Join our Newsletter — 33% off our NHI Course

Oracle Cloud identity gaps: what IAM teams need to fix

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20631
Topic starter  

TL;DR: OCI environments have often sat outside mainstream access review and privilege governance, leaving users, API keys, auth tokens, secret keys and AI agents less visible than the rest of the estate, according to Unosecur. Extending identity inventory into OCI matters because unmanaged cloud tenancy access is still where least-privilege programmes break down fastest.

NHIMG editorial — what this means for NHI practitioners

Questions worth separating out

Q: How should teams govern OCI identities that were outside existing access reviews?

A: Treat OCI as part of the core identity estate, not a special cloud exception.

Q: Why do broad OCI policies and stale identities increase identity risk?

A: Because excess access persists when policies are never recertified against actual use.

Q: What are the signs that cloud access governance is failing in OCI?

A: Common warning signs include outdated access records, inconsistent entitlement changes, weak review evidence, and gaps between approved access and actual system access.

Practitioner guidance

  • Inventory OCI identities alongside the rest of the estate Pull users, roles, groups, API keys, auth tokens, customer secret keys, OAuth client credentials and OCI apps into one reviewable identity graph so entitlement decisions are not made in isolation.
  • Apply access review cadence to OCI compartments and policies Review active and partially offboarded accounts, the policies granting broad access and the compartments those identities can reach, then remove unused privileges as part of the same control cycle.
  • Treat AI agents as governed identities in OCI Include agents in the same least-privilege review path as service accounts and tokens, with clear ownership for access scope and revocation when the agent is no longer needed.

What's in the full announcement

Unosecur's full post covers the operational detail this analysis intentionally leaves for the source:

  • How OCI tenancy discovery is structured across users, roles, groups, policies and compartments.
  • Which identity objects are inventoried in real time, including API keys, auth tokens and customer secret keys.
  • How over-permissioned access is surfaced and remediated in the product workflow.
  • How read-only onboarding and revocation work for OCI connections.

👉 Read Unosecur's OCI identity security announcement →

Oracle Cloud identity gaps: what IAM teams need to fix?

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 20222
 

OCI support closes an identity governance blind spot, not just a cloud coverage gap. The issue is not whether teams can connect to another cloud. The issue is whether OCI identities, credentials and agent access now enter the same governance loop as the rest of the estate. If they do not, least privilege becomes a partial control rather than an estate-wide standard.

A few things that frame the scale:

  • Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
  • That visibility gap is why OCI inventories cannot stop at users and groups. It has to include API keys, tokens, secret keys and agent identities as governed assets, not side data.

A question worth separating out:

Q: How do AI agents change OCI identity governance?

A: AI agents turn OCI access into a governed actor problem, not just a user or workload problem. Once an agent can exercise cloud permissions, it needs inventory, ownership, least privilege and revocation just like any other non-human identity.

👉 Read our full editorial: OCI identity inventory exposes the access most teams miss



   
ReplyQuote
Share: