<?xml version="1.0" encoding="UTF-8"?>        <rss version="2.0"
             xmlns:atom="http://www.w3.org/2005/Atom"
             xmlns:dc="http://purl.org/dc/elements/1.1/"
             xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
             xmlns:admin="http://webns.net/mvcb/"
             xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
             xmlns:content="http://purl.org/rss/1.0/modules/content/">
        <channel>
            <title>
									NHIMG Forum - Recent Topics				            </title>
            <link>https://nhimg.org/community/</link>
            <description>NHIMG Discussion Board</description>
            <language>en-US</language>
            <lastBuildDate>Tue, 02 Jun 2026 16:17:24 +0000</lastBuildDate>
            <generator>wpForo</generator>
            <ttl>60</ttl>
							                    <item>
                        <title>ERP access governance: what security teams miss at go-live</title>
                        <link>https://nhimg.org/community/nhi-support-guidance-forum/erp-access-governance-what-security-teams-miss-at-go-live/</link>
                        <pubDate>Tue, 02 Jun 2026 12:59:18 +0000</pubDate>
                        <description><![CDATA[TL;DR: ERP implementations often copy legacy access, rely on broad roles, and defer compliance work until late-stage testing, which increases SoD conflicts and audit findings, according to D...]]></description>
                        <content:encoded><![CDATA[<blockquote>
<p><strong>TL;DR:</strong> ERP implementations often copy legacy access, rely on broad roles, and defer compliance work until late-stage testing, which increases SoD conflicts and audit findings, according to Delinea. Treating security as a design input instead of a phase-two task is now the difference between controlled go-live and expensive remediation.</p>
</blockquote>
<p><em>NHIMG editorial — based on content published by Delinea: Include security and compliance from the start of ERP implementations</em></p>
<p><strong>By the numbers:</strong></p>
<ul>
<li>The organization was able to <a href="https://delinea.com/blog/why-build-security-and-compliance-into-erp-from-day-one?utm_source=nhimg&amp;utm_medium=NHIForum">reduce SoD conflicts at go-live by about 85%</a> compared to the initial design baseline.</li>
<li>The organization also <a href="https://delinea.com/blog/why-build-security-and-compliance-into-erp-from-day-one?utm_source=nhimg&amp;utm_medium=NHIForum">saved an estimated 60-70% in post-go-live remediation efforts</a>.</li>
</ul>
<h2>Questions worth separating out</h2>
<p><strong>Q: <a href="https://nhimg.org/faq/how-should-security-teams-implement-erp-access-governance-before-go-live/?utm_source=nhimg&amp;utm_medium=NHIForum">How should security teams implement ERP access governance before go-live?</a></strong></p>
<p><strong>A:</strong> Start with a defined access governance framework that assigns ownership, approval paths, and provisioning rules before implementation is complete.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/why-do-erp-projects-create-hidden-nhi-risk/?utm_source=nhimg&amp;utm_medium=NHIForum">Why do ERP projects create hidden NHI risk?</a></strong></p>
<p><strong>A:</strong> ERP projects create hidden NHI risk because batch jobs, integration accounts, and emergency access often receive broad or poorly attributed permissions.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/what-breaks-when-organisations-copy-legacy-access-into-a-new-erp-system/?utm_source=nhimg&amp;utm_medium=NHIForum">What breaks when organisations copy legacy access into a new ERP system?</a></strong></p>
<p><strong>A:</strong> Copying legacy access preserves old privilege patterns, including broad roles and unresolved segregation of duties conflicts.</p>
<h2>Practitioner guidance</h2>
<ul>
<li><strong>Map every ERP identity type before design freezes</strong> Inventory human roles, service accounts, <a href="https://nhimg.org/the-ultimate-guide-to-non-human-identities?utm_source=nhimg&amp;utm_medium=NHIForum">batch jobs, emergency access</a>, and integration credentials, then assign an owner and business purpose to each identity.</li>
<li><strong>Design roles from process boundaries, not from legacy templates</strong> Build RBAC around end-to-end business processes and separate configuration, operations, and monitoring duties so copied access does not reintroduce SoD conflicts.</li>
<li><strong>Test access controls during UAT and sprint reviews</strong> <a href="https://nhimg.org/the-ultimate-guide-to-non-human-identities?utm_source=nhimg&amp;utm_medium=NHIForum">Validate provisioning flows</a>, privileged access, and compensating controls before cutover so role defects are found while remediation is still cheap.</li>
</ul>
<p><em>That means the control priority is not just migration success, but how much inherited access is intentionally removed before launch?</em></p>
<p>&#x1f449; <strong><a href="https://delinea.com/blog/why-build-security-and-compliance-into-erp-from-day-one?utm_source=nhimg&amp;utm_medium=NHIForum">Read Delinea’s guidance on security and compliance in ERP implementations →</a></strong></p>
<blockquote>
<p><strong>Explore further</strong></p>
<p><a href="/community/?utm_source=nhimg&amp;utm_medium=NHIForum">View Full Forum →</a>  |  <a href="/nhi-training/?utm_source=nhimg&amp;utm_medium=NHIForum">NHI Foundation Course →</a></p>
</blockquote>]]></content:encoded>
						                            <category domain="https://nhimg.org/community/"></category>                        <dc:creator>NHI Mgmt Group</dc:creator>
                        <guid isPermaLink="true">https://nhimg.org/community/nhi-support-guidance-forum/erp-access-governance-what-security-teams-miss-at-go-live/</guid>
                    </item>
				                    <item>
                        <title>NHI visibility gap in AI adoption: are your controls keeping up?</title>
                        <link>https://nhimg.org/community/agentic-ai-and-nhis/nhi-visibility-gap-in-ai-adoption-are-your-controls-keeping-up/</link>
                        <pubDate>Tue, 02 Jun 2026 12:59:07 +0000</pubDate>
                        <description><![CDATA[TL;DR: Delinea reports that 87% of organisations say their identity security posture is prepared for AI, yet 46% admit their AI identity governance is deficient and 53% regularly encounter u...]]></description>
                        <content:encoded><![CDATA[<blockquote>
<p><strong>TL;DR:</strong> Delinea reports that 87% of organisations say their identity security posture is prepared for AI, yet 46% admit their AI identity governance is deficient and 53% regularly encounter unauthorized AI tools or agents accessing company systems. The gap is not visibility alone, but the mismatch between autonomous NHI behaviour and legacy IAM controls that still assume human-paced access review.</p>
</blockquote>
<p><em>NHIMG editorial — based on content published by Delinea: The hidden risk of non-human identities in AI adoption</em></p>
<p><strong>By the numbers:</strong></p>
<ul>
<li><a href="https://delinea.com/blog/securing-non-human-identities-and-ai-agents?utm_source=nhimg&amp;utm_medium=NHIForum">87% of organizations say their identity security posture</a> is prepared.</li>
<li><a href="https://delinea.com/blog/securing-non-human-identities-and-ai-agents?utm_source=nhimg&amp;utm_medium=NHIForum">46% of those surveyed admitting that their AI identity governance</a> is deficient.</li>
<li><a href="https://delinea.com/blog/securing-non-human-identities-and-ai-agents?utm_source=nhimg&amp;utm_medium=NHIForum">53% of surveyed organizations regularly encounter unauthorized AI tools</a> and agents accessing company systems.</li>
</ul>
<h2>Questions worth separating out</h2>
<p><strong>Q: <a href="https://nhimg.org/faq/how-should-security-teams-implement-least-privilege-for-ai-agents-and-nhis/?utm_source=nhimg&amp;utm_medium=NHIForum">How should security teams implement least privilege for AI agents and NHIs?</a></strong></p>
<p><strong>A:</strong> Start by treating AI agents as a separate identity class with explicit ownership, purpose, and lifecycle records.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/why-do-nhis-complicate-zero-trust-and-least-privilege-efforts/?utm_source=nhimg&amp;utm_medium=NHIForum">Why do NHIs complicate zero trust architecture in practice?</a></strong></p>
<p><strong>A:</strong> NHIs complicate zero trust architecture because they authenticate and act at machine speed, often without the human checkpoints that zero trust programs assume.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/what-breaks-when-organisations-cannot-see-their-non-human-identities/?utm_source=nhimg&amp;utm_medium=NHIForum">What breaks when organisations cannot see their non-human identities?</a></strong></p>
<p><strong>A:</strong> When NHIs are invisible, least privilege, credential rotation, and access review all become incomplete.</p>
<h2>Practitioner guidance</h2>
<ul>
<li><strong>Implement continuous discovery for machine identities</strong> Inventory service accounts, API keys, tokens, certificates, AI agents, and shadow AI tools across cloud and hybrid environments.</li>
<li><strong>Reduce standing privilege for autonomous identities</strong> Classify every persistent entitlement held by NHIs and AI agents, then replace it with <a href="https://nhimg.org/the-ultimate-guide-to-non-human-identities?utm_source=nhimg&amp;utm_medium=NHIForum">just-in-time access where operationally possible</a>.</li>
<li><strong>Enforce access certification for NHIs</strong> Run regular access reviews on machine identities with the <a href="https://nhimg.org/the-ultimate-guide-to-non-human-identities?utm_source=nhimg&amp;utm_medium=NHIForum">same rigor used for human access</a>.</li>
</ul>
<p><em>With 70% of organisations granting AI systems more access than they would give a human employee performing the exact same job, per the 2026 Infrastructure Identity Survey, the control model is already out of balance?</em></p>
<p>&#x1f449; <strong><a href="https://delinea.com/blog/securing-non-human-identities-and-ai-agents?utm_source=nhimg&amp;utm_medium=NHIForum">Read Delinea's analysis of hidden NHI risk in AI adoption →</a></strong></p>
<blockquote>
<p><strong>Explore further</strong></p>
<p><a href="/community/?utm_source=nhimg&amp;utm_medium=NHIForum">View Full Forum →</a>  |  <a href="/nhi-training/?utm_source=nhimg&amp;utm_medium=NHIForum">NHI Foundation Course →</a></p>
</blockquote>]]></content:encoded>
						                            <category domain="https://nhimg.org/community/"></category>                        <dc:creator>NHI Mgmt Group</dc:creator>
                        <guid isPermaLink="true">https://nhimg.org/community/agentic-ai-and-nhis/nhi-visibility-gap-in-ai-adoption-are-your-controls-keeping-up/</guid>
                    </item>
				                    <item>
                        <title>Identity supply chains and cascading trust risk: what teams need now</title>
                        <link>https://nhimg.org/community/nhi-support-guidance-forum/identity-supply-chains-and-cascading-trust-risk-what-teams-need-now/</link>
                        <pubDate>Tue, 02 Jun 2026 12:58:56 +0000</pubDate>
                        <description><![CDATA[TL;DR: March’s breach pattern showed that attackers are compromising trusted identities, not perimeter controls, and then using legitimate access to move downstream, according to Delinea Lab...]]></description>
                        <content:encoded><![CDATA[<blockquote>
<p><strong>TL;DR:</strong> March’s breach pattern showed that attackers are compromising trusted identities, not perimeter controls, and then using legitimate access to move downstream, according to Delinea Labs’ April 2026 Threat Outlook. The result is a governance problem, not just an authentication problem, because identity can become the weapon once trust is inherited across tenants, partners, and automation.</p>
</blockquote>
<p><em>NHIMG editorial — based on content published by Delinea: Identity supply chains are under siege</em></p>
<p><strong>By the numbers:</strong></p>
<ul>
<li>The European Commission was among the targets when a compromised Trivy development pipeline led to <a href="https://delinea.com/blog/supply-chain-identity-risk-compounding?utm_source=nhimg&amp;utm_medium=NHIForum">approximately 340 GB of data</a> being stolen.</li>
<li>In March, <a href="https://delinea.com/blog/supply-chain-identity-risk-compounding?utm_source=nhimg&amp;utm_medium=NHIForum">5,236 CVEs were disclosed</a> across the industry, including 519 identity-related vulnerabilities.</li>
</ul>
<h2>Questions worth separating out</h2>
<p><strong>Q: <a href="https://nhimg.org/faq/how-should-security-teams-handle-trust-assumptions-in-identity-supply-chains/?utm_source=nhimg&amp;utm_medium=NHIForum">How should security teams handle trust assumptions in identity supply chains?</a></strong></p>
<p><strong>A:</strong> Security teams should assume that any trusted upstream identity can become a downstream entry point if its permissions are not continuously verified.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/why-do-service-accounts-and-other-non-human-identities-increase-breach-impact/?utm_source=nhimg&amp;utm_medium=NHIForum">Why do service accounts and other non-human identities increase breach impact?</a></strong></p>
<p><strong>A:</strong> Service accounts and other non-human identities increase breach impact because they often carry broad, persistent access and bypass interactive controls like MFA.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/what-breaks-when-administrative-identity-governance-is-weak/?utm_source=nhimg&amp;utm_medium=NHIForum">What breaks when administrative identity governance is weak?</a></strong></p>
<p><strong>A:</strong> When administrative identity governance is weak, one compromised account can change policies, wipe devices, approve access, or unlock whole environments without a second control layer.</p>
<h2>Practitioner guidance</h2>
<ul>
<li><strong>Map downstream trust relationships</strong> Inventory where admin accounts, SSO sessions, cloud roles, and service accounts can operate across tenants, vendors, and automation workflows.</li>
<li><strong>Enforce just-in-time control for high-impact actions</strong> Apply just-in-time approval to destructive operations such as device wipes, policy changes, key rotation, and role assignment.</li>
<li><strong>Govern non-human identities as identities</strong> Assign owners, set expiry, rotate credentials, and review entitlements for service accounts, API keys, and automation tokens on a recurring schedule.</li>
</ul>
<p><em>Teams that can model those links will be better positioned to stop trust cascade before it becomes incident response?</em></p>
<p>&#x1f449; <strong><a href="https://delinea.com/blog/supply-chain-identity-risk-compounding?utm_source=nhimg&amp;utm_medium=NHIForum">Read Delinea's analysis of identity supply chain compromise patterns →</a></strong></p>
<blockquote>
<p><strong>Explore further</strong></p>
<p><a href="/community/?utm_source=nhimg&amp;utm_medium=NHIForum">View Full Forum →</a>  |  <a href="/nhi-training/?utm_source=nhimg&amp;utm_medium=NHIForum">NHI Foundation Course →</a></p>
</blockquote>]]></content:encoded>
						                            <category domain="https://nhimg.org/community/"></category>                        <dc:creator>NHI Mgmt Group</dc:creator>
                        <guid isPermaLink="true">https://nhimg.org/community/nhi-support-guidance-forum/identity-supply-chains-and-cascading-trust-risk-what-teams-need-now/</guid>
                    </item>
				                    <item>
                        <title>SAP npm supply chain incident: what it means for build security</title>
                        <link>https://nhimg.org/community/nhi-breaches/sap-npm-supply-chain-incident-what-it-means-for-build-security/</link>
                        <pubDate>Tue, 02 Jun 2026 12:58:46 +0000</pubDate>
                        <description><![CDATA[TL;DR: Malicious npm packages used in SAP CAP and MTA build workflows executed during dependency installation, targeting developer machines, CI/CD runners, build containers, and repositories...]]></description>
                        <content:encoded><![CDATA[<blockquote>
<p><strong>TL;DR:</strong> Malicious npm packages used in SAP CAP and MTA build workflows executed during dependency installation, targeting developer machines, CI/CD runners, build containers, and repositories for secrets, tokens, and cloud credentials, according to Pathlock and SAP Security Note 3747787. The incident shows that SAP security now has to cover the software supply chain that builds and deploys extensions, not just the application stack.</p>
</blockquote>
<p><em>NHIMG editorial — based on content published by Pathlock: SAP npm supply chain incident affecting CAP and MTA build workflows</em></p>
<p><strong>By the numbers:</strong></p>
<ul>
<li><a href="https://pathlock.com/blog/security-alerts/sap-npm-supply-chain-incident-malicious-packages-impact-cap-mta/?utm_source=nhimg&amp;utm_medium=NHIForum">28.65 million new hardcoded secrets</a> were detected in public GitHub commits in 2025 alone, a 34% year-over-year increase and the largest single-year jump ever recorded.</li>
</ul>
<h2>Questions worth separating out</h2>
<p><strong>Q: <a href="https://nhimg.org/faq/how-should-security-teams-contain-a-supply-chain-incident-in-build-environments/?utm_source=nhimg&amp;utm_medium=NHIForum">How should security teams contain a supply chain incident in build environments?</a></strong></p>
<p><strong>A:</strong> Containment starts with identifying every runner, workstation, cache, and container image that resolved the affected package versions.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/why-do-build-pipelines-create-such-a-large-nhi-risk/?utm_source=nhimg&amp;utm_medium=NHIForum">Why do build pipelines create such a large NHI risk?</a></strong></p>
<p><strong>A:</strong> Build pipelines often hold service accounts, deployment tokens, registry credentials, and cloud keys that allow software to move from code to production.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/what-breaks-when-secrets-are-stored-on-ci-runners-and-developer-machines/?utm_source=nhimg&amp;utm_medium=NHIForum">What breaks when secrets are stored on CI runners and developer machines?</a></strong></p>
<p><strong>A:</strong> Secrets on shared or long-lived runners break the assumption that installation is a harmless administrative step.</p>
<h2>Practitioner guidance</h2>
<ul>
<li><strong>Map all affected build and developer hosts</strong> Identify every workstation, CI runner, container image, and cache that installed the malicious package versions or resolved them through lockfiles, mirrors, or dependency updates.</li>
<li><strong>Rotate credentials reachable from the blast radius</strong> Revoke and recreate <a href="https://nhimg.org/nhi-lifecycle-management-guide?utm_source=nhimg&amp;utm_medium=NHIForum">GitHub tokens, npm tokens</a>, cloud keys, SAP BTP service keys, Kubernetes credentials, and any deployment secrets present on exposed hosts.</li>
<li><strong>Review repository and workflow tampering</strong> Search for unauthorized repositories, branch pushes, workflow edits, .vscode tasks, and .claude files that may indicate persistence or propagation attempts.</li>
</ul>
<p><em>With 24,008 unique secrets exposed in MCP configuration files in 2025 alone, the broader pattern is clear: machine-readable trust material is proliferating faster than most governance programmes can track it?</em></p>
<p>&#x1f449; <strong><a href="https://pathlock.com/blog/security-alerts/sap-npm-supply-chain-incident-malicious-packages-impact-cap-mta/?utm_source=nhimg&amp;utm_medium=NHIForum">Read Pathlock's analysis of the SAP npm supply chain incident →</a></strong></p>
<blockquote>
<p><strong>Explore further</strong></p>
<p><a href="/community/?utm_source=nhimg&amp;utm_medium=NHIForum">View Full Forum →</a>  |  <a href="/nhi-training/?utm_source=nhimg&amp;utm_medium=NHIForum">NHI Foundation Course →</a></p>
</blockquote>]]></content:encoded>
						                            <category domain="https://nhimg.org/community/"></category>                        <dc:creator>NHI Mgmt Group</dc:creator>
                        <guid isPermaLink="true">https://nhimg.org/community/nhi-breaches/sap-npm-supply-chain-incident-what-it-means-for-build-security/</guid>
                    </item>
				                    <item>
                        <title>EU AI Act and AI governance: what controls do teams need now?</title>
                        <link>https://nhimg.org/community/agentic-ai-and-nhis/eu-ai-act-and-ai-governance-what-controls-do-teams-need-now/</link>
                        <pubDate>Tue, 02 Jun 2026 12:58:36 +0000</pubDate>
                        <description><![CDATA[TL;DR: The EU AI Act applies to organisations that place AI systems or general-purpose AI models on the EU market, put them into service, or use them in the EU, and it sets staggered obligat...]]></description>
                        <content:encoded><![CDATA[<blockquote>
<p><strong>TL;DR:</strong> The EU AI Act applies to organisations that place AI systems or general-purpose AI models on the EU market, put them into service, or use them in the EU, and it sets staggered obligations from February 2025 through August 2027, according to Delinea. Policy alone is not enough; identity visibility, access control, and auditability now determine whether AI can be governed in motion.</p>
</blockquote>
<p><em>NHIMG editorial — based on content published by Delinea: EU and AI, what you need to know about AI regulations</em></p>
<p><strong>By the numbers:</strong></p>
<ul>
<li><a href="https://delinea.com/blog/eu-and-ai-regulations-what-you-need-to-know?utm_source=nhimg&amp;utm_medium=NHIForum">56% of organizations reported</a> that shadow AI incidents are occurring on a monthly basis.</li>
<li>The EU AI Act entered into force on August 1, 2024, with most of the broader regime applying from <a href="https://delinea.com/blog/eu-and-ai-regulations-what-you-need-to-know?utm_source=nhimg&amp;utm_medium=NHIForum">August 2, 2026</a>.</li>
<li>The Regulation sets thresholds up to <a href="https://delinea.com/blog/eu-and-ai-regulations-what-you-need-to-know?utm_source=nhimg&amp;utm_medium=NHIForum">€35 million or 7%</a> of worldwide annual turnover for certain infringements.</li>
</ul>
<h2>Questions worth separating out</h2>
<p><strong>Q: <a href="https://nhimg.org/faq/how-should-security-teams-govern-ai-agents-that-can-access-enterprise-systems/?utm_source=nhimg&amp;utm_medium=NHIForum">How should security teams govern AI systems that can act on sensitive data?</a></strong></p>
<p><strong>A:</strong> Security teams should treat AI systems as non-human identities with scoped access, named ownership, and full logging.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/when-does-ai-governance-become-an-iam-and-nhi-problem/?utm_source=nhimg&amp;utm_medium=NHIForum">Why do AI systems complicate IAM and NHI governance?</a></strong></p>
<p><strong>A:</strong> AI systems complicate IAM and NHI governance because they blur the line between user, workload, and automated actor.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/what-breaks-when-ai-agents-are-not-inventoried-or-classified/?utm_source=nhimg&amp;utm_medium=NHIForum">What breaks when AI agents are not inventoried or classified?</a></strong></p>
<p><strong>A:</strong> When AI agents are not inventoried or classified, organisations lose the ability to assign risk, apply the right obligations, and prove control to auditors.</p>
<h2>Practitioner guidance</h2>
<ul>
<li><strong>Inventory every AI touchpoint</strong> Map internal assistants, embedded SaaS features, developer tools, and third-party models to business owner, data scope, and regulatory role.</li>
<li><strong>Bind each AI workflow to a named identity</strong> Use scoped non-human identities, temporary tokens, and <a href="https://nhimg.org/the-ultimate-guide-to-non-human-identities?utm_source=nhimg&amp;utm_medium=NHIForum">identity-context logging</a> so every AI action can be traced back to an owner and purpose.</li>
<li><strong>Classify use cases before you classify tools</strong> Start with the business function, the sensitivity of the data, and the consequence of failure, then decide whether the AI activity falls into transparency, deployer, or high-risk obligations.</li>
</ul>
<p><em>Teams should prepare for AI identities to be reviewed like privileged workloads, not like policy exceptions?</em></p>
<p>&#x1f449; <strong><a href="https://delinea.com/blog/eu-and-ai-regulations-what-you-need-to-know?utm_source=nhimg&amp;utm_medium=NHIForum">Read Delinea's analysis of the EU AI Act and AI governance controls →</a></strong></p>
<blockquote>
<p><strong>Explore further</strong></p>
<p><a href="/community/?utm_source=nhimg&amp;utm_medium=NHIForum">View Full Forum →</a>  |  <a href="/nhi-training/?utm_source=nhimg&amp;utm_medium=NHIForum">NHI Foundation Course →</a></p>
</blockquote>]]></content:encoded>
						                            <category domain="https://nhimg.org/community/"></category>                        <dc:creator>NHI Mgmt Group</dc:creator>
                        <guid isPermaLink="true">https://nhimg.org/community/agentic-ai-and-nhis/eu-ai-act-and-ai-governance-what-controls-do-teams-need-now/</guid>
                    </item>
				                    <item>
                        <title>Federal zero trust and NHI sprawl: where execution breaks down</title>
                        <link>https://nhimg.org/community/nhi-support-guidance-forum/federal-zero-trust-and-nhi-sprawl-where-execution-breaks-down/</link>
                        <pubDate>Tue, 02 Jun 2026 12:58:04 +0000</pubDate>
                        <description><![CDATA[TL;DR: Federal zero trust efforts are stalling because agencies cannot continuously govern privileged identities, legacy systems resist modern controls, and NHIs are multiplying faster than ...]]></description>
                        <content:encoded><![CDATA[<blockquote>
<p><strong>TL;DR:</strong> Federal zero trust efforts are stalling because agencies cannot continuously govern privileged identities, legacy systems resist modern controls, and NHIs are multiplying faster than inventories and rotation processes can keep up, according to Delinea. The operational gap, not the policy gap, now determines whether zero trust becomes real.</p>
</blockquote>
<p><em>NHIMG editorial — based on content published by Delinea: Federal zero trust: Turn stalled strategy into execution</em></p>
<p><strong>By the numbers:</strong></p>
<ul>
<li>The rapid growth of NHIs compounds this problem, as service accounts, application credentials, machine-to-machine tokens, scheduled task credentials, and database connection strings <a href="https://delinea.com/blog/federal-zero-trust?utm_source=nhimg&amp;utm_medium=NHIForum">outnumber human identities by at least 10 to 1</a> in most environments.</li>
<li><a href="https://nhimg.org/the-ultimate-guide-to-non-human-identities?utm_source=nhimg&amp;utm_medium=NHIForum#key-research-and-survey-results">Only 5.7% of organisations</a> have full visibility into their service accounts.</li>
<li><a href="https://nhimg.org/the-ultimate-guide-to-non-human-identities?utm_source=nhimg&amp;utm_medium=NHIForum#key-research-and-survey-results">71% of NHIs are not rotated</a> within recommended time frames, increasing the risk of compromise over time.</li>
</ul>
<h2>Questions worth separating out</h2>
<p><strong>Q: <a href="https://nhimg.org/faq/how-should-security-teams-implement-zero-trust-for-non-human-identities-in-feder/?utm_source=nhimg&amp;utm_medium=NHIForum">How should security teams implement zero trust for non-human identities in federal environments?</a></strong></p>
<p><strong>A:</strong> Start with an inventory of all privileged NHIs, then assign owners, remove standing access where possible, and enforce short-lived credentials with automated rotation.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/why-do-non-human-identities-complicate-zero-trust-architecture/?utm_source=nhimg&amp;utm_medium=NHIForum">Why do non-human identities complicate zero trust architectures?</a></strong></p>
<p><strong>A:</strong> NHIs complicate zero trust because they multiply faster than human identities, are often overprivileged, and are frequently ignored in access reviews.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/what-breaks-when-privileged-access-is-not-continuously-governed/?utm_source=nhimg&amp;utm_medium=NHIForum">What breaks when privileged access is not continuously governed?</a></strong></p>
<p><strong>A:</strong> When privileged access is not continuously governed, standing privilege persists, dormant accounts remain usable, and the attack surface expands across human and machine identities.</p>
<h2>Practitioner guidance</h2>
<ul>
<li><strong>Inventory every privileged identity</strong> Build a current register of human and non-human <a href="https://nhimg.org/the-ultimate-guide-to-non-human-identities?utm_source=nhimg&amp;utm_medium=NHIForum">privileged accounts, including service accounts</a>, scheduled tasks, tokens, and local admin paths.</li>
<li><strong>Wrap legacy systems with compensating controls</strong> Map systems that cannot support modern authentication or policy enforcement, then apply compensating controls such as tighter segmentation, narrower privileges, and monitored jump paths.</li>
<li><strong>Automate rotation and revocation for machine credentials</strong> Move NHIs onto explicit <a href="https://nhimg.org/nhi-lifecycle-management-guide?utm_source=nhimg&amp;utm_medium=NHIForum">lifecycle processes for issuance, rotation, and offboarding</a>.</li>
</ul>
<p><em>The next funding cycle should favor inventory, ownership, and rotation capabilities before additional policy orchestration?</em></p>
<p>&#x1f449; <strong><a href="https://delinea.com/blog/federal-zero-trust?utm_source=nhimg&amp;utm_medium=NHIForum">Read Delinea's analysis of why federal zero trust is stalling on execution →</a></strong></p>
<blockquote>
<p><strong>Explore further</strong></p>
<p><a href="/community/?utm_source=nhimg&amp;utm_medium=NHIForum">View Full Forum →</a>  |  <a href="/nhi-training/?utm_source=nhimg&amp;utm_medium=NHIForum">NHI Foundation Course →</a></p>
</blockquote>]]></content:encoded>
						                            <category domain="https://nhimg.org/community/"></category>                        <dc:creator>NHI Mgmt Group</dc:creator>
                        <guid isPermaLink="true">https://nhimg.org/community/nhi-support-guidance-forum/federal-zero-trust-and-nhi-sprawl-where-execution-breaks-down/</guid>
                    </item>
				                    <item>
                        <title>OT privileged access controls: how do teams reduce risk without downtime?</title>
                        <link>https://nhimg.org/community/nhi-support-guidance-forum/ot-privileged-access-controls-how-do-teams-reduce-risk-without-downtime/</link>
                        <pubDate>Thu, 28 May 2026 11:39:34 +0000</pubDate>
                        <description><![CDATA[TL;DR: Operational technology environments keep privileged access in place longer than enterprise IT usually would, because availability, vendor support, and maintenance windows limit how fa...]]></description>
                        <content:encoded><![CDATA[<blockquote>
<p><strong>TL;DR:</strong> Operational technology environments keep privileged access in place longer than enterprise IT usually would, because availability, vendor support, and maintenance windows limit how fast controls can change, according to Delinea. The governance problem is not just access volume but accumulated exception paths, making blast-radius control the practical priority for OT teams.</p>
</blockquote>
<p><em>NHIMG editorial — based on content published by Delinea: Securing privileged access in OT without disrupting operations</em></p>
<h2>Questions worth separating out</h2>
<p><strong>Q: <a href="https://nhimg.org/faq/how-should-security-teams-reduce-privileged-access-risk-in-ot-without-causing-do/?utm_source=nhimg&amp;utm_medium=NHIForum">How should security teams reduce privileged access risk in OT without causing downtime?</a></strong></p>
<p><strong>A:</strong> Start with the access paths that create the largest blast radius, not the ones that are easiest to change.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/when-does-privileged-access-in-ot-become-a-governance-problem-rather-than-an-ope/?utm_source=nhimg&amp;utm_medium=NHIForum">When does privileged access in OT become a governance problem rather than an operations issue?</a></strong></p>
<p><strong>A:</strong> It becomes a governance problem when access persists by habit instead of by documented need.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/what-is-the-difference-between-session-monitoring-and-least-privilege-in-ot/?utm_source=nhimg&amp;utm_medium=NHIForum">What is the difference between session monitoring and least privilege in OT?</a></strong></p>
<p><strong>A:</strong> Session monitoring shows what an authenticated user did after access was granted, while least privilege limits what that user can do in the first place.</p>
<h2>Practitioner guidance</h2>
<ul>
<li><strong>Map every privileged access path</strong> Inventory shared administrator accounts, service accounts, remote vendor tools, jump hosts, and engineering workstation elevation paths.</li>
<li><strong>Move static credentials into controlled rotation</strong> Place privileged credentials under <a href="https://nhimg.org/nhi-lifecycle-management-guide?utm_source=nhimg&amp;utm_medium=NHIForum">centralized vaulting and enforce rotation</a> schedules that fit plant operations.</li>
<li><strong>Broker and record remote sessions</strong> Require controlled access paths for third-party and internal remote support, with proxied sessions, activity logging, and recording enabled by default.</li>
</ul>
<p><em>Teams that can measure account ownership, session evidence, and task-scoped elevation will be able to reduce risk without forcing unsafe standardisation?</em></p>
<p>&#x1f449; <strong><a href="https://delinea.com/blog/securing-privileged-access-in-operation-technology-ot?utm_source=nhimg&amp;utm_medium=NHIForum">Read Delinea's analysis of privileged access control in OT →</a></strong></p>
<blockquote>
<p><strong>Explore further</strong></p>
<p><a href="/community/?utm_source=nhimg&amp;utm_medium=NHIForum">View Full Forum →</a>  |  <a href="/nhi-training/?utm_source=nhimg&amp;utm_medium=NHIForum">NHI Foundation Course →</a></p>
</blockquote>]]></content:encoded>
						                            <category domain="https://nhimg.org/community/"></category>                        <dc:creator>NHI Mgmt Group</dc:creator>
                        <guid isPermaLink="true">https://nhimg.org/community/nhi-support-guidance-forum/ot-privileged-access-controls-how-do-teams-reduce-risk-without-downtime/</guid>
                    </item>
				                    <item>
                        <title>User access reviews at scale: are manual controls keeping up?</title>
                        <link>https://nhimg.org/community/nhi-support-guidance-forum/user-access-reviews-at-scale-are-manual-controls-keeping-up/</link>
                        <pubDate>Thu, 28 May 2026 11:39:24 +0000</pubDate>
                        <description><![CDATA[TL;DR: Manual user access reviews can consume hundreds of hours per cycle and still leave access creep, terminated accounts, and machine identities unchallenged, according to Delinea&#039;s analy...]]></description>
                        <content:encoded><![CDATA[<blockquote>
<p><strong>TL;DR:</strong> Manual user access reviews can consume hundreds of hours per cycle and still leave access creep, terminated accounts, and machine identities unchallenged, according to Delinea's analysis. Automation turns access certification from a spreadsheet exercise into a control that can keep pace with hybrid environments and NHI sprawl.</p>
</blockquote>
<p><em>NHIMG editorial — based on content published by Delinea: Save time and reduce risk by automating User Access Reviews</em></p>
<p><strong>By the numbers:</strong></p>
<ul>
<li>Across customer interviews, Fastpath reduced time spent on access reviews by <a href="https://delinea.com/blog/automating-user-access-reviews?utm_source=nhimg&amp;utm_medium=NHIForum">up to 80%, with some customers reporting savings of 120 hours per quarter</a>.</li>
<li>Norwegian Cruise Line Holdings had <a href="https://delinea.com/blog/automating-user-access-reviews?utm_source=nhimg&amp;utm_medium=NHIForum">450 unique reviewers, 14,000 users</a>, and approximately 300,000 lines of access across its in-scope SOX applications.</li>
</ul>
<h2>Questions worth separating out</h2>
<p><strong>Q: <a href="https://nhimg.org/faq/how-should-organisations-automate-user-access-reviews-without-weakening-control-/?utm_source=nhimg&amp;utm_medium=NHIForum">How should organisations automate user access reviews without weakening control quality?</a></strong></p>
<p><strong>A:</strong> Organisations should automate data collection, reviewer routing, reminders, remediation, and evidence capture, but keep human decision-making at the approval stage.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/when-do-user-access-reviews-become-too-risky-to-run-manually/?utm_source=nhimg&amp;utm_medium=NHIForum">When do user access reviews become too risky to run manually?</a></strong></p>
<p><strong>A:</strong> Manual reviews become too risky when the organisation has multiple systems, frequent role changes, or large volumes of human and non-human access.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/what-is-the-difference-between-access-certification-and-provisioning/?utm_source=nhimg&amp;utm_medium=NHIForum">What is the difference between access certification and provisioning?</a></strong></p>
<p><strong>A:</strong> Access certification checks whether existing access should remain in place, while provisioning grants or removes access in the source system.</p>
<h2>Practitioner guidance</h2>
<ul>
<li><strong>Map UAR scope to business risk</strong> Classify applications by data sensitivity, fraud exposure, and regulatory impact, then set review cadence accordingly.</li>
<li><strong>Automate ownership and reviewer routing</strong> Use attributes such as <a href="https://nhimg.org/top-10-non-human-identity-issues?utm_source=nhimg&amp;utm_medium=NHIForum">department, manager, location, and role ownership</a> to route certifications to the right decision-maker.</li>
<li><strong>Validate removals in the source system</strong> Do not count a campaign as complete until rejected access is <a href="https://nhimg.org/nhi-lifecycle-management-guide?utm_source=nhimg&amp;utm_medium=NHIForum">removed in the source application</a> and the change is verified.</li>
</ul>
<p><em>With 57% of organisations lacking a complete inventory of their machine identities, certification programs that do not account for non-human access will miss part of the risk surface entirely?</em></p>
<p>&#x1f449; <strong><a href="https://delinea.com/blog/automating-user-access-reviews?utm_source=nhimg&amp;utm_medium=NHIForum">Read Delinea's analysis of automating user access reviews for least privilege →</a></strong></p>
<blockquote>
<p><strong>Explore further</strong></p>
<p><a href="/community/?utm_source=nhimg&amp;utm_medium=NHIForum">View Full Forum →</a>  |  <a href="/nhi-training/?utm_source=nhimg&amp;utm_medium=NHIForum">NHI Foundation Course →</a></p>
</blockquote>]]></content:encoded>
						                            <category domain="https://nhimg.org/community/"></category>                        <dc:creator>NHI Mgmt Group</dc:creator>
                        <guid isPermaLink="true">https://nhimg.org/community/nhi-support-guidance-forum/user-access-reviews-at-scale-are-manual-controls-keeping-up/</guid>
                    </item>
				                    <item>
                        <title>Dynamics 365 access governance: are your controls keeping up?</title>
                        <link>https://nhimg.org/community/nhi-events-forum/dynamics-365-access-governance-are-your-controls-keeping-up/</link>
                        <pubDate>Thu, 28 May 2026 11:39:13 +0000</pubDate>
                        <description><![CDATA[TL;DR: Delinea’s DynamicsCon and DynamicsMinds resource roundup centers on access governance for Microsoft Dynamics 365, with emphasis on Segregation of Duties, license compliance, telemetry...]]></description>
                        <content:encoded><![CDATA[<blockquote>
<p><strong>TL;DR:</strong> Delinea’s DynamicsCon and DynamicsMinds resource roundup centers on access governance for Microsoft Dynamics 365, with emphasis on Segregation of Duties, license compliance, telemetry, and business-application risk management as identity controls strain under AI adoption and broader operational complexity. The underlying issue is not feature breadth but whether governance teams can still see, prove, and enforce access decisions fast enough.</p>
</blockquote>
<p><em>NHIMG editorial — here’s why we think this discussion matters</em></p>
<p><strong>By the numbers:</strong></p>
<ul>
<li>Delinea's 2026 Identity Security Report confirms that <a href="https://delinea.com/events/collateral/dynamics-2026-resource-toolkit?utm_source=nhimg&amp;utm_medium=NHIForum">AI adoption is rapidly outpacing identity controls</a>.</li>
<li>For <a href="https://delinea.com/events/collateral/dynamics-2026-resource-toolkit?utm_source=nhimg&amp;utm_medium=NHIForum">over 20 years, organizations have relied</a> on Fastpath, now part of Delinea, for strong internal controls, such as Segregation of Duties (SoD), in Microsoft Dynamics and across other critical business applications to reduce risk and maintain compliance.</li>
<li>Fastpath solutions integrate with <a href="https://delinea.com/events/collateral/dynamics-2026-resource-toolkit?utm_source=nhimg&amp;utm_medium=NHIForum">Dynamics 365 Finance &amp; Supply Chain, Business Central, Customer Engagement</a>, and with Dynamics AX and Dynamics GP.</li>
</ul>
<h2>Questions worth separating out</h2>
<p><strong>Q: <a href="https://nhimg.org/faq/how-should-teams-govern-access-in-dynamics-365-environments/?utm_source=nhimg&amp;utm_medium=NHIForum">How should teams govern access in Dynamics 365 environments?</a></strong></p>
<p><strong>A:</strong> Start with business transactions, not directory roles.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/why-do-enterprise-applications-complicate-iam-more-than-standard-user-directorie/?utm_source=nhimg&amp;utm_medium=NHIForum">Why do enterprise applications complicate IAM more than standard user directories?</a></strong></p>
<p><strong>A:</strong> Enterprise applications embed process logic, approvals, and data paths that directory IAM does not understand.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/what-is-the-difference-between-access-review-and-access-governance/?utm_source=nhimg&amp;utm_medium=NHIForum">What is the difference between access review and access governance?</a></strong></p>
<p><strong>A:</strong> Access review checks whether a permission still looks appropriate.</p>
<h2>Practitioner guidance</h2>
<ul>
<li><strong>Map SoD conflicts to business transactions</strong> Identify the specific Dynamics 365 actions that should never be held by the same identity, then test roles and exceptions against those combinations before production approval.</li>
<li><strong>Use telemetry to remove dormant access</strong> Tie access review to <a href="https://nhimg.org/the-ultimate-guide-to-non-human-identities?utm_source=nhimg&amp;utm_medium=NHIForum">observed use</a>, then revoke entitlements and licenses that show no legitimate activity over a defined review window.</li>
<li><strong>Separate human and non-human access paths</strong> Document <a href="https://nhimg.org/the-ultimate-guide-to-non-human-identities?utm_source=nhimg&amp;utm_medium=NHIForum">service accounts, integrations, and delegated admins</a> as distinct control classes so they are reviewed differently from end users.</li>
</ul>
<p><em>Dynamics environments expose how quickly access risk moves from human role management into service accounts, workflow automation, and delegated administration, which means control owners need one policy model for both people and NHIs?</em></p>
<p>&#x1f449; <strong><a href="https://delinea.com/events/collateral/dynamics-2026-resource-toolkit?utm_source=nhimg&amp;utm_medium=NHIForum">Read Delinea’s Dynamics 365 access governance resources and report →</a></strong></p>
<blockquote>
<p><strong>Explore further</strong></p>
<p><a href="/community/?utm_source=nhimg&amp;utm_medium=NHIForum">View Full Forum →</a>  |  <a href="/nhi-training/?utm_source=nhimg&amp;utm_medium=NHIForum">NHI Foundation Course →</a></p>
</blockquote>]]></content:encoded>
						                            <category domain="https://nhimg.org/community/"></category>                        <dc:creator>NHI Mgmt Group</dc:creator>
                        <guid isPermaLink="true">https://nhimg.org/community/nhi-events-forum/dynamics-365-access-governance-are-your-controls-keeping-up/</guid>
                    </item>
				                    <item>
                        <title>GRC maturity for application access governance on 2026-06-16</title>
                        <link>https://nhimg.org/community/nhi-events-forum/grc-maturity-for-application-access-governance-on-2026-06-16/</link>
                        <pubDate>Thu, 28 May 2026 11:39:03 +0000</pubDate>
                        <description><![CDATA[TL;DR: Application access governance teams often stall because they try to automate too broadly before establishing foundational controls, according to Delinea’s webinar preview on Fastpath ...]]></description>
                        <content:encoded><![CDATA[<blockquote>
<p><strong>TL;DR:</strong> Application access governance teams often stall because they try to automate too broadly before establishing foundational controls, according to Delinea’s webinar preview on Fastpath implementation, SoD, critical access monitoring, and user access reviews. The practical lesson is that phased control selection and targeted automation reduce audit risk faster than trying to modernise everything at once.</p>
</blockquote>
<p><em>NHIMG editorial — here’s why we think this discussion matters</em></p>
<p><strong>By the numbers:</strong></p>
<ul>
<li><a href="https://nhimg.org/2024-esg-report-managing-non-human-identities?utm_source=nhimg&amp;utm_medium=NHIForum">72% of organisations have experienced or suspect</a> they have experienced a breach of non-human identities.</li>
</ul>
<h2>Questions worth separating out</h2>
<p><strong>Q: <a href="https://nhimg.org/faq/how-should-organisations-prioritise-grc-controls-when-starting-application-acces/?utm_source=nhimg&amp;utm_medium=NHIForum">How should organisations prioritise GRC controls when starting application access governance?</a></strong></p>
<p><strong>A:</strong> Start with the controls that reduce risk fastest and are easiest to operationalise, usually SoD, critical access monitoring, and user access reviews.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/when-does-access-review-automation-create-more-risk-than-it-reduces/?utm_source=nhimg&amp;utm_medium=NHIForum">When does access review automation create more risk than it reduces?</a></strong></p>
<p><strong>A:</strong> Automation becomes risky when it speeds up the workflow without improving the underlying decision quality.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/what-is-the-difference-between-segregation-of-duties-and-critical-access-monitor/?utm_source=nhimg&amp;utm_medium=NHIForum">What is the difference between Segregation of Duties and critical access monitoring?</a></strong></p>
<p><strong>A:</strong> Segregation of Duties prevents conflicting actions from being combined in one identity or workflow, while critical access monitoring watches high-risk entitlements and events for inappropriate use.</p>
<h2>Practitioner guidance</h2>
<ul>
<li><strong>Prioritise foundational control domains first</strong> Start with <a href="https://nhimg.org/the-ultimate-guide-to-non-human-identities?utm_source=nhimg&amp;utm_medium=NHIForum#key-challenges-and-risks">SoD, critical access monitoring, and user access reviews</a> before expanding into broader automation.</li>
<li><strong>Map review ownership to a named control owner</strong> Assign explicit accountability for each review queue, exception path, and remediation step so the process does not stall after findings are identified.</li>
<li><strong>Automate evidence collection before expanding scope</strong> Use automation to pre-populate entitlements, approval history, and access context so reviewers can make decisions faster with fewer manual lookups.</li>
</ul>
<p><em>That same delay now defines many NHI initiatives, where inventories, ownership, and remediation cycles can fall out of sync before control owners act?</em></p>
<p>&#x1f449; <strong><a href="https://delinea.com/events/webinars/navigating-grc-journey-fastpath?utm_source=nhimg&amp;utm_medium=NHIForum">Register for Delinea's webinar on GRC maturity and application access governance →</a></strong></p>
<blockquote>
<p><strong>Explore further</strong></p>
<p><a href="/community/?utm_source=nhimg&amp;utm_medium=NHIForum">View Full Forum →</a>  |  <a href="/nhi-training/?utm_source=nhimg&amp;utm_medium=NHIForum">NHI Foundation Course →</a></p>
</blockquote>]]></content:encoded>
						                            <category domain="https://nhimg.org/community/"></category>                        <dc:creator>NHI Mgmt Group</dc:creator>
                        <guid isPermaLink="true">https://nhimg.org/community/nhi-events-forum/grc-maturity-for-application-access-governance-on-2026-06-16/</guid>
                    </item>
							        </channel>
        </rss>
		