Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Remote workforce identity risk: are your controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20377
Topic starter  

TL;DR: Remote and hybrid work expand identity attack paths through phishing, VPN credential theft, SaaS OAuth abuse, and shadow IT, and Expel argues that ITDR closes those gaps with behavioral baselines, device fingerprinting, and continuous SaaS monitoring. The deeper issue is that perimeter-era controls still assume identity is stable enough to trust, while distributed work makes trust conditional and constantly testable.

NHIMG editorial — based on content published by Expel: ITDR and remote workforce identity risk

Questions worth separating out

Q: How should security teams reduce identity risk in remote workforce environments?

A: Security teams should reduce the number of resources each remote identity can reach, then align MFA, device posture, and access reviews with how people actually work.

Q: Why does remote work make OAuth abuse more dangerous?

A: Remote work makes OAuth abuse more dangerous because SaaS access becomes the operational backbone, so a compromised grant can move laterally across business apps without a fresh login event.

Q: What breaks when identity monitoring only looks at network location?

A: Network-only monitoring breaks because remote users no longer share a stable office perimeter, and attackers can authenticate from anywhere once credentials are stolen.

Practitioner guidance

  • Map remote identity trust assumptions to actual access paths Document where your programme still assumes users are on trusted networks, then compare that assumption with VPN, SaaS, and browser-based access patterns.
  • Inventory OAuth grants and app consents across the SaaS estate Pull consent records from your identity provider and SaaS platforms, then identify apps with broad scopes, inactive owners, or no expiry review.
  • Tune behavioural baselines per user and role Separate frequent travellers, contractors, and fixed-location staff into different behavioural expectations so impossible travel, device changes, and login timing are judged in context.

What's in the full article

Expel's full article covers the operational detail this post intentionally leaves for the source:

  • Specific examples of how ITDR spots phishing, VPN theft, SaaS OAuth abuse, and shadow IT in remote environments.
  • Control-by-control comparison of behavioral baselines, impossible travel detection, device fingerprinting, and SaaS monitoring.
  • Practical guidance on what response actions can be automated when suspicious identity activity is detected.
  • Implementation considerations for organisations running Entra ID, Okta, or hybrid identity environments.

👉 Read Expel's analysis of ITDR for remote and hybrid workforce identity risk →

Remote workforce identity risk: are your controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19968
 

Continuous verification matters more than network location because remote work invalidates the old trust boundary. Security programmes that still rely on office IPs, managed subnets, or fixed access zones are already behind the operating model. Zero Trust Architecture only holds when identity signals are current enough to support every access decision, which is why ITDR belongs in the enforcement layer rather than the edge network. Practitioners should treat identity telemetry as a core control surface, not an optional detector.

A few things that frame the scale:

  • 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, according to The State of Non-Human Identity Security.
  • Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities.

A question worth separating out:

Q: Who is accountable when a non-human actor abuses delegated SaaS access?

A: Accountability should sit with the business owner of the integration, the platform team that approved the grant, and the security function that monitors its use. If no one owns the delegation lifecycle, then the organisation has created access that can persist without meaningful oversight.

👉 Read our full editorial: ITDR for remote workforces: closing the identity trust gap



   
ReplyQuote
Share: