Join our Newsletter — 33% off our NHI Course

Offboarding exposed NHIs: where mover-leaver controls fail

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Employee offboarding often stops at human accounts while exposed service accounts, API keys, and secrets remain active, leaving lateral-movement paths open, according to Oasis Security. The real control gap is that human leaver processes are not enough when non-human identities outlive the employee who saw them.

Editorial analysis by NHI Mgmt Group, based on content published by Oasis Security: “How to manage the NHIs exposed to an offboarded employee?”.

Key questions

Q: What breaks when human offboarding is used as the only control for NHIs?

A: The organisation keeps service credentials alive after the person who knew them is gone.

Q: Why do exposed non-human identities remain risky after an employee leaves?

A: They remain risky because NHIs are tied to systems and processes, not to the employee who handled them.

Q: How should teams decide between rotation and deactivation during offboarding?

A: Teams should choose based on service dependency.

Practitioner guidance

  • Build an exposed-NHI offboarding inventory Map every service account, API key, automated script, and secret the departing or moving employee could access, see, create, or share before any human account is deprovisioned.
  • Separate revoke, rotate, and reassign decisions Treat each exposed NHI as a dependency decision: some credentials can be reassigned, some must be rotated, and some should be retired because reassignment would over-privilege a successor.
  • Correlate human exposure to machine credentials Use contextual correlation between the offboarded identity and the secrets or roles they touched so that remediation targets only the NHIs actually exposed by that person.

Bottom line: Human offboarding is not complete if service accounts, API keys, and secrets that the employee touched are still active.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 21 hours ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 20880
 

Human leaver processes do not govern the credential estate that actually remains dangerous. The article shows that HR offboarding and service-desk deprovisioning can finish cleanly while NHIs, keys, and secrets stay active. That is not a gap in user lifecycle management alone; it is a lifecycle mismatch between human processes and machine credentials. The practitioner conclusion is that offboarding governance must include the identities the employee could expose, not only the identity the employee owned.

A question worth separating out:

Q: What signals show that mover-leaver controls are missing NHI exposure?

A: Common signals include offboarding checklists that stop at human accounts, service accounts that outlive role changes, and secrets that remain valid after a departure. When those conditions appear together, the organisation is managing people cleanly but not the credentials they influenced.

👉 Read our full editorial: Offboarding exposed NHIs is the gap human IAM keeps missing


This post was modified 21 hours ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.