TL;DR: Microsoft Entra ID Privileged Identity Management works predictably inside Azure, but the article argues that cross-cloud engineering workflows create friction through static roles, activation delays, and context switching, according to Apono. That friction pushes engineers toward broader access requests and weakens least privilege as a practical control.
NHIMG editorial — based on content published by Apono: Apono vs Entra ID PIM, building privileged access engineers will actually use across cloud
By the numbers:
- Only 13% of organisations feel extremely prepared for the reality of agentic AI despite the majority racing toward autonomous adoption.
- Only 5.7% of organisations have full visibility into their service accounts.
- 71% of NHIs are not rotated within recommended time frames, increasing the risk of compromise over time.
Questions worth separating out
Q: How should security teams reduce standing privilege in multi-cloud environments?
A: Start by identifying every identity that can access more than one critical system without fresh approval.
Q: Why do static roles create risk in cloud and hybrid environments?
A: Static roles assume access intent stays stable, but cloud and hybrid environments change context constantly.
Q: What do security teams get wrong about privileged access governance?
A: They often treat PAM as the whole answer instead of one control in a wider identity programme.
Practitioner guidance
- Map access-to-task translation points Identify where engineers must infer the correct privileged role, then document where they most often request broader access because the mapping is unclear.
- Measure activation latency against real work windows Track how often five to 45 minute delays interfere with debugging, incident response, or deployment tasks, then treat repeated delay as a governance defect.
- Unify privileged request paths Provide a consistent request experience across Azure, AWS, Kubernetes, and SaaS so privilege decisions are made in one workflow rather than many disconnected ones.
What's in the full article
Apono's full comparison covers the operational detail this post intentionally leaves for the source:
- Workflow-specific request paths across Slack, Teams, CLI, Backstage, and AI-assisted interfaces.
- How dynamic provisioning behaves when access must be extended without restarting the approval process.
- The practical differences between Azure-native eligibility models and cross-cloud runtime access delivery.
- Why engineers choose broader eligibility when activation delays interrupt live work.
👉 Read Apono's comparison of Entra PIM and cross-cloud privileged access design →
Entra PIM across cloud environments: where least privilege breaks down?
Explore further
Cross-cloud privileged access friction is a governance failure, not a user-experience nuisance. When engineers must translate intent into cloud-specific roles, they naturally optimise for speed and certainty. That shifts the burden from precise access design to workarounds, and least privilege becomes conditional on how much delay the control introduces. The practitioner conclusion is that access control quality is now measured by whether it survives real engineering workflows.
A few things that frame the scale:
- Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
- 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools, according to Ultimate Guide to NHIs.
A question worth separating out:
Q: Who is accountable when engineers bypass the approved privileged access path?
A: Accountability sits with the identity and platform teams that designed the access experience as much as with the engineer who took the shortcut. If the governance model is too slow, too fragmented, or too console-bound, the organisation has created the conditions for bypass. Frameworks such as the NIST Cybersecurity Framework 2.0 and NIST SP 800-53 both support that accountability view.
👉 Read our full editorial: Entra PIM friction in cross-cloud access governance