A dormant share is an externally shared file or resource that remains accessible after its original collaboration purpose has ended. These shares are risky because they often lack expiration, ownership, or monitoring, which allows unintended access to sensitive information to continue indefinitely.
Expanded Definition
A dormant share is a file share, folder, or other externally reachable resource that was created for a temporary collaboration need but was never closed, expired, or reassigned when that need ended. The key boundary is not whether the content was once legitimate, but whether access still exists after the business purpose has lapsed.
In security practice, dormant shares often arise from ad hoc collaboration, partner onboarding, project handoffs, or cloud sharing features that default to persistence. They are distinct from active shared workspaces because no current owner is reliably validating membership, revoking access, or reviewing content sensitivity. Definitions vary across vendors and platforms, but the governance problem is consistent: access outlives intent.
For NHI Management Group, the practical distinction is that dormant sharing is an access-lifecycle failure, not just a storage issue. It is often discovered during access reviews, external exposure scans, or cleanup after a project closes. If a share remains externally accessible, it can become a standing trust path even when no one still remembers why it exists.
Examples and Use Cases
Dormant shares appear in everyday collaboration and operations, often where speed was prioritised over lifecycle control.
- A project folder shared with a contractor remains open months after delivery, giving former collaborators continued access to working files.
- A customer document exchange site stays publicly reachable after a deal closes, leaving proposals, exports, or contract artifacts exposed.
- A team drive used for incident response is never retired, so old responders and outside partners still retain access long after the event.
- A cloud storage link created for one-time review is reused informally because no owner tracked the original expiration or audience.
- A merger or vendor transition leaves duplicated shares behind, making it unclear which location is authoritative and which can be removed.
The tradeoff is convenience versus governance. Temporary sharing reduces friction during fast-moving work, but if expiration, ownership, and review are not enforced, the convenience becomes a long-lived exposure surface. The OWASP Non-Human Identity Top 10 is useful background when those shares are backed by service accounts, tokens, or automation that continue to authorize access after the human collaboration need has ended.
Security Implications
The main security problem with dormant shares is that they preserve access after the organisation has stopped paying attention to them. That can expose confidential files, regulated data, source material, operational records, or internal discussions to former partners, ex-employees, or anyone who inherits a live link.
When dormant shares are unmanaged, the failure mechanism is usually simple: no expiration policy, no authoritative owner, and no monitoring for continued use. In practice, that means access reviews miss them, offboarding does not remove them, and security teams may not detect that an external path still exists until a scan or incident reveals it. If the share is indexed, forwarded, synced, or embedded in a workflow, the blast radius can extend beyond the original folder.
NHI Management Group reports that 92% of organisations expose NHIs to third parties, raising concerns about supply chain security. That matters here because dormant shares often persist through automation, shared credentials, or delegated access that no longer matches the original business context.
Domain and Governance Relevance
Dormant shares matter most in collaboration governance, data protection, and access lifecycle management. They show that “shared once” is not the same as “safe forever,” and they expose the gap between project completion and access retirement. In mature environments, the control question is not only who created the share, but who is accountable for ending it.
For non-human identity governance, dormant shares are especially relevant when access depends on service accounts, app tokens, API-driven integrations, or automated sync processes. Those machine-linked paths can keep content reachable even after the human owner has moved on, so sharing controls must be tied to ownership, inventory, and revocation rather than informal team memory. The right governance model treats external sharing as a lifecycle object, not a one-time permission.
That is why dormant shares sit at the intersection of data classification, least privilege, offboarding, and periodic review. When they are handled well, they are temporary collaboration tools. When they are not, they become invisible standing access.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | 6 — Access Control Management | Dormant shares persist because access is not removed when collaboration ends. |
| 8 — Audit Log Management | Monitoring helps detect continued use of shares that should have expired. | |
| 3 — Data Protection | Dormant shares can expose sensitive data beyond its intended audience. | |
| Recommendation — Review and revoke stale external shares and delegated access on a fixed schedule. Log external share creation, access, and revocation to spot lingering exposure. Classify shared data and restrict external access based on sensitivity. | ||
| NIST CSF 2.0 | PR.AA — Identity Management, Authentication, and Access Control | Dormant sharing is an access governance failure tied to entitlement lifecycle. |
| DE.CM — Security Continuous Monitoring | Unmonitored dormant shares often remain live until discovered by review or scan. | |
| Recommendation — Define ownership and enforce expiration for externally shared resources. Continuously detect externally accessible resources that no longer need exposure. | ||
| OWASP Non-Human Identity Top 10 | NHI-02 — Secrets and Credential Management | Shared resources may stay accessible through tokens, keys, or machine credentials. |
| Recommendation — Remove machine credentials that keep dormant shares reachable after purpose ends. | ||
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 9, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org