TL;DR: Mergers and acquisitions create a high-risk identity integration problem because service accounts, API keys, tokens, and certificates are often inherited across mismatched environments with unclear ownership, inconsistent scoping, and hidden secrets, according to Oasis Security. The security issue is not just sprawl, but the collapse of governance assumptions that make merged identity estates auditable and controllable.
Editorial analysis by NHI Mgmt Group, based on content published by Oasis Security: “How to manage Non-Human Identities during M&A”.
Key questions
Q: What breaks when non-human identities are merged without a baseline?
A: Ownership, scoping, and lifecycle controls break first.
Q: Why do orphaned service accounts create so much risk after an acquisition?
A: Orphaned service accounts are dangerous because they often keep working after the original owner has left or the original environment has changed.
Q: How do teams know if NHI governance is actually working?
A: Look for complete inventory coverage, clear ownership, enforced rotation, and reliable decommissioning.
Practitioner guidance
- Map every inherited NHI before system integration Scan cloud environments, repositories, container registries, on-prem applications, and SaaS tenants for service accounts, service principals, managed identities, PATs, certificates, and hard-coded secrets before the merger is operationalised.
- Freeze new long-lived credentials on day 0 Block the creation of new persistent credentials as soon as access is available, then use short-lived and tightly scoped credentials where the workflow can support them.
- Normalize ownership and lifecycle metadata Assign an owner, credential lifespan, privilege level, and business purpose to every discovered NHI so that orphaned or undocumented access can be prioritised for remediation.
Bottom line: M&A turns non-human identity governance into a control-reset problem because merged estates inherit conflicting ownership, scoping, and lifecycle assumptions.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
M&A exposes a governance assumption that no longer holds: identity ownership is assumed to remain stable long enough for normal lifecycle controls to work. That assumption fails when two organisations merge, because the same service account, secret, or workload identity can cross into a new operating model before anyone has aligned naming, scoping, or revocation authority. The implication is that merger integration must be treated as a control reset, not a data migration.
A few things that frame the scale:
- NHIs outnumber human identities by 25x to 50x in modern enterprises, according to the Ultimate Guide to NHIs.
A question worth separating out:
Q: Should organisations unify policy or federate identity systems during M&A?
A: That depends on maturity, regulatory pressure, and operational complexity. Federation can preserve separation while linking trust, but it does not remove the need for shared NHI governance. If the organisation cannot enforce the same lifecycle rules in both estates, unification without policy alignment only hides the risk.
👉 Read our full editorial: Managing non-human identities during M&A requires a new baseline