Agentic AI Module Added To NHI Training Course

Notifications
Clear all

NHI sprawl in 2025: what does it mean for IAM teams?


(@entro)
Reputable Member
Joined: 1 year ago
Posts: 90
Topic starter  

TL;DR: Non-human identities are on track to outnumber human identities by 100 to 1 in enterprise environments, and Entro Security argues that lifecycle management, AI-assisted detection, and zero-trust controls will become central to 2025 security planning. The governance assumption that machine access can be handled like human access is already breaking down.

NHIMG editorial — based on content published by Entro Security: Cybersecurity Predictions for 2025, focused on non-human identity takeover

By the numbers:

Questions worth separating out

Q: How should security teams implement NHI lifecycle management?

A: Start with discovery, then assign every service account, API key, token, and certificate to an owner with a defined approval and revocation path.

Q: Why do non-human identities complicate zero trust programmes?

A: Because NHIs authenticate at machine speed, often with long-lived secrets and repeated programmatic calls, which makes one-time trust decisions too weak.

Q: What breaks when secrets are stored in code and CI/CD tools?

A: Access becomes invisible, reusable, and hard to revoke, which means the organisation loses control of where authentication material exists.

Practitioner guidance

  • Map every machine identity to an owner Require a named business or platform owner for each service account, API key, token, and certificate so identity sprawl can be triaged and revoked quickly when it is no longer needed.
  • Inventory secrets outside approved vaults Scan code repositories, CI/CD tools, chat systems, and config files for long-lived credentials, then move them into controlled storage with clear rotation and revocation processes.
  • Separate detection from remediation Use anomaly detection to identify unusual machine identity behaviour, but route every alert into a revocation or rotation workflow that can invalidate the credential before reuse.

What's in the full article

Entro Security's full blog post covers the operational detail this post intentionally leaves for the source:

  • The specific 2025 prediction themes and the order Entro Security assigns to them across NHI growth, AI, IAM, lifecycle, and zero trust.
  • The vendor's recommendations for CISOs on continuous discovery, automated lifecycle management, and anomaly detection.
  • The article's own examples of how AI is expected to affect secrets usage patterns and access monitoring.
  • The framing Entro Security uses for why these trends matter to enterprise security planning in 2025.

👉 Read Entro Security’s predictions on NHI takeover and 2025 identity risk →

NHI sprawl in 2025: what does it mean for IAM teams?

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 weeks ago
Posts: 285
 

NHI sprawl is no longer a niche visibility problem, it is an enterprise control-plane problem. Once API keys, service accounts, cloud tokens, and workload credentials outnumber human identities by large multiples, IAM has to govern a much larger and less observable population. The issue is not just growth, but dispersion across pipelines, integrations, and cloud platforms. Practitioners should treat machine identity inventory as a core security boundary, not a reporting exercise.

A few things that frame the scale:

  • 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools, according to The State of Secrets Sprawl 2026.
  • A separate finding shows that 79% of organisations have experienced secrets leaks, and 77% of those incidents resulted in tangible damage.

A question worth separating out:

Q: How do you know if NHI governance is actually working?

A: Look for measurable reduction in unmanaged credentials, faster revocation after exposure, and clear ownership for each machine identity. If the organisation cannot prove where secrets live, who owns them, and how quickly they are invalidated, the governance model is still incomplete.

👉 Read our full editorial: Non-human identities will dominate 2025 IAM planning



   
ReplyQuote
Share: