CIO Brief: Non-Human Identities Are Your Fastest-Growing Risk
Retrospective: this article looks back at events from December 2020, written in 2026 with the benefit of hindsight.
The short version: In the SolarWinds attack, intruders read email by hijacking applications connected to Microsoft 365 rather than user accounts. Apps and automated accounts — "non-human identities" — now outnumber people in most environments, and they are often less protected.
What non-human identities are
Every integration, script, automation and cloud service uses an identity: applications in Microsoft 365, service accounts, cloud roles, API keys. Many have more access than any employee, never use multi-factor authentication, and have no clear owner.
Why they're attractive to attackers
- Broad permissions, often granted "to be safe."
- Credentials that rarely change.
- Little monitoring compared with user accounts.
- No human to notice unusual activity.
The business impact
- Silent data access across the organization.
- Persistence that survives password resets and user account cleanup.
Questions to ask your team
- How many applications and service accounts have access to our email, files or directory?
- Does each have an owner?
- How old are their credentials?
- Would we notice if one started behaving differently?
What good looks like
An inventory of non-human identities, owners for each, least-privilege permissions, short-lived credentials, and monitoring for changes and unusual activity.
The decision
Make non-human identity governance an explicit part of your identity program, with its own metrics. It is now where many sophisticated attacks hide.
- After SolarWinds (Dec 2020): Attackers Abuse Azure AD Application Credentials Incident Teardowns
- How to Audit Service Principal and App Registration Credentials in Entra ID How-To & Hardening
- Detecting Service Principal Credential Abuse: Entra Sign-In Logs and Sentinel KQL Detection & Response