Non-human identities now outnumber human users. Yet most IGA systems, built for a different era, leave them unmanaged, unowned, and dangerously exposed. Trying to force-fit NHIs into legacy IGA models only deepens the problem. Endless customization creates fragility, not flexibility.
The result is an expanding attack surface disguised as “identity management.” A different approach is required - one that abandons the illusion of control and embraces standardization, business alignment and agility as non-negotiables.
Nitish Deshpande, Research Analyst at KuppingerCole Analysts will highlight the fundamental differences between human and non-human identities and present strategies for embedding business-driven accountability into identity programs. He will also highlight the critical risks associated with not managing NHIs properly.
Thomas Müller-Martin, Principal Product Manager at Omada will show how modern IGA platforms can restore control. He will demonstrate how to establish ownership for NHIs, govern service accounts with precision and leverage out-of-the-box capabilities that deliver results quickly without falling back into complexity.
So, hello everyone. Welcome to today's KuppingerCole webinar, Integrating Non-Human Identities Into Identity Governance Programs. My name is Nitish Deshpande, Research Analyst, and today I'm joined by Thomas Müller-Martin, Field Strategist from Omada.
Thomas, welcome to the webinar. Would you like to maybe quickly introduce yourself?
Yes, thanks Nitish, great to be here today with you. My name is Thomas Müller-Martin, I'm working here from Germany for a company called Omada. We're doing identity governance and I'm Field Strategist, which is a very listening role, so I want to understand a lot about the market, what are the challenges of today's enterprises, and would like to translate that into what we do with the product and then give as well recommendations about how to utilize what we have today and what is coming next to maximize the impact that identity governance has for enterprises today.
So, thank you for being here with me today, Nitish, and looking forward to this webinar. Thank you so much, Thomas. I think the questions are really important points and to an extent we are going to cover those in today's webinar. We will definitely go through what are the challenges in today's IAM environment for NHIs, what are the governance and lifecycle aspects that need to be taken into consideration, also what's the future for these NHIs in this age of AI.
So, we'll go through that, but before that, here are some quick housekeeping rules for everyone. You all are muted centrally, so you don't need to mute or unmute yourself. We are controlling that.
As always, we like to keep these webinars very interactive, so we will be running a couple of polls during this webinar and I would like to encourage all our attendees to participate in this poll, provide your input using the Livestorm control panel, and yeah, we are excited to see the results and we will discuss those results during the Q&A session, which will be towards the end of the webinar. But if you have any questions during the webinar, please feel free to use the Livestorm control panel.
You can enter your questions at any time and we will try our best to answer as many questions as possible. And this webinar is being recorded, so the slide deck and the recording will be made available for download in the coming days on our website, www.kubingercall.com.
Perfect, then let's jump in. Here's a quick overview of the agenda that we have today lined up for everyone. We will talk a bit on NHIS, how the lifecycle management should be around the NHIS, what are the key challenges for these processes, what should be the governance aspect, and the future of this space as well, and then we will have the Q&A session. But before we begin, I would like to invite everyone to participate in today's first poll, and that is the question that everyone keeps on asking is, what is the current ratio of NHIS versus human identities in your organization?
Is it first, you don't know? Is it second, is it zero to 20 times NHIS, which are more than human identities? Is it third, you have 20 to 50 times NHIS more than human identities? Or is it fourth, your NHIS are exceeding more than 50 times than human identities? So I look forward to seeing the results of this webinar. This is a very interesting point as well that I have been coming across in the last 12 months. Let's see what the ratio says towards the end of the webinar, so stay tuned.
Well, let's start with first understanding what we can go through today's webinar and what we're trying to cover is that we want to understand how to secure the future, manage the NHIS in the age of AI. So the need for an adaptive control model that is responsible with AI and the broader impact of NHIS on the risk and trust in digital ecosystems. NHIS have a wide variety of types. They vary from bots, APIs, microservices. You have different terminologies for them as machine identities, workflow identities. Then you have these autonomous agents as well as bots as well.
So it's a wide space and if you compare that with your human identities on this diagram, you have your workforce identities, contractors, B2B partners, you have consumers as well. So we'll try to understand how NHIS differ from them, how is the behavior different from them, what are the governance requirements of NHIS that are different than the human identities, what could be the risks that come out of these unmanaged NHIS and explore some out-of-the-box functionalities and also talk about the flexibility trap.
And I think Thomas would like to also bring you in here is maybe do you have something to also add on this one and from a governance point of view, what do you think? Yes, so I think it's exciting that we are now on this new frontier of identity because we're now seeing that, I mean, we have, this space is not new and it's now 20 years, but what we see is that we now fight challenges on a whole new level, right? So we need to prepare for the future and the future is definitely not going to be less demanding.
So what I've seen in the past is that lots of organizations are diving into the complexity of very small parts of identity management, but now we have to look to the future and that means that we can't take as many decisions, we can't manage hyper-complex super individual systems anymore because we want to serve the business. So the paradigm is shifting completely, nothing of that is new.
We've always worked with service accounts, machine accounts, with all those kinds of things, but now as it hits a new dimension and a new scale, we really have to adopt to what that means and that doesn't mean that the industry needs to work better with our products, it's rather a both way evolution.
So the vendors are really fast adapting, we see the requirements evolving and we see lots of demands coming from the security and technical side, but more and more from the business side and we know that as soon as the business wants something and sees value, we really have to move fast because we need to suit that and we have this hyper-dynamic world where enterprises are not struggling to keep up, but the pace of change for enterprises and how business is made is so dynamic, much higher than in the past, that we really need to reflect that in our IT and I think NHI is a very good sample of where we have to pulse, to finger the pulse.
Exactly and also you touched on a very, obviously one point which I've always tried to, it found me by surprise is that they have been around for decades, you said 20 years and they've been around for decades, but I think now it's like I guess the last 12 months I have seen a lot of friction around these spaces, just trying to understand what they are because of maybe the explosion that we are seeing with NHIs, how to govern them, how to manage them, so that's a very I think important point right now and I'm glad the industry and the space is focusing on these particular issues as well, so yeah we will go through all these points in the next part of the webinar, but first we want to just tackle the solution is like why do NHIs represent such a challenge, so why are they becoming the next challenge?
I would say first we need to understand the current situation, you have many of these NHIs that are invisible to the traditional IM tools, they are often unmanaged with static credentials, over-privileged access and overall having a weak governance which can have some serious consequences like breaches, compliance failures, losing trust between your customers and stakeholders, so once you understand the current situation I guess then it's about identifying what is the core problem, is how can we securely authenticate, authorize and govern NHIs in this current scale in the age of AI and why do we need that is because they behave very differently from humans, we need to first understand that and so we need to ask ourselves a few questions, is our NHIs already outnumbering human identities in your environment, is the AI accelerating this imbalance and without zero trust could they become the weakest link, so this is the current challenge here right now, we will go through some more in the next slides but I want to highlight that here, so now when you have these new challenges on NHI, what becomes essential?
Zero trust, zero trust becomes essential, we need to have a zero trust framework for NHIs which means you need to have continuous authorization, authentication for every access request, you need to involve humans as well in the loop, for example for sensitive operations and critical operations, you need to have fine-grid policies so that NHIs do what they're meant to do and when they're meant to do and finally you need a good locking and monitoring for full traceability of these NHIs, so just like humans I would say, NHIs also need to earn the trust and they need to be re-verified at every step, so NHIs and the message would be that they're growing at a very faster pace than we thought, so managing them and governing is not an option right now, we have to do it right now, it's critical for security, compliance, trust, so by applying this various lifecycle governance, enforcing least privilege, zero trust, we can get ahead of the curve and try to address the issue, but for that we need to first go through the initial phase of the governance lifecycle management and I think Thomas, this is where you have the point about the ownership as well, so would you like to maybe elaborate on that one?
Yeah, so what we see is that there is something that we can reuse from what we see today, so the concept of ownership is quite important when it comes now from the shift of human identities to non-human identities, because we still need to know who is accountable for things, we have some things like non-remediation of actions and auditing and audit trails and those requirements won't go away, so ownership is something that is quite important in that sense and what I like to have this, how I want to compare is that very often things are super complex, but if you look at things like Pokemon right and regard those little things as non-human identities, you could say that, I don't know if you're aware about Pokemon, but mainly they are, there are many of them out in the field, you need to catch them and find them and probably there are more than you think and if you do things properly in this movie or in this series or in the game, then they're going to empower you significantly and make sure that you're very effective in your job, so you're going to find much more than you think initially and they come in very different forms right and there's not one way of non-human identities and they are more along the way right now, we see not just service and machine identities but as well APIs and keys to that, we see bots and things that run autonomous on your behalf doing tasks that you are not really related to anymore and so things are evolving over time, so it's not a one-time thing, if you leave them unnoticed or unmanaged, they're going to change significantly without your attention, so ownership and an idea about which forms and quantities of non-human identities do you have and what are they used for and who's accountable for the stuff that they're doing on behalf of somebody else is quite significant and I think that's something that we know from existing IGA solutions or common identity management where you onboard some systems and automate lots of you always have to get people accountable because you need to have somebody who knows what happens and what is the purpose of the things that are happening in this system and the purpose gets lost when lots of things happen automatically and unnoticed and ownership is one of the very key elements that you should regard when tackling these new challenges.
I agree, I cannot agree with you more, I think you have used a really interesting analogy here of the sense what the NHS you have in your system, you need to have some ownership for them as well, but these NHS, they are the same but they're kind of different from the human identities as well, so how would you maybe differentiate that from a normal human identity?
Yeah, I think that there's more similarities than we think but there's some difference, as I said before you have this ownership concept right, so if you provide access to a human being this person knows what he or she has to do with the access that he or she is provided with, if it goes to non-human identities you suddenly lose control about what is really happening, so you need this ownership and reflect that, but as well when it comes to termination of some things you need as well to have some differences, so for example when you have a person that is leaving the organisation you would like to remove the access, if it's a non-human identity there may be a requirement to keep it because it runs for a higher cause independent from the individual that is leaving the organisation, so for example there might be a technical connector that is used to send emails out on behalf of your marketing team and if this person leaves and has these non-human accounts attached to him or her, then if you remove the access some automatic things that you expect to happen will not happen anymore, so in these cases it's rather about changing ownership on departure instead of removing access, so you need to have a different kind of life cycle for those identities and be aware about the relevance for them, and then as well when it comes to the access to grant to them, when it comes to humans you want to have simplicity, you don't want to have so many questions etc, so you want to automate a lot of access depending on the project they're working in, the manager they're working for, depending on the location, and if there is something that you can't grant automatically that's good, but if you look into non-human identities it's a higher risk of over-privileging them because every access that you're granting to those non-humans is going to be used, so try to be very precise in how you define the automatic access or if you go for standing privileges be very very careful and keep it short and keep it very dynamic and up to the special need that this non-human identity requires, so there might be as well when you go into role-based access and have roles that have lots of accesses in, you probably want that for humans because they want to understand what they're doing when it comes to privileges for let's say service identities, you need to be very careful, so you probably don't even want any role to be requestable for those items because it has one job and just one thing and you don't want access and sprawl of access.
Then account quantity, typically you have one account for each human, you have a personal account, you may have one admin account, you may have one demo or test or whatever account, but when it comes to non-human identities they can have many target accounts for one individual system, so there's as well this little nuance of how to grant access there that you need to reflect and then two other things, naming conventions, super easy for humans because you have typically some rules like ADM in the beginning of your username indicates it's an admin account for non-human identities and because they may have many of those accounts in the system it's a bit harder, so you need to have those different way of joining things and different way of understanding that and probably not the same automatism that you have for human identities, but those are small things.
All in all what I would say is for humans you can increase the happiness by reducing the choice, making their life easy and understandable, not just for the requester but for the approver and automate as much as possible linked to how the business works and when it comes to non-human identities you have to increase the choice so that you can be very specific and not run into risk of over privileges.
So those are just the differences but there's lots of joint requirements, so don't reinvent the wheel just because it's a different type of identity, there's lots of things that you can still do and redo with those new types but we're coming to that later I'd say. Yeah perfect, I think that's clearly perfectly summarizes the differences as well so thank you for that.
I think that then brings us to the question is that how should we secure this at scale because scale is the main issue here right now and this is a five-step process that we have kind of outlined here is that what you should do and how to close the gaps.
First is of course as Thomas mentioned earlier is just discovery and classification, you have to identify all NHIs that are in your system, you need to map those accounts, assign ownership of those NHIs, categorize them by function and risks and next is then you only grant the required rights for each NHI based on its purpose, something like just time access and time-bound access is quite you can say beneficial in this learning NHIs.
You can regularly review access rights and revoke access entitlements as Thomas earlier mentioned, over privilege is a big issue in NHIs so you need to revoke access of these entitlements to keep them governed properly and human-in-the-loop is also critical, everything cannot be made automated but sometimes you need a human-in-the-loop for approval for some critical situations, critical operations, so you need that.
You have the secrets management as well so you need to eliminate hard-coded passwords, tokens, well these are the static, exposed, hard to rotate and they're so use secure vaults for rotation, revocation and auditable protection and all this needs to be done automatically, you need to automate the key renewal and revocation of secrets for minimal exposure reducing the attack surface.
Then you have the step around monitoring and auditing, continuous logging of all NHI activity, it's important that helps you to then understand anomalies, detection of anomalies and you also can use behavior analytics as well. We have seen NHIs behave a bit differently than humans so you need to first understand the behavior and then develop a behavior analytics around that part.
Integration of these NHI logs into SEAM and SOAR platforms is also important for having a more centralized monitoring and a more unified overview of the entire NHI inventory and then escalating these critical actions for human authorization.
Finally it's about the decommissioning part, so you need to identify the unused or the abandoned NHIs that are in your system, track and decommission the active NHIs owned by orphaned human accounts, you've seen this case several times around is that the owner of the NHI, the human account is deactivated but NHI still remain active in the space, so we need to have some governance around that part as well as that will reduce this attack surface. Thomas I would like to also bring you in here is from Omar's point of view, how do you see the governance in action here?
Yeah I liked your slide because it shows this move that we see over the last two, three, four years into the identity fabric where we used to see identity management solutions rather in their silo as something specific for a dedicated task and now we see this joint activity because there's some solutions are very good in finding signals that make risks, some things that give you information about usage patterns and some things that are very important about deleting accounts, making sure that you have a comprehensive overview about stuff etc and giving you this governance panel that is so important for many organizations and now as things come together we see that the more you agree on what good looks like the easier it is for those different solutions to come together and accelerate and build on top of each other's strength, so identity fabric comes more and more into play the more we talk about things like NHI but all those other trend topics that we're talking about in all the webinars that we're doing but when I look into what you should look at in your current solution especially when it comes to identity governance administration there are four parts that I would say that are worth looking at at the moment because it makes sense to start using things instead of waiting till NHI is defined till the end and then taking a step, so start right away and look into those following things, so first is of course discovery and reconciliation, Nishish told us just before how important the detection even is and as well classification of stuff, so look into the import of those kind of elements into your current solution so that you have an overview that you have either the ability to link them to an individual to an owner or as well might be a benefit to understand how big the problem is and how fast it grows, so even to give the trend is quite important and then very often in these solutions you can as well classify some accounts or some NHIs depending on the access that is provided to them so that you can make a highlight about the things that should keep you up at night because of there's a overprivileged NHIs and you don't know who has access to them and what people are doing with it, the risk of significant breaches are much higher than in the past, so that's quite important and that's something that you can start typically based on your current solution already and then we move on the right side where we have the service and recertifications, so typically you do recertification of access but you can as well do recertification of ownership, so if you detect non-human identities or accounts you could go and say who's responsible for that, who takes ownership about those NHI and what they're doing because then you can link it and you can have this consistency, it doesn't go out of sync, you can always go and deal with the delta that is definitely coming up and that's quite important for you as well, then you have those life cycle elements where you have join a mover lever but as well things like delegation, things like people being added to projects and having this matrix organizations with multiple employments that are quite common for man and enterprises and very often you will find that you have identity management solutions that bring their own ownership concept which means that you can attach the non-human identity to a primary identity so to say and then link the secondary steps to what happens with the the owning identity, so you could have request non-human identity access dedicated to non-human identities or reuse the request access with dedicated approval steps for these kind of scenarios, you can onboard and off-board those identity themselves and as well you can relate them to a purpose and no matter we call that a context but it can be a team, it can be anything that makes them valuable or meaningful, so as long as you are working for this and that project, as long as you have this and that task to fulfill, those non-human identities can be privileged but as soon as the purpose, as soon as the reason drops, you need to remove the access as soon as possible because then it's opening for misuse and then the fourth pattern is this access compliance reporting right and that's there as well in many organizations you have already some reporting capabilities and if you don't press your vendor because it's quite important to just have the overview about non-human identities in parallel to the identities that are of human natures like employees, like contractors, suppliers etc.
So use the risk indicators to measure the success, measure the quality of your system and bad quality is not necessarily bad but it gives you an overview and the reason for move and many times people are just missing this link, they do so much very good quality work but they're missing to demonstrate the relevance for the organization and translate what we're doing to the management who are then sponsoring the next project phase and trying to keep you secure, trying to keep the risk low.
So the ability to report on how problematic we have it is quite important and much to a high degree over underrated at the moment and overseen. Perfect understood, thank you so much. I have one question for you, does Omada provide most of these capabilities out of the box or like for example you mentioned several use cases or maybe? Of course there's a dynamic right, as we have some changing requirements in the NHI sector at every time, for example we're changing the way that we're doing the reporting now to be more precise and more illustrative on how does that reflect to the non-human factor.
So most of the things are there, many things need to be fine-tuned to be adjusted to how the business works because it's not a technical thing, it's as well this requirement to adjust to the business but in principle most of those elements are pre-existing and they are pre-existing not in form of a toolbox but in form of a concept that you can use and don't have to reinvent and I think this reusing of best practices and having strong concepts and identity management solutions is getting much more required to stay agile and to stay ahead of the requirements than ever before and I think there's a trend where organizations are really now fast adapting things because they see that if they don't go with best practices they're stuck in a very narrow corner with a hyper monolithic super customized hard to operate solution that nobody understands but the two people that have written all the scripts and you don't want to be there going forward because you really need to prepare for scale, you need to prepare for this new agility that is required so most of the things come out of the box with some things that we are just fine-tuning and a few things where we need to look into the business but thanks for the question and I hope it answers it.
Perfect, thank you so much that answers my question and I think you mentioned around the risk and changes as well so I would like to very quickly briefly touch around, we talked about the lifestyle management of NHIs but what could be some of the risks that and that could be coming out of each phase let's say for example you have the discovery phase on here on the right side at the top many NHIs are currently undocumented or hidden so you need a strong discovery phase to first identify how many NHIs are in your environment then comes the classification and the ownership part where you are lacking clear accountability of who is creating this who owns these NHIs and what I have also seen is from talking with different customers and vendors is that earlier this year most of the point of period of this year is most of the organizations are currently in this phase from discovery, inventory, classification and ownership they are just trying to identify how many NHIs are in their environment who owns these NHIs and then once they have addressed that I guess you move on to the posture management you identify the overprivileged account NHIs the static permissions that are being granted and also identify the inactive accounts then the secrets and credential essential part of the NHI lifestyle management as well is secrets need to be rotated you have hardware tokens and API keys monitoring governance very important part as well as was mentioned how they also do OMARA at OMARA is critical for NHI lifestyle management it can help you identify anomalies it provides you can say without a good monitoring and governance aspect you will be having a limited oversight into the NHI activity and finally the decommissioning is very important because if often abandoned accounts are still active this creates a huge security risk this can be used as a security back channel for breaches so there are some risks which can which need to be first taken into our account address in each life cycle phase of NHIs while you are trying to tackle this huge problem of NHIs that we have right now and I think that brings me to the next poll question for everyone in the webinar today is what risk concerns you most about unmanaged NHIs is the first privilege escalation is it second you have orphaned and abandoned NHIs is it third you have long-lived secrets or is it fourth multiple applications are using the NHIs so both the polls are in our lifestyle control panel you can select your preferable answer and we will discuss the result of both the polls in the in the next I would say less than 10 minutes we will go towards that but before that I would like to first understand where the NHI market is right now just before we do that I see that there are some first questions already in the polls we're coming to a Q&A in the end or we try to we try to keep ourselves honest so if you have questions write them in and we're going to look at that and and try to answer your question as good as possible so don't don't hold back we're looking really forward to that but we're not doing that now in the middle because just for the flow and to reserve the time and do that properly in the end all right so thank you for your reminder Thomas I think please enter your questions at any time using the control panel and we will try to address them towards the end so thank you for that reminder yeah so what I was saying is we want to first understand what is the current priority of the NHI market now we have been talking with several vendors several customers on this NHI space and after talking with them going through everyone's requirements also these are the top five priorities that they have so if you take a look at the let's say the first part is having a unified discovery and automated remission so organizations can no longer afford this fragmented visibility across this cloud platforms workloads so they want a single consistent way to identify every NHI understand what it can access understand what it can do automatically remediate risks without relying on manual interventions and the second big priority that I have come across is AI and machine learning driven detection and governance so with the skill and speed at which the NHIs are growing it has become physically also impossible to keep track of them manually for humans so we are seeing rapid adoption of adaptive authentication animal detection and even autonomous governance action that can respond in real time to unusual behavior patterns or misconfigurations of these NHIs so that's the second point third is again just in time in the camera access also FM identities so that is also priority instead of having long-lived secrets that sit exposed for months or years entities are created when they are needed and disappear when the task is complete so that will dramatically reduce the attack surface that is a priority as well then we have the last two priorities that is having more broader integrations across your CI CD pipelines DevSecOps multi-cloud environments SAS systems so NHIs are not you can say operating in isolation they are moving through complex automation chains and there needs to be guardrails governance that follows them across this entire life cycle and finally it's about the growing emphasis of advanced governance for both the NHIs and also AI agents there's been a significant advancement in AI in the last I wouldn't say last quarter last half a year so it means just clearly assigning ownership enforcing the consistent policies automating as much as the governance processes is possible so that's the I would say the five key points that we are seeing right now but Thomas maybe if you want to add something what you're seeing as well when you're talking with the customers what is the priority right now?
Yeah I think it's a great list and especially if you look at this AI ML driven anomaly detection we need to prepare for for a world in where we cannot take the number of decisions that we're today so we need real support by lots of agents and tools that are looking for patterns etc and they are much better than that than the humans so there's a lot of change coming and of course we need to prepare the solutions to to adapt to that.
We see as well lots of organizations that are now today just got it solved to have to trigger a change of access whenever somebody moves from one department to the other and we're super proud about that because that just happens every I don't know year or something but going forward we need to be much faster in changing the access patterns and that goes especially when it comes to non-human identities down to a minute in in the midterm and later on we need to have by the second or a couple of seconds changes to the access depending on the need so you want some access just for dedicated task and remove it straight away and that's something that that that is fundamental change in the way that the solutions work and the business going forward will expect solutions to work like that and then we see as well language support right you everybody's working with teams and we want these assistants that support you that say I don't understand what I need to to request just support me with finding the right access for me and then get those recommendations etc you want to have a natural language friend not just for requesting access and approvals but as well for creating records there's there's an auditor in front of me and this to needs to related report for the last six months for this that system where we had a breach or where we had where we have a specific requirement and and you don't want experts to do these reports you just want to have a clear language model that allows you to gain the information and there might be as well some additional agents that are sitting in between the identity management solution and the business purpose that are soaking in the information and you need a secure way of controlling the data flow in that so a lot of ways where apis and new new ways of working are influencing the way that identity governance is work uh are working and so there's a lot to do for identity management solutions uh but we've heard the call and it's it's an exciting challenge to go there and lots of ideas that we hear from our customers that we hear from the industry and where we are as well so entitled to have the analysts that are sharing information from the field with us so thanks for being a call as well for for guiding us there and giving us a hand in and uh reflecting uh and and making sense of all the noise that we get from from all those directions but there's there's so much to do and i think that we have an exciting roadmap there that goes directly to this this point that you're naming perfect i think that perfectly summarizes that market wants right now automation full visibility intelligence and flexibility and if you talk about what the future holds um well the adoption is growing so that means number of NHIs is growing quite rapidly every new AI driven process is creating new apis microservices ports and where these identities are often short-lived making them harder to track with traditional IM tools so and if you add to that the complex web of dependencies in AI ecosystems and governance becomes extremely difficult so without having a adaptive automated governance the high-tech surface is expanding dramatically so it's about the scale yes but it's also about the speed with which the AI driven systems are moving and i think that's where the future is going towards but i would like to also understand from your point of view from Umar's point of view what do you see where is the future for AI or IGA as well yeah i think AI is a very important topic as well in the way that we are governing our non-human identities and i would see that there's a three step thing uh of which the first has already gone i'm here in Omada for quite a while and when i look back into um into my early days of consulting and architect it was rather like we needed to understand how identity management is built and that's like we wanted to understand how to build an airplane but these times are not there anymore people understand how flying works and now it's rather about how can it accelerate much faster so that we can get the uplift and take then the cool advantage of of every experience so today we are having much more modern solutions they are more they're not just tools that are can be stitched together in any but they have best practices they allow you to um have be very effective if you use them correctly and now there's a two-step thing the AI for IGA is that we are using the AI assistance so to make the identity governance much smarter so you have those assistants you have these reporting capabilities and you don't have to stitch things on your own you have don't have to reinvent the wheel and you can use pattern recognition for role management you know those business processes that are already there those different types of identities recommendations all the good thing to reduce the number of decisions that people have to make and allow them to understand much easier what they have to do to gain efficiency and to gain security at the same time and when we do that now and when we focus on that not just as a vendor but as the industries um we need to focus for just a while to get the speed and then we are able to lift because then it comes to the IGA for the AI right because then we have all those multitudes of different forms of identity of AI agents etc and then we're able to control them in second step right most of the solutions are not there yet are building for the future and the importance for the customers in the world now is to use this phase to reduce complexity to prepare for scale to accelerate with the solution and then to take the uplift so that you can use the solution that you have built for the future where we have the AI as the norm the non-human identities at scale and let's get there very very fast and this needs to be the vendor plus the customer a joint move and we see that there's such a big need and demand and such a great opportunity for acceleration in both fields let's just join and do that jointly.
Okay and that brings us perfectly towards the next step is that what would be your key recommendations here for yeah yeah I love that as well because I mean there's lots of things they're going to tell you next but the underlying thing is you are not alone and don't try to make everything on your own because this is a team sport right it's not a security thing it's a security and efficiency thing and it's as well compliance thing so there are many functions required so first is like make an assessment like how bad is it where are the non-human identities find owners for them right all that I did on the Pokemon slide right do that first the readiness assessment how problematic is it and then define first policies and have this roadmap about where to where you want to get how to reduce the impact of a breach of an attack and secure the executive sponsorship this is the translation from technology to why does it matter to the business how problematic is it if it goes wrong and then people can take proper decisions and support you with your activity and then you go for automation reducing things to the absolute minimum so that you are then prepared to scale from there don't just do recertification because of recertification but prioritize high risk and fast changing things so that you're on top of where the most the most risk is and then try to be informed about the landscape look into best practices look into regulations talk to analysts they really know well what other organizations are struggling with and they know that you are not alone and there are more similarities between you and other companies than you would expect so look into what those authorities are able to to tell you it's super valuable we find that for ourselves very often and we're sure that lots of organizations will find that too and then do cross-functional review so have this cadence and involve security it devops and all those functions that you need to be successful in that because not one person in this organization can take decisions because it's not just a business requirement it's as well as security data protection compliance requirement so many functions need to be evolved and involved in this over time especially when those changes happens over time so it's not a one-shot it's not one person and one function that needs to solve this problem or face this challenge take the organization and try to make your your your roadmap for that so that you're able to articulate everything that you do to those people in power that can grant you access to the credential through the resources in your company that can fund the project and allow them to understand the relevance of what we're doing here that's the most important thing I would say I would say I would agree with the steps that you have mentioned here you need to have a perfect you can say not perfect but you must understand what NHS you have you need to define the policies it sounds easy but I don't say it's not easy I would say as I mentioned earlier when I talked with the customers and vendors the main challenge is just trying to identify how many NHS they have and who owns them and then I guess it comes down to being more informed around them and prioritizing which ones to govern and which ones to have let's say have human in the loop as well it's a journey right it's it's not something that you can just write down in an excel and say oh but now I've solved the problem it's something that that that requires as well organizational changes right but volume and the business value that that your your leadership sees is so big that that should be something that would be hard to uh to not do right so uh I completely agree it's it's just five bullet points and it's easy to read but if you have to apply it in the organization it's it's it's it's quite hard but these are the steps and you have to evolve them over time and have them on your radar for for success so put them in in your work cadence okay I think that brings me to a perfect point is addressing the results of the poll questions oh yeah um and it I think it it shows the importance of discovery because the answer question is what is the current ratio of NHIS versus human entities in your organization and uh most words have gone to don't know what the person has said they don't know how many NHIS are there compared to human entities I think that's that goes back to your slide of pokemon as well right so maybe you want to maybe share something on that go go and find them yeah but I think I it's it's worrying on the one side but on the other side it's like you're not alone right it should be as well comforting because we are we are all now in this process of our process of seeing the volume of the challenge and articulating what the potential business risk is so it's a journey but the important thing is that we're on track with getting there and I think we're going to be surprised about how many they are yeah and we have some other responses as well as like around 31% have said they have around 0 to 20 times and it has more than humans 23% have said they have more than 50 times human so I guess that's that's again very alarming so you need to focus on that as well so we have new votes coming in don't know has gone down to 30% but still I guess it still stays the dominant one is we need to identify how many NHS you have and then just yeah you think like 23% of the organization have found every everything they have more than 50 times so that is it's a big number but it's a volume it's significant volume wow okay great thank you thanks for because I mentioned yeah shall we go for the second absolutely yes so the second question we asked was what risk concerns you most about NHS top answer with 50% of the votes is orphaned or abandoned NHS 21% has said it's privileged escalation and 14% is tied for long-lived secrets and multiple applications using NHS so clearly orphaned and abandoned NHS seems to be the most risk that is currently concerning everyone would you see that from your point of view as from Umar's point of view when you talk with customers is this also something that you come across yeah I think that's an indication of we're very early in this non-human identity era right because at the moment the orphan the we see that 43% don't know how many NHI's there are so orphan is the problem but the better we get with these orphan accounts and orphan NHIs the more problems we're going to have with this long-lived secrets right it's with the trainee that goes from department to department to department and collects access over access right but at the moment we're not yet there to worry about those things because we have the groundwork to do but yes so that's as well where we want to attack the the challenge right and that's what is in many identity governance solutions already today it's a good start in finding those things and then qualifying and then getting an idea on how to to work with them so that's the first thing we need to do so we are on point with where the industry sees the biggest challenge I think that's a very good result for for us for understanding and and and taking the next steps I couldn't agree more yeah I agree with you I think that summarizes exactly I think what we were discussing over the last 15 minutes in this polls um I think we have 10 minutes left so I would maybe jump to some of the questions that we have from the audience as well so we have one question uh which says is um what does regular access review mean for NHIs if this NHIs especially in agentic AI can change in days not months as with humans so what would be your recommendation here um maybe I can go first um I would say in to answer shortly I would say it should be event-driven it should be the access review should be done based on the changes and not based on periodic reviews but um also that's my short answer but Thomas do you have maybe something else to add here what would be your recommendation for yeah uh reviewing NHIs yeah so I think that we need to focus on risk right and the risk and change and fast changing environments so it's and what we would like to do as well is to reduce the number of questions that you're sending out to your managers because if they have a list of 100 decisions individual decisions to take it's going to be rubber stamping but if there's every now and then five things it's much easier and much more comprehensive and allows efficiency and security at the same time and this is where we need to head and the bigger the challenge gets the more we need to focus on that so I would hope that you have um at least once a a number of questions prioritized by an AI agent that says like this is the risk this is the most relevant thing that you need to answer right now but it compresses it down to those things that are really significantly having the potential to hurt you so the more the risk and and and the risk classification of the non-human identity is that's one aspect and the other aspect is um the the speed of change and that doesn't does not mean that you have every week to recertify the same non-human identity but that you get those accesses um promoted to the highest in the list and then are able to um to to make the right decisions based on where the risk is so it's it should be down to a week weekly task weekly weekly 15 minutes that's where I would love this to to end.
I agree with that hopefully that answers our question we have another question here as well is uh which type of NHI would you focus on assuming you can't focus on all of them okay and service accounts have existed for decades agree perhaps the rise of AI agents might be an initial area of focus given the attention to AI right now in most organizations so Thomas would you maybe focus on AI agents right now for uh you can say governance as well or would you have some different approach yeah I think agents are quite important and it's it's it's a rising thing and um the the question now is um let's say like this so the stuff happens before the vendors are ready right so AI exists AI does things and then people start worrying about how about data security etc so now we have of course to catch up with um the reality that we're facing and that means that you have um those those um agents directly attached to the human having the same access rights etc and they are at the moment identical uh going forward I could see that we are evolving into a kind of delegation scenario where you can pass on some of your access rights to an agent that then is able to perform the subset of what you want to do uh with its uh within its own context um so it's it's it's something where we need to look into what is the market doing what is the market expecting and then catching up as fast as possible we have strong ideas and we think that we have good ideas for best practices but this is so quickly evolving that uh it's it's super hard to uh to say how to tackle them whether to tackle them first um and and depending on the solution that you as well are having deployed there's different answers to that but yes AI agents are one of the um highly interesting fields to look in um as first or one of the first things service accounts or machine accounts machine identities etc uh technical accounts etc have existed uh AI agents super interesting field to or to dive in next absolutely I agree with you I think with these agents you mentioned something important is that they have some sort of you can say they act behalf of on behalf of humans so if you if the NHI can sort of perform some sort of authentication on its own access some data sets then maybe that's I guess the place to start for doing the governance and I think that brings the next question as well is should NHIs ever be allowed to request or escalate their own access if so how should we control that so um this again goes back to what you said is about AI agents as well so we need to first have I think good governance in place and identify first focus on AI agents and third of service account so what maybe would you say something else no I mean ever allowed is is a very distant future so so at the moment uh I don't see that but I could imagine that in the run of the next one or two years there are going to be some requirements around that but um I I would wait for that to happen for the requirement to um come up before we solve something so um it's it's it's important to keep the level of autonomy under control much more than we do today at the moment we see more opportunities less risk and this will come to a good uh equilibrium um but yeah uh request access for for non-human identities on their own is is something that I don't see at the moment understood perfectly thank you so much um we have just a few more minutes left maybe I'll get through one more question is should uh no that we just tackle that one uh next one we have one question in the chat so service accounts have existed for the longest time and IT directors are getting frustrated with the lack of progress so should we not stop jumping to the next great thing and fix this problem I that's a very good question the fixing first the fundamental issues maybe it's the right approach but almost maybe you have something to add yeah yeah definitely um I think that we have a lack of communication between um whoops skip there's a pop-up I hope you can still hear me I think that we that that we um what I said with this aeroplane slide right now we need to make sure that we're ready to scale to accelerate and acceleration is coming and there's always going to be the next big thing but that requires us to be very honest to be very pragmatic to to the effective things to reuse best practices instead of staying in this little small chamber of technical requirements uh it's super important to accelerate the way we implement identity governance so that we're then ready to take the next big thing but the next big thing is coming and it's going to be super challenging so let's let's definitely jump into preparation for that perfect thank you so much Thomas for that just a couple of minutes left so I would like to use this couple of minutes for uh for our announcement we have just released our leadership compose on non-human IT management it's currently live on our website but along with that they're also doing several more research areas in the entire space we have a couple of notes as well so um I would encourage everyone to go on the website and check them out let us know what you think of those research materials um I think Thomas maybe you have something to add as well regarding Omada yeah right just about who we are what we do I'll keep that short um Omada is a company that provides identity governance administration solution we are very focused on that area because we think there's there's so much to accelerate we want to be the fastest in deploying uh environments into the production typically we do that within three months or 12 weeks uh we do that with an AI powered governance approach so there's a lot more than the classical uh solutions we try to reuse lots of things we learn from the um from from the projects that we have already done so what we do is not just a Lego box and build your own project but we have a building instructions guide so that we have give can give you an idea on how good looks and how 80 percent of the other enterprises have done successful implementations already so we want to be much faster much better much more prepared for the future and we're building our product for that customers of Omada are typically quite large so we have customers starting from a couple of hundred but typically starting from three to five thousand uh up to several hundred thousand um managed identity which means uh employees and contractors and suppliers what we're not doing is consumer identity management etc we have probably have millions of those managed identities but if that speaks to you reach out uh we're here we're there for a demo for giving you more insights about what we're doing why we think this is exciting um but that's so much about Omada and what we do perfect Thomas thank you so much I think we are right on time um if you have any more questions you can reach out to me or Thomas using this QR code you can reach out to us on LinkedIn or these are our email ids as well so happy to take this conversation offline as well the very interesting space which is going forward evolving in a very rapid space I think uh I would like I will be interested to see how the space evolves and so see what doing in the future thank you thanks Nitish that's great perfect thank you so much for everyone's attendance then we'll see you at the next webinar thank you so much thanks see you soon
See All Locations
See All Locations