Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk Why do organisations need a separate process for…
Governance, Ownership & Risk

Why do organisations need a separate process for never-enrolled users?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 2, 2026 Domain: Governance, Ownership & Risk

Because the absence of an enrolled factor is not temporary noise, it is a recurring operational state. New hires, contractors, alumni, and users who never accepted a corporate app all arrive without the same proofing history. A separate process keeps recovery from becoming a guess and gives the service desk a defensible way to verify identity without relying on memory or urgency.

Why This Matters for Security Teams

A separate process for never-enrolled users matters because identity recovery is not the same as routine authentication. New hires, contractors, alumni, and users who never completed enrollment do not share the same proofing trail, so forcing them through a standard reset flow creates weak verification, service-desk guesswork, and avoidable exceptions. The operational risk is not just account lockout; it is mistaken reactivation, unauthorized access, and incomplete audit evidence.

For NHI Management Group, lifecycle discipline is central to identity governance, and the same principle applies when a human account has no enrolled factor history. The lifecycle view in the Ultimate Guide to NHIs — Lifecycle Processes for Managing NHIs shows why identity state must be handled explicitly rather than assumed. In practice, identity teams that blur enrollment recovery with first-time proofing usually discover the weakness only after a user presses the help desk for urgent access.

The issue also aligns with broader control hygiene in the NIST Cybersecurity Framework 2.0, which emphasises repeatable, documented processes instead of ad hoc approval paths. A separate never-enrolled workflow gives security, HR, and support a defensible way to decide who the user is before any factor is issued.

How It Works in Practice

Never-enrolled handling should start by classifying the request as a proofing event, not a password reset. That means the service desk follows a stronger identity verification path, then routes the user into a first-time enrolment workflow that issues the correct factor set and records the outcome. The goal is to establish a known-good identity state, not to restore access by shortcut.

Current guidance suggests separating these steps:

  • Verify the requester with evidence tied to HR, onboarding, or sponsor records.
  • Confirm whether the person ever completed factor enrolment or is truly absent from the identity system.
  • Use a controlled recovery channel for cases with prior proofing, and a distinct first-enrolment path for users with none.
  • Log the decision, verifier, evidence used, and enrolment outcome for audit and dispute handling.
  • Limit service-desk discretion so exceptions do not become the default process.

This distinction matters because a user who never enrolled has no shared recovery history to fall back on. The separate workflow reduces the temptation to reuse old credentials, answers from a colleague, or informal approvals that are hard to defend later. It also gives IAM teams a clean boundary between identity proofing, factor registration, and account activation.

In mature environments, the process should be mapped to joiner, mover, and leaver controls so that first-time enrolment is triggered by a trusted source of truth rather than by a user opening a ticket. The Ultimate Guide to NHIs — Lifecycle Processes for Managing NHIs is useful here because it reinforces a lifecycle-first mindset, even though the identity is human. These controls tend to break down in high-volume help desks where agents are measured on speed and are pressured to bypass proofing to reduce call time.

Common Variations and Edge Cases

Tighter identity proofing often increases friction, so organisations have to balance user convenience against the cost of impersonation and bad recovery decisions. That tradeoff becomes more pronounced when users are remote, contractors rotate frequently, or onboarding data arrives late from HR and sponsorship systems.

There is no universal standard for every never-enrolled scenario, but current guidance suggests treating these cases differently from lost-factor recovery in at least three situations. First, users who were never onboarded to the workforce directory need enrolment, not recovery. Second, alumni or suspended users may require identity re-verification before any new factor is issued. Third, shared-service environments may need sponsor confirmation in addition to personal identity evidence.

The strongest programs also define escalation rules for edge cases such as name mismatches, duplicate records, and missing manager approval. This is where documented policy matters more than individual judgement, because the absence of an enrolled factor does not tell support whether the user is new, inactive, or misbound to the wrong account. A clear process protects both the user and the organisation when the record is incomplete or ambiguous.

In practice, many security teams encounter identity confusion only after a support ticket has already become a time-sensitive access exception, rather than through intentional proofing at the start.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63, NIST AI RMF and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AA-01Identity proofing and enrolment workflows support controlled access decisions.
NIST SP 800-63IALIdentity assurance levels govern how strongly a user must be verified.
OWASP Non-Human Identity Top 10NHI-05Lifecycle and recovery discipline reduces identity misuse and weak fallback paths.
NIST AI RMFGOVERNGovernance is needed to define accountable, repeatable identity handling.
NIST Zero Trust (SP 800-207)AC-1Zero Trust favours explicit verification instead of implicit trust in requests.

Apply the appropriate assurance level before first-time factor enrolment or recovery.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 2, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org