Teams often assume dormant accounts are harmless because they are not used daily. In practice, they are frequently under-monitored, carry outdated permissions, and escape normal lifecycle controls. That combination makes them attractive targets for spray attacks and lateral movement. Effective governance requires the same review, access minimization, and offboarding discipline used for production identities.
Why dormant and test accounts are treated as “low risk” when they are not
Dormant and test accounts look harmless because they do not generate regular user activity, but that is exactly why they are often missed. They can retain old entitlements, stale group membership, and forgotten authentication paths long after the business has stopped watching them. In identity governance, “unused” is not the same as “safe”.
Test accounts are especially prone to exception handling that never gets revisited, while dormant accounts often outlive the role, project, or person that justified them. That makes them part of the identity estate, even when no one considers them operationally active.
What makes these accounts attractive from a control perspective?
The main problem is that dormant and test accounts frequently sit outside normal review rhythms. They can keep elevated access, bypass tighter controls applied to production users, and survive beyond offboarding or application retirement. NHIMG’s IAM and IGA Basics is useful here because the governance issue is not the account label, it is whether the access, ownership, and lifecycle state are still valid.
When teams do not inventory these accounts, they lose visibility into who owns them, what they can reach, and whether the credentials behind them are still active. That is why dormant identities become a governance blind spot rather than a storage problem.
Why they become an entry path for attackers and a source of internal risk
Dormant accounts are attractive because they are less likely to trigger human scrutiny and more likely to have weak or stale controls. That creates a practical path for password spraying, credential stuffing, token abuse, and lateral movement if the account still has useful access. The Microsoft Midnight Blizzard breach is a good reminder that a legacy test account can be enough to create serious exposure when its authentication and monitoring are weak.
Teams also underestimate how often test identities are reused across environments or left with broader access than their purpose requires. NHIMG’s Top 10 NHI Issues captures the broader pattern well: visibility gaps, overprivilege, and unmanaged credentials are the recurring failure modes, and dormant or test accounts fit that pattern closely.
Risk and Threat Considerations
Dormant and test accounts are risky because they combine low oversight with potentially high privilege. If an attacker discovers one of these accounts, the account may provide a quiet foothold that survives normal detection and can be used for persistence, internal reconnaissance, or movement into more sensitive systems.
Failure mechanism: The account remains valid after its business purpose has ended, so stale permissions, weak authentication, or forgotten credentials can be abused without immediately breaking any visible process.
Impact: Organisations can lose control of an identity that still reaches production systems, making compromise harder to detect and more expensive to contain.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and OWASP API Security Top 10 address the attack and risk surface, while NIST SP 800-53 Rev 5 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Dormant and test accounts often fail because stale authenticators remain valid. |
| AC-2 — Account Management | The question is about accounts that outlive their business need and governance state. | |
| AC-6 — Least Privilege | Dormant and test accounts commonly retain access that exceeds current need. | |
| Recommendation — Rotate or revoke unused authenticators and enforce lifecycle rules for dormant accounts. Review, disable, and remove accounts that no longer have a justified purpose. Reduce retained access to the minimum required for the account's current purpose. | ||
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | Dormant accounts often persist because offboarding and retirement were never completed. |
| NHI-05 — Overprivileged NHI | Dormant and test accounts are often left with permissions broader than their role needs. | |
| NHI-07 — Long-Lived Secrets | Test and dormant accounts commonly retain secrets that remain valid too long. | |
| Recommendation — Remove or disable accounts when the business purpose ends and ownership is lost. Re-scope dormant and test accounts to the smallest viable permission set. Enforce expiry and rotation for secrets tied to dormant or test accounts. | ||
| OWASP API Security Top 10 | API2 — Broken Authentication | Stale test or dormant identities can become weak authentication paths into systems. |
| API5 — Broken Function Level Authorization | Retained privileges on dormant accounts can expose functions they should no longer reach. | |
| Recommendation — Harden authentication paths and remove any unused test identities from access routes. Verify that any remaining access is explicitly authorised and role-bound. | ||
Practitioner Guidance
What to prioritise: Treat dormant and test accounts as governed identities, not cleanup items. The first question is ownership, then access scope, then whether the account still has a justified business purpose.
What to verify: Confirm that every dormant or test account has an owner, an expiry or review date, and a clear offboarding path. If any of those are missing, the account should be handled as an unresolved exception rather than a harmless leftover.
Common mistake: Teams often review only visibly active users and assume inactivity means no risk. That misses the identities most likely to hold stale privilege and the least likely to be noticed during an incident.
Practitioner takeaway: The real governance test is whether an account still needs to exist and still deserves its access, not whether someone is currently logging in with it.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org