TL;DR: Cloud service providers entering Saudi Arabia and the UAE face compliance pressure not just on data location, but on how identities, privileged access, third parties, and audit evidence are controlled across region-specific environments, according to Teleport and Coalfire. Long-lived credentials, VPNs, bastions, and fragmented access controls turn identity governance into a regulator-facing evidence problem, not just an operational one.
NHIMG editorial — based on content published by Teleport: Navigating SAMA, ADGM and DFSA Requirements with Teleport
Questions worth separating out
Q: How should security teams implement just-in-time privileged access in cloud environments?
A: Start with the most sensitive administrative paths, then require approval, session bounds, and automatic expiry for each elevation event.
Q: Why do long-lived machine credentials increase cloud risk?
A: Long-lived machine credentials create standing privilege, which gives attackers a reusable access path if the secret is exposed.
Q: What breaks when privileged access is split across multiple tools and platforms?
A: The evidence chain breaks first.
Practitioner guidance
- Map every privileged access path to an audit owner Document who approves, who reviews, and who can revoke access for each privileged path, including third parties and machine accounts.
- Replace persistent administrative access with session-scoped access Use just-in-time elevation, short-lived certificates, and per-session MFA so privileged access expires with the task.
- Centralize logs across cloud, on-premises, and third-party paths Require a single reviewable trail for approvals, authentication events, privilege use, and revocation outcomes.
👉 Read Teleport's analysis of SAMA, ADGM, and DFSA identity requirements →
SAMA, ADGM and DFSA compliance: are your identity controls auditable?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
Identity governance, not data locality, is the real compliance battleground. The article correctly frames sovereign cloud rules as an access and evidence problem rather than a storage-only problem. SAMA, ADGM, and DFSA all care about who can act, how access is approved, and whether the activity can be proven later. That means identity architecture is now part of regulatory design, not a separate operational layer. Practitioners should treat access traceability as a control objective in its own right.
A few things that frame the scale:
- 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, according to The State of Non-Human Identity Security.
- Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared with nearly 1 in 4 for securing human identities.
A question worth separating out:
Q: Who is accountable when a third-party identity can reach critical infrastructure?
A: Accountability sits with the organisation that allows the trust path to exist and remain active. Security teams should require documented access ownership, test revocation, and verify that supplier access is auditable across the full lifecycle, not just at onboarding.
👉 Read our full editorial: SAMA, ADGM and DFSA compliance exposes identity control gaps