A user who can legitimately need access but has no usable pre-existing factor in the organisation’s environment. This includes first-day employees, contractors, alumni, and people whose device or number changed, making standard recovery workflows insufficient.
Expanded Definition
A never-enrolled user is a legitimate person who needs access but cannot complete the organisation’s standard identity proofing or recovery path because no usable factor already exists in the tenant, directory, or support workflow. The term is common in onboarding, contractor access, alumni access, and device replacement scenarios, where the problem is not authentication strength but how to safely bootstrap trust.
Definitions vary across vendors, but the operational distinction is clear: a never-enrolled user has no recoverable baseline to verify against, so ordinary password reset or MFA reset flows do not solve the access problem. That makes this a governance issue as much as a help desk issue. In practice, the right response is usually an out-of-band enrolment path with stronger approval, identity proofing, or manager validation, aligned to the sensitivity of the requested access. NIST Cybersecurity Framework 2.0 is useful here because it frames identity and access as part of broader governance, protection, and recovery outcomes rather than a one-time login event. The most common misapplication is treating a never-enrolled user like a routine account recovery case, which occurs when support staff assume a prior factor or device can be reused.
Examples and Use Cases
Implementing never-enrolled user handling rigorously often introduces onboarding friction, requiring organisations to balance faster access against stronger proofing and approval controls.
- A first-day employee needs access before their laptop is issued, so HR and IAM must use a verified enrolment path instead of a reset workflow.
- A contractor arrives with no company-managed phone number, making SMS-based recovery unusable and forcing an alternate authenticator setup.
- An alumnus returning for short-term consulting loses access after leaving the organisation, and their prior factor is no longer valid for re-entry.
- A user replaces a device mid-engagement, and the old authenticator is gone before the new one is enrolled, creating a bootstrap gap.
- Access to a sensitive application is requested by a newly assigned team member, so enrolment must be paired with approval and least-privilege scoping.
These cases are often discussed alongside broader identity lifecycle control in the Ultimate Guide to NHIs, because the same lifecycle weaknesses that affect service accounts can also affect human bootstrap flows. For access design, NIST Cybersecurity Framework 2.0 remains relevant because it helps teams treat enrolment as part of a managed control process rather than an informal support exception. The core question is not whether the user is legitimate, but whether the organisation can establish that legitimacy without relying on an already enrolled factor.
Why It Matters in NHI Security
Never-enrolled user handling matters in NHI security because the same weak recovery habits that create human access exceptions often spill into service account, agent, and shared-admin processes. When support teams improvise, they may create temporary credentials, bypass proofing, or reuse stale contact methods, all of which can weaken identity assurance across the broader environment. This is especially important in organisations where the boundary between human and non-human access is already blurred through delegated admin, automation, and agentic workflows.
NHIMG research shows that 91.6% of secrets remain valid five days after an organisation is notified, which illustrates how slowly identity-related remediation can move when lifecycle processes are unclear. That delay is a warning sign for never-enrolled workflows too: if the bootstrap path is weak, exceptions linger and get reused. The same discipline highlighted in the Ultimate Guide to NHIs applies here because lifecycle visibility and revocation are inseparable from safe access provisioning. Organisations typically encounter this consequence only after a lost device, urgent onboarding, or account takeover event, at which point never-enrolled user handling becomes operationally unavoidable to address.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63, NIST Zero Trust (SP 800-207) and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AA | Identity proofing and access provisioning are part of CSF identity assurance outcomes. |
| NIST SP 800-63 | IAL/AAL | The term depends on identity proofing and authenticator assurance when no prior factor exists. |
| NIST Zero Trust (SP 800-207) | SP 800-207 | Zero Trust requires explicit verification before granting access, even for legitimate users. |
| OWASP Non-Human Identity Top 10 | NHI-05 | Lifecycle gaps and recovery shortcuts can weaken identity bootstrapping for NHI-like access paths. |
| NIST AI RMF | Agentic and AI-assisted workflows need trusted identity bootstrap before tool access is granted. |
Treat never-enrolled users as a governed onboarding workflow with verified approval and recovery steps.
Related resources from NHI Mgmt Group
- How should security teams handle users who never enrolled a verification app?
- Why do legacy MFA methods fail to prove that the person authenticating is the enrolled user?
- When do service accounts become a higher risk than ordinary user accounts?
- How should security teams govern infrastructure identities alongside user identities?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 2, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org