means for IAM teams?</em></p>
<blockquote>
<p><strong>Explore further</strong></p>
<p><a href="/community/?utm_source=nhimg&amp;utm_medium=NHIForum">View Full Forum →</a>  |  <a href="/nhi-training/?utm_source=nhimg&amp;utm_medium=NHIForum">NHI Foundation Course →</a></p>
</blockquote>]]></content:encoded>
						                            <category domain="https://nhimg.org/community/"></category>                        <dc:creator>NHI Mgmt Group</dc:creator>
                        <guid isPermaLink="true">https://nhimg.org/community/nhi-breaches/ai-native-data-security-funding-what-it-means-for-iam-teams/</guid>
                    </item>
				                    <item>
                        <title>AI data integrity and DSPM: is your governance model keeping up?</title>
                        <link>https://nhimg.org/community/nhi-support-guidance-forum/ai-data-integrity-and-dspm-is-your-governance-model-keeping-up/</link>
                        <pubDate>Mon, 08 Jun 2026 17:08:38 +0000</pubDate>
                        <description><![CDATA[TL;DR: As AI adoption grows, data integrity becomes the critical control point and DSPM becomes the mechanism for classifying, discovering, and enforcing policy across cloud and on-prem data...]]></description>
                        <content:encoded><![CDATA[<blockquote>
<p><strong>TL;DR:</strong> As AI adoption grows, data integrity becomes the critical control point and DSPM becomes the mechanism for classifying, discovering, and enforcing policy across cloud and on-prem data estates, according to Cyera. The governance break is that security teams can no longer rely on perimeter-era controls to keep pace with AI-generated and AI-consumed data.</p>
</blockquote>
<p><em>NHIMG editorial — based on content published by Cyera: Are You Ready for Web 3.0? How DSPM helps you move at the speed of AI</em></p>
<p><strong>By the numbers:</strong></p>
<ul>
<li>This year the world is producing <a href="https://www.cyera.com/blog/are-you-ready-for-web-3-0-how-dspm-helps-you-move-at-the-speed-of-ai?utm_source=nhimg&amp;utm_medium=NHIForum">over 180 zettabytes of data</a>, one byte for every star in the known universe.</li>
<li>DSPM can classify even unstructured data with <a href="https://www.cyera.com/blog/are-you-ready-for-web-3-0-how-dspm-helps-you-move-at-the-speed-of-ai?utm_source=nhimg&amp;utm_medium=NHIForum">95 percent precision or better</a>, an essential capability when so much of the data used to train AI models consists of documents in various file formats.</li>
</ul>
<h2>Questions worth separating out</h2>
<p><strong>Q: <a href="https://nhimg.org/faq/how-should-security-teams-govern-sensitive-data-used-by-ai-systems/?utm_source=nhimg&amp;utm_medium=NHIForum">How should security teams govern AI access to sensitive data?</a></strong></p>
<p><strong>A:</strong> Security teams should govern AI access by combining data discovery, semantic classification, and entitlement review.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/why-do-traditional-dlp-and-casb-tools-fall-short-for-ai-governance/?utm_source=nhimg&amp;utm_medium=NHIForum">Why do traditional DLP tools struggle with AI data governance?</a></strong></p>
<p><strong>A:</strong> Traditional DLP tools struggle because they depend heavily on pattern matching and edge inspection.</p>
<p><strong>Q: When should organisations prioritise DSPM over perimeter upgrades?</strong></p>
<p><strong>A:</strong> Organisations should prioritise DSPM when sensitive data is already distributed across cloud services, collaboration tools, and AI workflows.</p>
<h2>Practitioner guidance</h2>
<ul>
<li><strong>Inventory sensitive data across all storage layers</strong> Catalogue data in SaaS, IaaS, PaaS, DBaaS, and on-prem systems so classification does not stop at the perimeter.</li>
<li><strong>Replace regex-only detection with semantic classification</strong> Use classification that recognises <a href="https://nhimg.org/nhi-lifecycle-management-guide?utm_source=nhimg&amp;utm_medium=NHIForum">meaning and context</a> in unstructured documents, logs, and mixed file types.</li>
<li><strong>Link DSPM findings to identity governance workflows</strong> Feed exposed-data findings into <a href="https://nhimg.org/the-ultimate-guide-to-non-human-identities?utm_source=nhimg&amp;utm_medium=NHIForum">access review</a>, stale-account cleanup, and privilege reduction so the control loop does not stop at discovery.</li>
</ul>
<h2>What's in the full article</h2>
<p>Cyera's full article covers the operational detail this post intentionally leaves for the source:</p>
<ul>
<li>The article’s full explanation of how DSPM classifies data with large language models and natural language processing</li>
<li>The specific control mapping Cyera uses to connect DSPM to Gartner TRiSM capabilities</li>
<li>The source’s discussion of AI-native data protection use cases across cloud and on-prem environments</li>
<li>The vendor’s own framing of how DSPM supports policy enforcement and monitoring at scale</li>
</ul>
<p>&#x1f449; <strong><a href="https://www.cyera.com/blog/are-you-ready-for-web-3-0-how-dspm-helps-you-move-at-the-speed-of-ai?utm_source=nhimg&amp;utm_medium=NHIForum">Read Cyera's analysis of DSPM and AI data integrity in the Web 3.0 era →</a></strong></p>
<p><em>AI data integrity and DSPM: is your governance model keeping up?</em></p>
<blockquote>
<p><strong>Explore further</strong></p>
<p><a href="/community/?utm_source=nhimg&amp;utm_medium=NHIForum">View Full Forum →</a>  |  <a href="/nhi-training/?utm_source=nhimg&amp;utm_medium=NHIForum">NHI Foundation Course →</a></p>
</blockquote>]]></content:encoded>
						                            <category domain="https://nhimg.org/community/"></category>                        <dc:creator>NHI Mgmt Group</dc:creator>
                        <guid isPermaLink="true">https://nhimg.org/community/nhi-support-guidance-forum/ai-data-integrity-and-dspm-is-your-governance-model-keeping-up/</guid>
                    </item>
				                    <item>
                        <title>GDPR and customer identity: where compliance breaks down</title>
                        <link>https://nhimg.org/community/nhi-support-guidance-forum/gdpr-and-customer-identity-where-compliance-breaks-down/</link>
                        <pubDate>Mon, 08 Jun 2026 17:08:28 +0000</pubDate>
                        <description><![CDATA[TL;DR: GDPR compliance is shifting from manual legal and IT workflows to identity-based controls for consent, access, erasure, logging, and lifecycle management, according to Okta. The core ...]]></description>
                        <content:encoded><![CDATA[<blockquote>
<p><strong>TL;DR:</strong> GDPR compliance is shifting from manual legal and IT workflows to identity-based controls for consent, access, erasure, logging, and lifecycle management, according to Okta. The core issue is not policy intent but operational scale: compliance fails when identity data, downstream app permissions, and audit evidence remain fragmented across systems.</p>
</blockquote>
<p><em>NHIMG editorial — based on content published by Okta: Starting Your General Data Protection Regulation (GDPR) Journey with Okta</em></p>
<p><strong>By the numbers:</strong></p>
<ul>
<li>Only <a href="https://nhimg.org/the-ultimate-guide-to-non-human-identities?utm_source=nhimg&amp;utm_medium=NHIForum#key-research-and-survey-results">5.7% of organisations have full visibility</a> into their service accounts.</li>
<li><a href="https://nhimg.org/the-ultimate-guide-to-non-human-identities?utm_source=nhimg&amp;utm_medium=NHIForum#key-research-and-survey-results">96% of organisations store secrets outside</a> of secrets managers in vulnerable locations including code, config files, and CI/CD tools.</li>
<li><a href="https://nhimg.org/the-ultimate-guide-to-non-human-identities?utm_source=nhimg&amp;utm_medium=NHIForum#key-research-and-survey-results">91.6% of secrets remain valid</a> five days after the targeted organisation is notified, showing a critical gap in remediation procedures.</li>
</ul>
<h2>Questions worth separating out</h2>
<p><strong>Q: <a href="https://nhimg.org/faq/how-should-organisations-operationalize-gdpr-access-and-erasure-requests-through/?utm_source=nhimg&amp;utm_medium=NHIForum">How should organisations operationalize GDPR access and erasure requests through identity systems?</a></strong></p>
<p><strong>A:</strong> Treat them as lifecycle workflows, not manual tickets.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/why-do-manual-gdpr-processes-break-down-as-organisations-scale/?utm_source=nhimg&amp;utm_medium=NHIForum">Why do manual GDPR processes break down as organisations scale?</a></strong></p>
<p><strong>A:</strong> Manual processes break down because the number of requests, apps, and data stores grows faster than the team’s ability to reconcile them.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/how-do-you-know-if-consent-management-is-actually-working/?utm_source=nhimg&amp;utm_medium=NHIForum">How do you know if consent management is actually working?</a></strong></p>
<p><strong>A:</strong> Consent management is working when the current purpose, scope, and timestamp are available in one authoritative record and downstream applications honor those attributes consistently.</p>
<h2>Practitioner guidance</h2>
<ul>
<li><strong>Model GDPR rights as lifecycle workflows</strong> Map access, rectification, portability, and erasure to governed provisioning and deprovisioning steps, with ownership and approval paths defined before requests arrive.</li>
<li><strong>Store consent with the authoritative identity record</strong> Keep consent purpose, scope, and timestamp as identity attributes that downstream apps can read consistently.</li>
<li><strong>Centralize access evidence and login history</strong> Aggregate <a href="https://nhimg.org/the-ultimate-guide-to-non-human-identities?utm_source=nhimg&amp;utm_medium=NHIForum">system logs</a>, access reports, and suspicious activity signals into one evidentiary trail that supports breach notification and subject access requests.</li>
</ul>
<h2>What's in the full article</h2>
<p>Okta's full article covers the operational detail this post intentionally leaves for the source:</p>
<ul>
<li>The specific mapping between GDPR articles and Okta identity functions for consent, access, and erasure workflows.</li>
<li>Examples of how Universal Directory is used to store consent and profile attributes for downstream enforcement.</li>
<li>The logging and reporting approach used to support breach investigation and supervisory authority notification.</li>
<li>The staged compliance model showing how organisations move from manual handling to platform-based governance.</li>
</ul>
<p>&#x1f449; <strong><a href="https://www.okta.com/resources/whitepaper/starting-your-general-data-protection-regulation-journey-with-okta/?utm_source=nhimg&amp;utm_medium=NHIForum">Read Okta's analysis of GDPR compliance through customer identity →</a></strong></p>
<p><em>GDPR and customer identity: where compliance breaks down?</em></p>
<blockquote>
<p><strong>Explore further</strong></p>
<p><a href="/community/?utm_source=nhimg&amp;utm_medium=NHIForum">View Full Forum →</a>  |  <a href="/nhi-training/?utm_source=nhimg&amp;utm_medium=NHIForum">NHI Foundation Course →</a></p>
</blockquote>]]></content:encoded>
						                            <category domain="https://nhimg.org/community/"></category>                        <dc:creator>NHI Mgmt Group</dc:creator>
                        <guid isPermaLink="true">https://nhimg.org/community/nhi-support-guidance-forum/gdpr-and-customer-identity-where-compliance-breaks-down/</guid>
                    </item>
				                    <item>
                        <title>Phishing-resistant MFA and the governance gap teams still face</title>
                        <link>https://nhimg.org/community/nhi-support-guidance-forum/phishing-resistant-mfa-and-the-governance-gap-teams-still-face/</link>
                        <pubDate>Mon, 08 Jun 2026 17:08:18 +0000</pubDate>
                        <description><![CDATA[TL;DR: Phishing remains the most likely attack for 49% of respondents, while 64% cite fear of change as the main reason they keep passwords and non-phishing-resistant MFA, according to Axiad...]]></description>
                        <content:encoded><![CDATA[<blockquote>
<p><strong>TL;DR:</strong> Phishing remains the most likely attack for 49% of respondents, while 64% cite fear of change as the main reason they keep passwords and non-phishing-resistant MFA, according to Axiad’s 2023 State of Authentication Survey. Removing the human step is only part of the answer; authentication strategy still has to align with real IAM, rollout, and lifecycle constraints.</p>
</blockquote>
<p><em>NHIMG editorial — based on content published by Axiad: How to Adopt Phishing-Resistant MFA</em></p>
<p><strong>By the numbers:</strong></p>
<ul>
<li><a href="https://www.axiad.com/blog/how-to-adopt-unphishable-mfa?utm_source=nhimg&amp;utm_medium=NHIForum">49% of respondents said phishing</a> is the most likely attack to happen.</li>
<li><a href="https://www.axiad.com/blog/how-to-adopt-unphishable-mfa?utm_source=nhimg&amp;utm_medium=NHIForum">64% of respondents said fear of change</a> is the top reason for holding onto passwords and non-phishing-resistant MFA.</li>
<li>Only <a href="https://nhimg.org/the-ultimate-guide-to-non-human-identities?utm_source=nhimg&amp;utm_medium=NHIForum#key-research-and-survey-results">5.7% of organisations have full visibility</a> into their service accounts.</li>
</ul>
<h2>Questions worth separating out</h2>
<p><strong>Q: <a href="https://nhimg.org/faq/how-should-security-teams-reduce-phishing-risk-in-mfa-without-creating-more-user/?utm_source=nhimg&amp;utm_medium=NHIForum">How should security teams roll out phishing-resistant MFA without disrupting users?</a></strong></p>
<p><strong>A:</strong> Start with high-risk user groups, define assurance levels by role, and support the rollout with clear onboarding and recovery processes.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/why-do-passwords-and-conventional-mfa-still-create-phishing-risk/?utm_source=nhimg&amp;utm_medium=NHIForum">Why do passwords and conventional MFA still create phishing risk?</a></strong></p>
<p><strong>A:</strong> Passwords can be stolen, and many MFA methods still rely on users approving prompts or entering codes that can be captured in real time.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/what-do-organisations-get-wrong-when-they-treat-phishing-resistance-as-a-technol/?utm_source=nhimg&amp;utm_medium=NHIForum">What do organisations get wrong when they treat phishing resistance as a technology project?</a></strong></p>
<p><strong>A:</strong> They focus on the authentication method and ignore the rollout model, support process, and fallback paths.</p>
<h2>Practitioner guidance</h2>
<ul>
<li><strong>Prioritise high-risk user groups first</strong> Start with administrators, finance users, executives, and anyone who can approve money movement or sensitive access.</li>
<li><strong>Map assurance levels to user categories</strong> Define which employee groups need certificate-based authentication, which can use passkeys, and where exceptions are allowed.</li>
<li><strong>Plan for existing IAM interoperability</strong> Document where the new authentication layer will overlay current directories, SSO flows, and legacy applications.</li>
</ul>
<h2>What's in the full article</h2>
<p>Axiad's full blog post covers the operational detail this post intentionally leaves for the source:</p>
<ul>
<li>Practical comparison of certificate-based authentication and FIDO passkeys for real-world rollout decisions</li>
<li>Guidance on mapping authentication levels to user categories without forcing a rip-and-replace IAM project</li>
<li>Implementation considerations for organisations that already have PKI and want to extend it for stronger authentication</li>
<li>Employee preparation and onboarding steps that reduce support friction during phishing-resistant MFA adoption</li>
</ul>
<p>&#x1f449; <strong><a href="https://www.axiad.com/blog/how-to-adopt-unphishable-mfa?utm_source=nhimg&amp;utm_medium=NHIForum">Read Axiad's guide to adopting phishing-resistant MFA →</a></strong></p>
<p><em>Phishing-resistant MFA and the governance gap teams still face?</em></p>
<blockquote>
<p><strong>Explore further</strong></p>
<p><a href="/community/?utm_source=nhimg&amp;utm_medium=NHIForum">View Full Forum →</a>  |  <a href="/nhi-training/?utm_source=nhimg&amp;utm_medium=NHIForum">NHI Foundation Course →</a></p>
</blockquote>]]></content:encoded>
						                            <category domain="https://nhimg.org/community/"></category>                        <dc:creator>NHI Mgmt Group</dc:creator>
                        <guid isPermaLink="true">https://nhimg.org/community/nhi-support-guidance-forum/phishing-resistant-mfa-and-the-governance-gap-teams-still-face/</guid>
                    </item>
							        </channel>
        </rss>
		