Join our Newsletter — 33% off our NHI Course
Home› Glossary› Governance, Ownership & Risk› Dormant Licence
Governance, Ownership & Risk

Dormant Licence

← Back to Glossary
By NHI Mgmt Group Updated October 8, 2026 Domain: Governance, Ownership & Risk

A dormant licence is an assigned software entitlement that shows little or no recent use but remains provisioned. In governance terms, dormant licences can indicate wasted spend, but they can also signal stale access that should be reviewed and possibly revoked.

What a dormant licence actually is

A dormant licence is not the same as a deleted account or an unassigned entitlement. It is still provisioned, which means the organisation continues to hold the right to use that software, even if the assigned user or system has not exercised it recently.

That distinction matters because dormant licences sit in the space between asset management and access governance. They can be perfectly legitimate, for example during seasonal inactivity or role changes, but they can also be the first visible sign that access has outlived its business need.

In practice, the term is most useful when it is tied to observation, not assumption. Low usage may reflect genuine inactivity, infrequent but valid use, or a stale assignment that was never cleaned up after a transfer, termination, or project end.

Why dormant licences matter to governance

Dormant licences are often discussed as a cost optimisation issue, but the governance value is broader. A licence that remains assigned without recent use may indicate weak entitlement hygiene, incomplete ownership, or a review process that is not catching stale access early enough.

That is why dormant licences should be interpreted alongside ownership, business justification, and recertification history. The question is not only whether the licence is being used, but whether it still belongs to the current operating model.

For access-heavy environments, dormant entitlements can become a quiet drift problem. A licence can remain available long after the original need has passed, which makes cleanup harder and obscures the true state of who or what still has approved access.

For the access and entitlement side of the problem, NIST SP 800-53 Rev 5 Security and Privacy Controls is the clearest control catalog for reviewing account and entitlement hygiene.

How dormant licences are identified and interpreted

Identification usually starts with usage telemetry, procurement records, and entitlement inventory. A licence may look dormant because sign-in activity is absent, application events are rare, or consumption falls below a defined threshold over a review period.

That said, a low-activity label is only a signal. Some software is used intermittently, some licences are pooled, and some business roles require infrequent but legitimate access. Treating every quiet entitlement as waste can create false positives and unnecessary churn.

The more reliable interpretation combines usage with context, such as who owns the licence, what role it supports, whether the software is business critical, and whether the entitlement was intentionally retained for resilience or support purposes.

When the entitlement exists for a service, automation, or other non-human consumer, the same discipline applies: low use may still be normal, but it can also hide stale access that should be reviewed against current function. The OWASP Non-Human Identity Top 10 is useful here because it frames overprivilege, secret exposure, and lifecycle failures in a way that maps well to dormant access states.

What dormant licences tell you about lifecycle hygiene

A dormant licence is often a symptom of broader lifecycle weakness. If the organisation cannot quickly answer why an entitlement is still provisioned, who approved it, and when it should be removed or renewed, then the issue is not just a licence count, it is entitlement governance.

That is especially important where licences are linked to privileged functions, sensitive business systems, or regulated data. In those cases, dormant access can outlast the original business justification and become part of the attack surface even if it is seldom used.

Good lifecycle hygiene means the organisation can distinguish temporary inactivity from unnecessary persistence. It also means dormant licences are reviewed as part of a broader entitlement inventory rather than treated as a one-off cleanup exercise.

For organisations managing broader access posture, NIST Cybersecurity Framework 2.0 helps frame dormant licences within governance, inventory, and protection functions, while NIST AI Risk Management Framework is relevant only where the entitlement supports AI-enabled workflows or automated decision systems.

Risk and Threat Considerations

Dormant licences are risky when they represent access that no longer has a valid business purpose but still exists in production. The exposure is usually quiet rather than dramatic, yet stale entitlements can accumulate into excessive privilege, unnecessary cost, and a larger surface for abuse.

Failure mechanism: The entitlement remains provisioned after the business need has expired, or the lack of routine review allows a stale assignment to persist unnoticed. If an attacker, insider, or compromised account reaches that dormant access path, the old entitlement can become a ready-made foothold.

Impact: The result can include unauthorized use, privilege creep, audit findings, and delayed detection of access that should have been removed. In larger environments, dormant licences also hide governance debt by making active and inactive access look more similar than they really are.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-2 — Account ManagementDormant licences reflect entitlement lifecycle and review discipline.
AC-6 — Least PrivilegeDormant licences can indicate unnecessary standing access beyond current need.
IA-5 — Authenticator ManagementWhere dormant licences involve credentials or tokens, lifecycle control is central.
Recommendation — Review assigned entitlements regularly and remove access that no longer has a valid business need. Limit active entitlements to the minimum needed for each role or function. Track and retire identity-bearing material when the associated access is no longer required.
NIST CSF 2.0ID.AM-01 — Physical devices and systems inventoriedDormant licences depend on inventory visibility to distinguish active from stale entitlements.
Recommendation — Maintain an accurate inventory of software entitlements and usage state.
CIS Controls v8CIS-5 — Account ManagementDormant licences are an account and entitlement hygiene issue requiring periodic review.
Recommendation — Identify inactive or unnecessary entitlements and remove them from production use.

Practitioner Guidance

What to watch for: Treat dormant licences as a review signal, not an automatic revocation event. The practical judgment is whether the entitlement is genuinely unused, intentionally reserved, or simply poorly observed, because those three cases require different handling.

Governance implication: Ownership, recertification, and removal criteria should be explicit enough that dormant access can be challenged without guesswork. A licence that cannot be explained by current business use should not remain provisioned by default.

Practitioner takeaway: The best dormant-licence program is not the one that finds the most inactive entitlements, but the one that can prove which inactive entitlements are still justified.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org