TL;DR: Identity attacks can evade traditional controls by using legitimate accounts, valid sessions, unmanaged devices, and approved permissions until business context is applied, according to Offroad AI. The real control gap is not authentication alone but whether identity, device, resource, and purpose can be evaluated together in time to drive response.
NHIMG editorial — based on content published by Offroad AI: identity attacks can hide behind legitimate access and approved permissions
By the numbers:
- Only 5.7% of organisations have full visibility into their service accounts.
- 71% of NHIs are not rotated within recommended time frames, increasing the risk of compromise over time.
- 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools.
Questions worth separating out
Q: How should security teams investigate a large data download from a valid account?
A: Start by joining the identity, device, session, entitlement, and business-purpose records into one case.
Q: Why do valid sessions still create identity risk?
A: Because session validity only proves the account authenticated successfully.
Q: What do security teams get wrong about permissioned data access?
A: The common mistake is treating permissioned access as a compliance checkbox instead of an operational control.
Practitioner guidance
- Join identity, device, and purpose data in one investigation path Create a case workflow that pulls authentication, endpoint trust, application audit, vendor assignment, and ticket data together before an analyst decides whether the activity is expected or suspicious.
- Define approved business purpose for high-risk access Require each sensitive third-party or contractor entitlement to map to a named assignment, support case, migration, or change request so investigators can test whether the action matched the reason access existed.
- Alert on context mismatch, not only on volume Treat unmanaged devices, out-of-assignment resources, and unexplained exports as primary risk signals even when the login is valid and the account is in good standing.
What's in the full article
Offroad AI's full analysis covers the operational detail this post intentionally leaves for the source:
- How its investigation flow correlates identity provider, endpoint, application, and ticketing data into one case view
- Examples of plain-language detection objectives for contractor access, bulk exports, and out-of-assignment activity
- The response logic for routing cases to revocation, containment, or business-owner decisioning
- What the system surfaces about identity history, business purpose, and recommended next action
👉 Read Offroad AI's analysis of identity attacks hidden in legitimate access →
Legitimate access, illegitimate outcomes: where identity controls fail?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
Context, not login success, is the real control boundary. Authentication answers only whether an identity proved itself to a system. It does not prove the action was expected, justified, or proportionate to the assignment. That means identity governance has to move beyond access granted toward access used in context. Practitioners should treat this as a structural limitation of event-level IAM, not a tuning problem.
A few things that frame the scale:
- Only 5.7% of organisations have full visibility into their service accounts, according to the Ultimate Guide to NHIs.
- 91.6% of secrets remain valid five days after the targeted organisation is notified, showing how slowly identity exposure is often remediated.
A question worth separating out:
Q: How can organisations tell the difference between work and abuse?
A: By checking for an approved reason, trusted device, expected resource, and normal behaviour history. If those elements do not align, the team should treat the activity as suspicious even when authentication succeeded and the account still holds valid access.
👉 Read our full editorial: Identity attacks hide in legitimate sessions and approved access