TL;DR: 38% dormant accounts, 8% orphaned identities, and 17:1 non-human-to-human identity ratios are expanding attack surface and obscuring real entitlement risk across modern enterprises, according to Veza’s 2026 State of Identity & Access Report. The lesson is that identity debt, not just access volume, is now the governance problem security teams must measure and reduce.
Editorial analysis by NHI Mgmt Group, based on content published by Veza: “The State of Identity & Access Report 2026”.
By the numbers:
- 38% of dormant accounts and 8% of orphaned identities are creating a massive attack surface.
- Non-human identities outnumber human identities by a factor of 17:1.
Key questions
Q: How should teams reduce identity implementation debt in complex environments?
A: Start by identifying where lifecycle logic has been pushed into scripts, custom workflows, and external automations.
Q: Why do non-human identities make privileged access governance harder?
A: NHIs scale faster than human accounts and are often created for automation, integrations, and AI agents, which makes them easy to forget and hard to review.
Q: What breaks when access reviews ignore the data behind an entitlement?
A: What breaks is prioritisation.
Practitioner guidance
- Inventory dormant and orphaned identities continuously Track accounts that are inactive, unowned, or detached from current business roles, then flag them for lifecycle review before they become latent access paths.
- Extend governance to all non-human identities Map service accounts, API keys, tokens, certificates, and AI agents into the same ownership and review model used for human access, with explicit business purpose and expiry.
- Reduce entitlement noise with privilege-based prioritisation Rank permissions by usage, inheritance, and blast radius so review teams focus on the small set of access rights that materially change exposure.
Bottom line: Dormant accounts and orphaned identities create residual access that attackers can use long after business ownership has lapsed.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Identity debt is now a control failure, not an inventory issue. The report shows that dormant accounts, orphaned identities, and unused permissions are not abstract hygiene concerns. They create residual trust that adversaries can abuse long after business ownership has faded. The practitioner conclusion is simple: if identity governance cannot explain why access still exists, it has already lost control of the estate.
A few things that frame the scale:
- 19% of organisations give AI systems dramatically more access than human employees, nearly one in five granting unrestricted privilege, according to the 2026 Infrastructure Identity Survey.
- NHIs outnumber human identities by 25x to 50x in modern enterprises, according to the Ultimate Guide to NHIs.
A question worth separating out:
Q: How should organisations measure whether identity governance is actually working?
A: Organisations should measure whether governance reduces incident cost, manual workload, and time to detect or contain risky access. If the only visible improvement is fewer tools, the programme may not be effective. Strong governance shows up in faster policy enforcement, clearer ownership, and fewer unreviewed access paths.
👉 Read our full editorial: 2026 identity debt and NHI sprawl are widening enterprise risk