Join our Newsletter — 33% off our NHI Course
Home Glossary Governance, Ownership & Risk Never-Enrolled User
Governance, Ownership & Risk

Never-Enrolled User

← Back to Glossary
By NHI Mgmt Group Updated September 2, 2026 Domain: Governance, Ownership & Risk

A user who can legitimately need access but has no usable pre-existing factor in the organisation’s environment. This includes first-day employees, contractors, alumni, and people whose device or number changed, making standard recovery workflows insufficient.

Expanded Definition

A never-enrolled user is a legitimate person who needs access but cannot complete the organisation’s standard identity proofing or recovery path because no usable factor already exists in the tenant, directory, or support workflow. The term is common in onboarding, contractor access, alumni access, and device replacement scenarios, where the problem is not authentication strength but how to safely bootstrap trust.

Definitions vary across vendors, but the operational distinction is clear: a never-enrolled user has no recoverable baseline to verify against, so ordinary password reset or MFA reset flows do not solve the access problem. That makes this a governance issue as much as a help desk issue. In practice, the right response is usually an out-of-band enrolment path with stronger approval, identity proofing, or manager validation, aligned to the sensitivity of the requested access. NIST Cybersecurity Framework 2.0 is useful here because it frames identity and access as part of broader governance, protection, and recovery outcomes rather than a one-time login event. The most common misapplication is treating a never-enrolled user like a routine account recovery case, which occurs when support staff assume a prior factor or device can be reused.

Examples and Use Cases

Implementing never-enrolled user handling rigorously often introduces onboarding friction, requiring organisations to balance faster access against stronger proofing and approval controls.

  • A first-day employee needs access before their laptop is issued, so HR and IAM must use a verified enrolment path instead of a reset workflow.
  • A contractor arrives with no company-managed phone number, making SMS-based recovery unusable and forcing an alternate authenticator setup.
  • An alumnus returning for short-term consulting loses access after leaving the organisation, and their prior factor is no longer valid for re-entry.
  • A user replaces a device mid-engagement, and the old authenticator is gone before the new one is enrolled, creating a bootstrap gap.
  • Access to a sensitive application is requested by a newly assigned team member, so enrolment must be paired with approval and least-privilege scoping.

These cases are often discussed alongside broader identity lifecycle control in the Ultimate Guide to NHIs, because the same lifecycle weaknesses that affect service accounts can also affect human bootstrap flows. For access design, NIST Cybersecurity Framework 2.0 remains relevant because it helps teams treat enrolment as part of a managed control process rather than an informal support exception. The core question is not whether the user is legitimate, but whether the organisation can establish that legitimacy without relying on an already enrolled factor.

Why It Matters in NHI Security

Never-enrolled user handling matters in NHI security because the same weak recovery habits that create human access exceptions often spill into service account, agent, and shared-admin processes. When support teams improvise, they may create temporary credentials, bypass proofing, or reuse stale contact methods, all of which can weaken identity assurance across the broader environment. This is especially important in organisations where the boundary between human and non-human access is already blurred through delegated admin, automation, and agentic workflows.

NHIMG research shows that 91.6% of secrets remain valid five days after an organisation is notified, which illustrates how slowly identity-related remediation can move when lifecycle processes are unclear. That delay is a warning sign for never-enrolled workflows too: if the bootstrap path is weak, exceptions linger and get reused. The same discipline highlighted in the Ultimate Guide to NHIs applies here because lifecycle visibility and revocation are inseparable from safe access provisioning. Organisations typically encounter this consequence only after a lost device, urgent onboarding, or account takeover event, at which point never-enrolled user handling becomes operationally unavoidable to address.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63, NIST Zero Trust (SP 800-207) and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AAIdentity proofing and access provisioning are part of CSF identity assurance outcomes.
NIST SP 800-63IAL/AALThe term depends on identity proofing and authenticator assurance when no prior factor exists.
NIST Zero Trust (SP 800-207)SP 800-207Zero Trust requires explicit verification before granting access, even for legitimate users.
OWASP Non-Human Identity Top 10NHI-05Lifecycle gaps and recovery shortcuts can weaken identity bootstrapping for NHI-like access paths.
NIST AI RMFAgentic and AI-assisted workflows need trusted identity bootstrap before tool access is granted.

Treat never-enrolled users as a governed onboarding workflow with verified approval and recovery steps.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 2, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org