Common signs include accounts not using MFA, service accounts being reused for user access, identity stores outside admin control, and assets being accessed through paths that bypass ZTNA or PAM policy. Another warning sign is incomplete visibility into user, service, and device accounts. When those signals appear together, identity governance is not enforcing the intended zero trust boundary.
What Identity Signals Show Zero Trust Is Not Being Enforced?
Identity controls are failing when they still behave like perimeter controls in disguise. If MFA is absent on meaningful access paths, if shared or reused service accounts blur ownership, or if the identity store is not authoritative for access decisions, the environment is not operating as zero trust. The same is true when users can reach assets through routes that bypass ZTNA or PAM policy, because the decision point has moved away from the identity boundary.
One useful indicator is visibility. NHI Management Group research notes that only 5.7% of organisations have full visibility into their service accounts, which is a strong sign that identity governance cannot reliably support zero trust decisions. In practice, that gap often means organisations can describe their policies better than they can prove them. When those conditions cluster, the control objective exists on paper but not in the access path.
How Identity Controls Fail in Practice
Zero trust depends on continuous, context-aware verification of who or what is requesting access, what it is allowed to do, and whether that access is still justified. Identity controls fail when they are treated as a one-time login event rather than an enforcement layer. For human identities, this often appears as exceptions for legacy apps, weak MFA coverage, or overbroad role assignments. For non-human identities, the pattern is usually more severe because secrets, tokens, and service accounts can be reused far beyond their original purpose.
In a working design, the identity provider, policy engine, and enforcement points should agree on the same source of truth. If an asset can be reached without a policy evaluation, or if a privileged path sidesteps the normal control stack, the zero trust model is fragmented. That fragmentation can come from unmanaged identity stores, locally trusted accounts, stale credentials, or service accounts that are effectively shared admin backdoors. NHI Management Group’s Ultimate Guide to NHIs is useful here because it ties visibility, lifecycle control, and rotation to the practical mechanics of zero trust.
- Look for accounts that authenticate successfully but do not pass through the expected policy engine.
- Check whether privileged access is still being granted through static membership rather than current context.
- Review service accounts for reuse, undocumented ownership, or credentials that outlive the workload they were meant for.
- Confirm that logging covers user, service, and device identities with enough detail to reconstruct the access decision.
NIST’s NIST SP 800-207 Zero Trust Architecture is the clearest external reference for the model, especially where teams need to distinguish policy enforcement from simple authentication. These controls tend to break down when identity and network exceptions accumulate faster than teams can prove who still has effective access.
Where the Warning Signs Become Operationally Meaningful
Tighter identity controls often increase operational overhead, so teams need to balance enforcement against the friction caused by poor inventory, legacy dependencies, and unmanaged machine access. The key tradeoff is not convenience versus security in the abstract; it is whether the organisation can still explain, in real time, why a given identity was trusted for a given action.
Best practice is evolving, but a few edge cases matter. Legacy applications may not support modern policy checks, which can create temporary exceptions that look harmless until they become permanent. Service accounts used by automation can also appear legitimate while still violating zero trust if their credentials are long-lived, broadly scoped, or copied between systems. Similarly, if access reviews focus only on human users, the organisation may miss the larger trust gap created by machine identities and shared secrets.
If the environment has strong MFA coverage but still relies on static credentials, unmanaged local accounts, or bypass routes for admin tasks, the problem is not login strength but trust-path consistency. NIST SP 800-207 and NHI management guidance both point to the same practical lesson: zero trust fails when the control plane is partial, not when a single control is missing. Organisations usually discover this only after an exception path has become the normal way work gets done.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC — Identity Management, Authentication and Access Control | Zero trust identity failures are access-control and governance failures. |
| Recommendation — Enforce least privilege and continuous access validation across all identity types. | ||
| NIST Zero Trust (SP 800-207) | Policy Decision Point — Policy Decision Point and Enforcement | The question asks whether access decisions are truly enforced at the zero trust boundary. |
| Recommendation — Route all sensitive access through policy decisions and enforcement points. | ||
| CIS Controls v8 | 6 — Access Control Management | Repeated identity misuse, shared accounts, and bypass paths are access-control weaknesses. |
| Recommendation — Remove shared access, review exceptions, and revoke unnecessary privileged paths. | ||
| OWASP Non-Human Identity Top 10 | NHI-01 — NHI Inventory and Ownership | Service-account visibility and ownership are core non-human identity concerns. |
| NHI-03 — Secrets and Credential Management | Bypassed zero trust often depends on long-lived secrets and reusable credentials. | |
| Recommendation — Inventory every non-human identity and assign clear ownership before granting access. Rotate and scope secrets tightly so static credentials cannot outlive policy. | ||
Practitioner Guidance
What to prioritise: Start by mapping where identity decisions are actually enforced, then compare that map with the paths people, services, and automations use every day. Any access path that can still reach production without current policy evaluation should be treated as a zero trust exception, not as a tolerated convenience.
What to verify: Confirm three things before trusting the control: the identity source is authoritative, the credential is bound to a clearly owned account or workload, and the access log shows the policy decision that allowed the request. If any of those are missing, the environment may be authenticating identities without governing them.
What practitioners underestimate: The most common failure is not the absence of a control, but the accumulation of small bypasses that eventually define the real operating model. Once shared service accounts, invisible machine identities, or admin exceptions become normal, zero trust becomes a reporting label rather than an access discipline.
Practitioner takeaway: Identity controls are supporting zero trust only when every meaningful access path is both attributable and policy-checked; anything else is a partial perimeter with modern terminology.
Related resources from NHI Mgmt Group
- What are the signs that a frictionless identity experience is not working as intended?
- What are the signs that identity controls are not resilient enough for a major outage?
- Which identity controls matter most in a Zero Trust programme?
- How should teams unify zero trust controls across identity and device security?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 10, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org