Entra ID & IdentityCIO BriefingsRetrospectives

CIO Brief: Non-Human Identities Are Your Fastest-Growing Risk

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from December 2020, written in 2026 with the benefit of hindsight.

The short version: In the SolarWinds attack, intruders read email by hijacking applications connected to Microsoft 365 rather than user accounts. Apps and automated accounts — "non-human identities" — now outnumber people in most environments, and they are often less protected.

What non-human identities are

Every integration, script, automation and cloud service uses an identity: applications in Microsoft 365, service accounts, cloud roles, API keys. Many have more access than any employee, never use multi-factor authentication, and have no clear owner.

Why they're attractive to attackers

  • Broad permissions, often granted "to be safe."
  • Credentials that rarely change.
  • Little monitoring compared with user accounts.
  • No human to notice unusual activity.

The business impact

  • Silent data access across the organization.
  • Persistence that survives password resets and user account cleanup.

Questions to ask your team

  • How many applications and service accounts have access to our email, files or directory?
  • Does each have an owner?
  • How old are their credentials?
  • Would we notice if one started behaving differently?

What good looks like

An inventory of non-human identities, owners for each, least-privilege permissions, short-lived credentials, and monitoring for changes and unusual activity.

The decision

Make non-human identity governance an explicit part of your identity program, with its own metrics. It is now where many sophisticated attacks hide.

azure ad application credential abuse impactApp credential abuse2020

More on this story