← All topics

# Topic

Non-Human Identity

6 articles on this subject.

01 4 min read

What 614 Non-Human Identities Taught Me — and the False Positive That Almost Cried Wolf

I pointed nhi-scan at a real Entra tenant with 614 non-human identities. The 80:1 ratio became a worklist — and the top finding was a false positive: 53 "long-lived secrets" that were really 1. What a real NHI scan reveals, and why context beats raw counts.

02 3 min read

Making an NHI Scanner Production-Ready: What a 600-Identity Run Taught the Tool

Running my NHI tool against a real 600+ identity Entra tenant exposed three things unit tests missed: it didn't run on Windows, the enriched scan took 40 minutes, and it mistook managed identities for stored secrets. The fixes — including a 20x speedup — and why dogfooding matters.

03 5 min read

What an AI Agent Must Never Be Allowed to Do

Buried in a Microsoft Graph reference is a list of permissions that cannot be granted to an AI agent identity at all. Read backwards, it's the first enforced authority model for agents — six prohibitions worth applying to every agent platform you run, not just Entra.

04 3 min read

Drift Detection for Agent Identities: When Reach Grows and the Tier Doesn't Move

An AI agent's reach is the one thing that can grow without anyone touching the identity — give it a new tool or connector and its blast radius expands while privilege, credential age, and owner all look unchanged. Here's why point-in-time posture scans miss it, and how to close the gap.

05 13 min read

A Control Framework for Non-Human & Agentic Identity

A practitioner control framework for governing non-human and agentic identities: eight principles, a four-tier risk model, thirty-five controls across eight domains, an agentic threat model, and a maturity model — mapped to OWASP NHI Top 10, NIST AI RMF, CSF 2.0, and 800-53.

06 3 min read

The Non-Human Identity Reckoning — and Why Agents Make It Urgent

Non-human identities are the enterprise's largest and least-governed identity population, and AI agents just added autonomy to the problem. Here is why the next identity crisis is already here — and the discipline that answers it.