TL;DR: A private credit firm secured its Azure AD non-human identities by combining auto-discovery, risk posture analysis, stale account disablement, and credential rotation, according to Oasis Security. The lesson is that NHI governance fails when inventory, entitlement review, and rotation are treated as separate projects instead of one control loop.
Editorial analysis by NHI Mgmt Group, based on content published by Oasis Security: “How a Financial Service Institution Secures Azure NHIs with Oasis Security”.
Key questions
Q: Why do Azure non-human identities become hard to govern as cloud estates grow?
A: Azure NHIs become hard to govern when discovery, ownership, access review, and rotation are split across separate processes.
Q: When should teams prioritise rotation over more visibility work for NHIs?
A: Teams should prioritise rotation once they already know which identities are active and which are stale.
Q: What breaks when stale Azure NHI accounts are left enabled?
A: Stale accounts break governance because they preserve access that no longer has a live business purpose.
Practitioner guidance
- Map every Azure NHI to an owner and purpose Create a current inventory of Azure service principals, app identities, and other NHIs, then attach business owner, technical owner, and intended use so every identity can be judged against a live purpose.
- Tie risk scoring to identity records Record usage patterns, access paths, stale status, and credential age on each identity so remediation can be prioritised from the inventory instead of from a separate report.
- Disable stale accounts as part of governance Remove NHIs that no longer have an operational purpose before rotating active credentials, so dormant access does not remain available while teams focus elsewhere.
Bottom line: The article shows that Azure NHI governance fails when discovery, risk analysis, disablement, and rotation are treated as separate tasks instead of one workflow.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Azure NHI governance breaks when inventory, risk, and lifecycle control are separated. The article shows that discovery alone did not solve the problem, and rotation alone did not solve it either. What changed was the creation of one operational loop in which identities are found, assessed, disabled if stale, and rotated if still needed. For financial services, that is the real governance unit: a continuously maintained control loop, not a collection of disconnected tasks.
A few things that frame the scale:
- NHIs outnumber human identities by 25x to 50x in modern enterprises, according to the Ultimate Guide to NHIs.
A question worth separating out:
Q: What should security teams do when NHI inventory and rotation are managed separately?
A: They should merge the workflows into one lifecycle process with a single source of truth for identity state. Separate programmes create blind spots, because an identity can be counted, reviewed, or rotated without the other controls being updated. The goal is one governed record that drives both access decisions and credential actions.
👉 Read our full editorial: Azure NHI governance in financial services: visibility, rotation, control