Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Identity debt, 17:1 NHI sprawl, and what teams must recheck


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19563
Topic starter  

TL;DR: 38% dormant accounts, 8% orphaned identities, and 17:1 non-human-to-human identity ratios are expanding attack surface and obscuring real entitlement risk across modern enterprises, according to Veza’s 2026 State of Identity & Access Report. The lesson is that identity debt, not just access volume, is now the governance problem security teams must measure and reduce.

NHIMG editorial — based on content published by Veza: 2026 State of Identity & Access Report

By the numbers:

Questions worth separating out

Q: How should security teams reduce risk from dormant and orphaned identities?

A: Start by identifying identities with no active owner, no recent use, or no business dependency, then revoke access in order of privilege and exposure.

Q: Why do non-human identities complicate IAM governance?

A: Non-human identities complicate IAM governance because they do not behave like people.

Q: What do security teams get wrong about platform permissions?

A: They often assume a well-organised interface means a well-governed access model.

Practitioner guidance

  • Map and retire dormant identities Identify accounts with no recent business use, no current owner, or no active workflow dependency, then remove access in priority order based on privilege and network reach.
  • Build a continuous NHI inventory Track every service account, token, certificate, workload identity, and AI-related credential across cloud, code, and infrastructure pipelines, with clear ownership and expiry data.
  • Reduce entitlement noise before the next recertification cycle Normalize permissions into business-relevant roles and remove redundant grants so access reviews evaluate meaningful risk instead of raw permission volume.

What's in the full report

Veza's full report covers the operational detail this post intentionally leaves for the source:

  • Role-by-role breakdowns of identity debt across human and non-human populations
  • Source dataset context on entitlements, access patterns, and identity exposure trends
  • Implementation details for measuring dormant accounts, orphaned identities, and permission sprawl
  • Benchmarks that help teams compare their own identity posture against the report’s findings

👉 Read Veza's 2026 State of Identity & Access Report →

Identity debt, 17:1 NHI sprawl, and what teams must recheck?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19154
 

Identity debt is now a governance failure, not a housekeeping issue. The report shows that dormant accounts, orphaned identities, and permission sprawl are accumulating faster than organisations can certify or remove them. That means identity programmes are no longer failing only at the margins. They are losing track of the live access estate itself, which makes identity debt a board-level control problem rather than an operational clean-up task.

A few things that frame the scale:

  • 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface, according to Ultimate Guide to NHIs.
  • Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.

A question worth separating out:

Q: How should organisations measure whether identity governance is actually working?

A: Organisations should measure whether governance reduces incident cost, manual workload, and time to detect or contain risky access. If the only visible improvement is fewer tools, the programme may not be effective. Strong governance shows up in faster policy enforcement, clearer ownership, and fewer unreviewed access paths.

👉 Read our full editorial: 2026 identity debt and NHI sprawl are widening enterprise risk



   
ReplyQuote
Share: