Without full accounting coverage, the system may still authenticate users, but it cannot reliably track whether sessions are still active or have ended. That means access records become incomplete, enforcement decisions can be wrong, and administrators may see stale or partial session data. The result is weaker control over shared networks and BYOD environments.
Where the control breaks down
Full accounting coverage is what turns Wi-Fi or VPN authentication into a trustworthy access control record. When that coverage is missing, the platform may still know who authenticated, but it no longer has a dependable view of whether the session remains valid, what state that session is in, or whether the enforcement engine should still treat it as active.
This gap matters because accounting is not just reporting. It is the feedback loop that lets administrators reconcile active sessions against policy, detect stale logins, and support investigation after the fact. Without it, access decisions can drift away from reality even when the initial sign-in was valid.
Shared network access makes that failure mode more visible. A session that is no longer accurately tracked can look legitimate long after the user has moved on, disconnected, or lost the device. In practice, that creates incomplete records, delayed revocation, and weaker confidence in the control plane. NHI Mgmt Group’s Ultimate Guide to NHIs notes that only 5.7% of organisations have full visibility into their service accounts, a reminder that visibility gaps often become control gaps.
Why the failure is operationally dangerous
Without complete accounting, enforcement logic can make the wrong call in two directions. It may allow a session to continue when it should have expired, or it may force a new authentication even though an existing session is still valid. Both outcomes create friction, but the first one is the more serious security problem because it preserves access that should already have been closed.
That uncertainty also weakens investigation. If session start, continuation, and end events are incomplete, administrators cannot easily answer basic questions such as which device was active, whether a disconnect really happened, or whether the same account held multiple concurrent sessions. In BYOD and guest-heavy environments, that makes post-incident reconstruction slow and often inconclusive.
For VPNs in particular, the risk is amplified when the session is the enforcement boundary for internal resources. A stale or partial record can hide access persistence, especially when the user is roaming or switching networks. NHI Mgmt Group’s SonicWall VPN Mass Breach via Stolen Credentials illustrates how remote access controls become far more consequential once session state and credential trust are imperfectly observed.
Practitioner guidance for accounting-dependent access controls
What to verify: Confirm that the access platform emits distinct events for authentication, session establishment, session refresh or continuation, and session termination. If any of those events are absent, delayed, or not correlated to the same session identifier, treat the accounting coverage as incomplete rather than “mostly working.”
Decision rule: If the network relies on session state to permit internal access, disconnected endpoints, BYOD devices, and roaming users should be treated as higher-risk until the accounting path is proven reliable. If the system cannot tell whether a session is still live, do not assume inactivity has ended the exposure.
What good looks like: Administrators can reconcile live sessions against logs, see stale sessions close promptly, and use the records to support both enforcement and investigation. The control should answer not only “who authenticated?” but also “what is still active right now?”
Practitioner takeaway: Authentication without dependable accounting is only a partial control, because the real security decision often depends on session truth, not just sign-in truth.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST Zero Trust (SP 800-207), NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST Zero Trust (SP 800-207) | 5 — Policy Enforcement Continuity and Access Decision Consistency | Session accounting gaps weaken continuous access decisions in zero trust environments. |
| Recommendation — Correlate session state to enforcement so stale access is removed when trust conditions change. | ||
| NIST CSF 2.0 | PR.AA — Identity Management, Authentication and Access Control | The issue concerns access control state, session validity and reliable enforcement records. |
| Recommendation — Ensure access decisions are backed by continuous identity and session state monitoring. | ||
| CIS Controls v8 | 6 — Access Control Management | Missing accounting undermines control over who remains active on shared and remote access paths. |
| Recommendation — Track active sessions and revoke access when records show a session should no longer be valid. | ||
| OWASP Non-Human Identity Top 10 | NHI-03 — Visibility and Inventory | Incomplete session accounting is a visibility failure that obscures active access and control state. |
| Recommendation — Maintain complete visibility into active identities, sessions and access paths. | ||
Related resources from NHI Mgmt Group
- What breaks when unmanaged devices are allowed into internal apps without session controls?
- What breaks when organisations allow stay signed in without additional session controls?
- What breaks when organisations allow BYOD without tight session and device controls?
- What do banks get wrong when they try to cut onboarding friction without changing identity controls?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 18, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org