Dormant accounts and over-privileged access expand the blast radius of a single compromise. Attackers often log in with valid credentials, then move laterally or escalate privileges using accounts that were never removed or never scoped down. Organisations should prioritise revocation, least privilege, and continuous review because identity sprawl turns routine access into an attack surface.
Why Dormant Accounts Become High-Risk Identity Assets
Dormant accounts are not harmless leftovers. They are valid identities that often keep old group membership, cached tokens, service bindings, or forgotten API access long after the original business need has ended. That makes them ideal for attackers who prefer to log in rather than break in. The risk is amplified when organisations treat identity as a one-time provisioning task instead of a continuously managed control surface. NHIMG research shows that 97% of NHIs carry excessive privileges, and 71% are not rotated within recommended time frames, which helps explain why compromise so often turns into lateral movement. See Ultimate Guide to NHIs and the OWASP Non-Human Identity Top 10 for the underlying risk pattern.
Once a dormant account is discovered, an attacker does not need to defeat perimeter controls first. They inherit whatever the account can reach, including admin consoles, storage, CI/CD, SaaS admin functions, or internal APIs. In practice, identity abuse becomes harder to contain because the account already looks legitimate to logging, authorization, and monitoring systems. Security teams usually find this only after an access review, breach investigation, or unusual billing event has already exposed the account.
How Excess Privilege Turns a Single Login into Broad Access
Excessive privileges multiply impact because they collapse normal separation of duties. If a service account can read production data, write configuration, and trigger deployments, compromise of that one identity can cascade across workloads. The practical response is not just removal of dormant accounts, but scoping each identity to a narrow, documented purpose and continuously validating that the current permission set still matches that purpose. NIST guidance on access control in NIST SP 800-53 Rev 5 Security and Privacy Controls supports this least-privilege approach, while Ultimate Guide to NHIs — Key Challenges and Risks highlights how widespread over-permissioning is in real environments.
- Revoke accounts that no longer have an active owner or business function.
- Replace standing access with just-in-time elevation where possible.
- Separate read, write, and administrative roles instead of bundling them.
- Review service-account entitlements after every material workload change.
- Rotate secrets and tokens so old credentials cannot be reused indefinitely.
These controls work best when identities are inventoried, owners are assigned, and authorization is checked against current context rather than legacy group membership. They tend to break down in environments with shared admin accounts, unmanaged third-party integrations, or legacy automation that depends on long-lived credentials.
Common Containment Gaps Security Teams Miss
Tighter revocation often increases operational overhead, requiring organisations to balance faster containment against application stability and support effort. That tradeoff is real, but it is not a reason to preserve broad access indefinitely. The hardest cases are usually not the obvious admin accounts, but the quiet ones: old CI jobs, stale vendor accounts, backup operators, and test identities that still carry production access. Current guidance suggests treating these as active exposure points, not administrative clutter. The 52 NHI Breaches Analysis and CISA cyber threat advisories both reinforce that identity misuse often persists because defenders focus on malware or perimeter signals instead of access hygiene.
There is no universal standard for how quickly every dormant account must be removed, but best practice is evolving toward continuous attestation, short-lived credentials, and owner-based expiration. That is especially important where access is machine-to-machine or delegated through SaaS, because the original approver may no longer understand what downstream permissions still exist. In practice, containment fails when organisations assume an account is safe simply because it has not been used recently, while its privileges and tokens remain fully valid.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207), NIST SP 800-63 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | Addresses stale, over-permissioned non-human identities that expand blast radius. |
| NIST CSF 2.0 | PR.AC-1 | Supports identity proofing, access control, and least-privilege enforcement. |
| NIST Zero Trust (SP 800-207) | GV.PO-01 | Zero trust limits lateral movement when one identity is compromised. |
| NIST SP 800-63 | Identity assurance and authenticator lifecycle affect dormant credential risk. | |
| NIST AI RMF | Risk management requires continuous monitoring of access drift and misuse. |
Expire, rebind, or re-verify credentials so inactive identities do not remain trusted indefinitely.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org