Join our Newsletter — 33% off our NHI Course
Home Glossary Identity Beyond IAM Monthly Active Users
Identity Beyond IAM

Monthly Active Users

← Back to Glossary
By NHI Mgmt Group Updated August 19, 2026 Domain: Identity Beyond IAM

A billing metric that counts each unique user who authenticates at least once during a month. It is simple to administer, but it can overstate actual infrastructure consumption when the same user logs in only occasionally or when one spike day pulls many one-time users into the billing period.

Expanded Definition

Monthly Active Users, or MAU, is a billing and adoption metric that counts each unique user who authenticates at least once during a calendar month. It is most useful when a provider bills per person, per seat, or per authenticated account rather than by raw request volume.

In NHI and IAM discussions, MAU should be treated as an access-surface metric, not a direct measure of infrastructure load. A service can have a low MAU count but still carry high risk if each user touches sensitive data, privileged workflows, or downstream automation. That distinction matters when teams compare MAU with technical controls such as NIST SP 800-53 Rev 5 Security and Privacy Controls, because usage counting does not substitute for entitlement review, logging, or access restriction. Definitions vary across vendors when MAU is applied to monthly logins, distinct identities, or first-time activation events, so the billing rule must be read carefully.

The most common misapplication is treating MAU as a proxy for security exposure, which occurs when teams assume any authenticated user represents the same operational or governance risk.

Examples and Use Cases

Implementing MAU rigorously often introduces billing ambiguity for shared workspaces, trial users, and infrequent accounts, requiring organisations to weigh pricing simplicity against measurement precision.

  • A SaaS platform bills by MAU and counts a contractor once in the month even if they sign in only on day one, which can make growth look steadier than actual daily engagement.
  • A security team reviews MAU alongside service usage to separate casual human access from NHI activity, using the Ultimate Guide to NHIs as a reference for identity scope and lifecycle concerns.
  • A product team sees a spike in MAU after a promotion and discovers that many accounts are one-time evaluators, not sustained users, so the metric is poor evidence of ongoing adoption.
  • A compliance team maps user access patterns to NIST SP 800-53 Rev 5 Security and Privacy Controls and learns that MAU alone does not show whether inactive accounts still retain access.
  • A business analyst pairs MAU with retention and session depth to understand whether the month reflects real product stickiness or only a temporary login surge.

Why It Matters in NHI Security

MAU matters in NHI security because identity counts can mask how much privileged access is actually in play. An environment may appear manageable by headcount-style metrics, yet still carry elevated exposure if a small number of users trigger broad API access, automation, or delegated permissions. NHIMG notes that only 5.7% of organisations have full visibility into their service accounts, which illustrates why identity metrics that focus on human-style usage can leave critical NHI activity unmeasured. The Ultimate Guide to NHIs also reports that 97% of NHIs carry excessive privileges, reinforcing that counting active users does not reveal privilege concentration.

Used correctly, MAU helps teams understand adoption and licensing. Used poorly, it can hide dormant but dangerous access paths, especially where accounts remain enabled after role changes, offboarding, or project end dates. Organisations typically encounter the security consequences only after an audit, breach review, or license dispute, at which point MAU becomes operationally unavoidable to reconcile with actual access exposure.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0ID.AM-1Asset inventory includes users and accounts, but MAU is only a usage count.
NIST SP 800-63AAL2Authentication events underlying MAU should still meet the needed assurance level.
NIST Zero Trust (SP 800-207)AC-2Zero Trust requires continuous account governance beyond monthly active counts.
OWASP Non-Human Identity Top 10NHI-01MAU can obscure non-human account exposure when service identities are not separately tracked.
OWASP Agentic AI Top 10A-03Agent activity may be counted as usage while actually representing autonomous access.

Use MAU to inform inventory trends, then verify actual account states and access paths separately.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 19, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org