Join our Newsletter — 33% off our NHI Course
Governance, Ownership & Risk

Mega IdP

← Back to Glossary
By NHI Mgmt Group Updated September 2, 2026 Domain: Governance, Ownership & Risk

A Mega IdP is a large, centralized identity provider that serves many applications, tenants, or business units from one trust plane. The security concern is concentration risk: when the provider or its delegated pathways are abused, the attacker can inherit broad access across the connected environment.

Expanded Definition

A Mega IdP is a centralized identity control plane that brokers authentication and authorization for many applications, tenants, or business units. In NHI security, the term matters because the IdP often becomes the highest-value trust anchor for service accounts, workload access, federation, and delegated tokens. That concentration can simplify governance, but it also creates a single blast radius if signing keys, admin roles, conditional access policies, or delegated consent pathways are abused.

Definitions vary across vendors, and no single standard governs this term yet. In practice, a Mega IdP is not defined by size alone. It is defined by the amount of trust it concentrates, the number of downstream identities it can affect, and how much operational dependence exists on one platform. NIST’s security outcomes remain useful here because the issue is fundamentally about access governance, monitoring, and resilience.

The most common misapplication is treating a Mega IdP as just a larger directory, which occurs when teams ignore the risk created by shared trust paths and cross-tenant privilege inheritance.

Examples and Use Cases

Implementing a Mega IdP rigorously often introduces governance and resilience tradeoffs, requiring organisations to weigh centralized control against broader blast radius and more complex recovery planning.

  • A global enterprise uses one IdP to issue SSO access to internal apps, SaaS tools, and workload identities, creating a single policy surface for both people and NHIs.
  • A multi-tenant platform delegates tenant authentication through one central IdP, so a misconfigured federation path can affect many customer environments at once.
  • A DevOps organisation ties CI/CD secrets, machine tokens, and cloud roles to one identity plane, making token misuse capable of cascading across pipelines.
  • A merger integrates several business units into one directory-backed trust model, reducing duplication but increasing the impact of admin compromise.
  • Real-world incidents such as the OneLogin API Key Vulnerability and the Microsoft Entra ID Flaw show how weaknesses in a centralized identity layer can create far-reaching exposure.

For broader control context, the NIST Cybersecurity Framework 2.0 provides a practical way to map identity governance, detection, and recovery activities around centralized trust services.

Why It Matters in NHI Security

Mega IdPs are especially important in NHI security because machine identities often inherit access through the same policy, token, and federation machinery used by human users. If that machinery is weak, over-permissioned, or poorly monitored, attackers do not need to compromise many systems individually. They can target the central trust plane and gain scalable access across clouds, apps, and automation workflows.

This risk is not theoretical. NHIMG reports that 97% of NHIs carry excessive privileges, which means a centralized provider can amplify already dangerous entitlement patterns when it is the primary broker for tokens and service access. A Mega IdP also complicates offboarding, key rotation, and incident response because compromise may span many downstream dependencies before defenders can fully scope it.

Organisations typically encounter the full cost of Mega IdP concentration only after an IdP outage, token abuse, or tenant-level intrusion, at which point the trust model itself becomes operationally unavoidable to address.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01Centralized trust planes magnify NHI exposure, privilege, and delegated access risk.
NIST CSF 2.0PR.ACIdentity and access control outcomes map directly to centralized IdP governance.
NIST Zero Trust (SP 800-207)SC-7Zero trust treats the IdP as one component, not a blanket trust source for all access.
NIST SP 800-63AAL2Assurance guidance informs how strongly IdP-issued credentials should be protected.
CSA MAESTROAgentic and automated workflows inherit risk when one IdP governs many execution paths.

Inventory all identities and trust paths that depend on the Mega IdP and reduce unnecessary central trust.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 2, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org