TL;DR: Identity sprawl across multi-cloud, SaaS, and hybrid estates is pushing IAM and IGA together, while overprivileged service accounts remain a major cloud risk and cloud governance increasingly depends on continuous visibility, lifecycle enforcement, and least-privilege drift control, according to Bravura Security.
Editorial analysis by NHI Mgmt Group, based on content published by Bravura Security: “Identity and Access Management and Identity Governance Explained”.
By the numbers:
- Overprivileged service accounts triggered 46.4% of cloud security alerts in H2 2024.
- Overprivileged service accounts enabled 62.2% of lateral movement incidents.
Key questions
Q: What breaks when identity governance is built only for human users?
A: Access review, joiner-mover-leaver processes, and periodic certification break down when the identity is a service account or autonomous agent.
Q: Why do overprivileged service accounts create such persistent cloud risk?
A: Overprivileged service accounts create persistent risk because they combine standing access, weak ownership, and broad lateral movement potential.
Q: How should IAM teams measure whether IGA is actually working?
A: They should measure whether IGA reduces risky access conditions, not just whether reviews are completed on time.
Practitioner guidance
- Unify human and machine identity inventories Build one authoritative inventory for employees, contractors, service accounts, APIs, workloads, and third-party identities so access can be reviewed in context rather than in separate silos.
- Review overprivileged service accounts first Prioritise the identities most likely to support lateral movement, especially long-lived service accounts with broad cloud permissions and weak ownership metadata.
- Tie lifecycle events to automatic revocation Make joiner, mover, and leaver changes trigger deprovisioning across SaaS, cloud, and on-premises resources so stale access does not survive the business reason for it.
Bottom line: Hybrid identity sprawl is pushing IAM and IGA into a shared governance role because cloud, SaaS, and on-premises access can no longer be managed as separate problems.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
IAM and IGA are no longer separable disciplines in hybrid estates: the article correctly shows that cloud, SaaS, and on-premises identity sprawl collapses the old boundary between access control and governance. IAM without IGA leaves entitlement drift unchecked, while IGA without IAM cannot enforce lifecycle outcomes at the access layer. The practical conclusion is that identity programmes now need one operating model for grant, review, and revocation across all identity types.
A few things that frame the scale:
- Over 70% of organisations lack automated access risk analysis, user access reviews and provisioning and deprovisioning, according to Pathlock's 2025 Digital Transformation and Access Risk Report.
A question worth separating out:
Q: Should organisations prioritise access review or lifecycle automation first?
A: Organisations should prioritise lifecycle automation first when review cycles cannot keep pace with change. Reviews can confirm policy, but automation removes stale access when the underlying event occurs. For high-volume NHIs, that is usually the only practical way to keep entitlements current enough to matter.
👉 Read our full editorial: IAM and IGA are converging around hybrid identity risk