So, the topic for my presentation is almost human. So, everybody's talking the last few many years around human, hey, I'm a human, I will protect my other humans inside my company, we are investing a lot of money inside of MFA, we are investing money in a lot of stuff, but now we are here to talking about AI, right? That's why you're here, because you love AI, correct? You love this little person who is your co-pilot.
So, sorry, I am Microsoft-influenced a little bit, this is why it's my co-pilot for today. So, we love our co-pilots, we love our agents, which are helping us, flying us inside of our environment, make sure that we get more productivity, make sure that we can do the stuff that we need to do inside of our daily life, inside of our personal life, and inside of our organization, communication, which is supporting us. But maybe someday it can get evil.
Maybe, I would say it, I can guarantee you to 100%, someday you will face an evil AI agent, and it's not friendly anymore. The reason is, it's maybe not friendly, because maybe your AI is shouting at you and saying, yeah, you're doing stupid stuff. This will maybe not be the case. But it could be that with too high privileges, with too many activities that the AI agent have inside of your organization, within your personal life, that it's becoming from this to this, and this is maybe not cool.
This is something that you need to protect and be aware of it, and that is why I'm talking about this stuff. So, short introduction to myself, thanks for presenting myself.
So, my name is Tim Wolfe, I'm working for St. Paris. We are doing everything around identity, making sure that your identity provider is on a safe state, making sure that whatever happening, that you can recover, and at the end of the day, we are also talking about evil identities, because maybe it could be that our friendly or evil person is maybe compromised, and you need to recover it.
So, something also starting, not just talking about the fancy cool stuff, maybe also talking about the basics. So, because, hey, AI has cool functionalities, but thinking all about your daily IT life, you're all thinking about, you should thinking about the basic functionalities. What kind of permission does it has? It's not just the value, it's just all around, hmm, what kind of permission? What is the access? What kind of networking? What DNS? We're all thinking about that in our daily life, and we sometimes forget, because the fancy new stuff is AI.
So, the problem with AI that we are facing over the last many years is that AI is outrunning us a little bit. Just a little bit. Did you have any idea of, or when was the last time you checked inside of your identity provider? What is the quote between real human identities, so the person that you're paying money inside of your organization, compared to non-human identities? When was the last time you really checked this? Are you guessing it? Has somebody a proof number to say, hey, yeah, we currently have a ratio between one and blah blah? Did somebody ever check this? Yeah? Cool.
Is it something below 10? So, ratio between one and 10.
So, let's say you have 10 employees, and you have 100 non-human identities. So, it's the ratio one between 10. Yeah? Is it higher? Okay.
So, then you're maybe in a lucky position that you're lower. So, you're maybe on a ratio one to one. Maybe. But there are many reports on the market, and this is an old report, but they believe, and they say, in 2026, this is today, it's not something in the future, it's today, that it will be outrunning the ratio between human identities to non-human identities by 100. Don't forget it. How many employees do you have in your organization? Add two zeros. Pretty simple. It's not complicated. And this is something you should thinking about.
Okay, maybe it's a high number, it's maybe license fees that I need to take care of on that. Think about all of your stuff around that.
So, just a quick checkup. What is a non-human identity? I hope everybody already know it, but just to make a quick checkup. Non-human identity is not only an AI agent. It can be something, let's check it out. Wait. It can be an API key.
Yeah, it's the stupid developer stuff, API keys, we don't care about, we're identity people. No, no, no, no, no. It's for you, it's something you need to take care.
So, AI keys, service accounts, cloud tokens. Again, it's developer stuff, but it's also something that you all, everybody who's working in identity, everybody who's working in security, should think about, hey, what's happening with my token? Because at the end of the day, the token is like my driver license. Wherever I have this information, can do some evil stuff with that. And this is what you think about, and this are, at the end of the day, not maybe just AI stuff. It's non-human identities.
So, this is around AI, but it's also the basics are non-human identities. Something you need to take care about.
So, the big problem that we, or that I'm facing over the last years is, what you're expecting from security side of life. We all know, and we all are experts in identity access management, in security. We are applying really good stuff. We have our users, which are protected by MFA. I assume everybody, all of you are using MFA. Somebody's willing to raise their hand to say we have no MFA?
Fantastic, I love it. You got a sticker if you want to at the end of the day.
So, MFA, it's something important. We are requiring it for all of our users. What's for non-human identity? MFA for non-human identity? Make MFA on my mobile phone? No? Maybe in the near future with robots, they can, there's a robot, click on it here. I approve my MFA request. Is it something we want? No? I don't think so. It's around life cycle stuff. How long should a non-human identity stay inside of your environment? Is it maybe for a short amount of time where you say, hey, yeah, I give it some specific permission, it's running stuff, it's running stuff, it's running stuff.
Did it ever end? I would say yes. So you should also thinking about what's about your joiner, mover, lever processes, not just for real people, also for your non-human identities. There's some day where you cut off AI agents with permissions because it's running out of business. It's maybe not necessary functionality value in your organization. Maybe it exists forever? I would say in many organizations, it lives forever. How about these privileges? Are you fine with that, that you give a non-human identity directory rewrite all permissions to it?
I hope you say no, because otherwise you have a big problem. Because what does directory rewrite all means? It can basically bring you into a big trouble because it can wipe out your full environment. Is it something you want? No. So going to the next step, it's also on governance. So we see where there are coming many topics together. We're talking about governance. Who is the owner of a non-human identity? Who is the person who's maybe paying for it? Because again, thinking about on the user side of life, we know who's the manager, who's paying for it, on which kind of payroll they are on.
We know this. For non-human identity, yeah, someone is generating it. Who's paying for it? I don't really know.
And sadly, I don't really care around this, but we should care around that. So what are maybe the solutions for this? Thinking about for non-human identity, there shouldn't be credentials in best case. And I say in best case. In a realistic world, we see there are a lot of credentials. So we need to protect also credentials. You can or you should apply the same life cycle that you have for users to your non-human identities. To be really honest and to bring it down to the basic, it's not that complicated. There are many tools on the market.
There are many tools outside which do a really great job. Bring outside into the pavilion, have some conversations with Mr. Non-Human Identity. There are great functionalities on the market to apply same life cycle stuff to also to your non-human identities. Same for privileges. It is not that complicated. Also for governance. To generating this presentation was pretty easy because yeah, same stuff on the left side that you have on the right side. So now the problem is, now we have a good feeling about, okay, how they are working, how they should work.
Let's analyze a little bit around how they attack, how non-human identities attacking your environment, your infrastructure, your payment system, your provisioning, your personal data inside your environment. So this is just an example. I will talk in a little bit. I see it was maybe not the best choice to make it in dark mode. So I'm more or less also a developer, so I'm choosing dark mode. Let me quickly explain what will happening on during the demonstration. This is just a really short example of how easy a non-human identity and what you can test attack your environment.
So what you see inside of this presentation is more or less, I'm giving a secret. I'm giving a username and a password because a non-human identity and an AI agent is at the end of the day, just something similar to a username and a password, something you identify and somebody, you have a secret for it. Same terminology can be applied to non-human identities.
Okay, cool. So let's go back that you can see it maybe better, that I can explain it a little bit more. So if you have these two types of information, the identifier and the secret, you can sign in. This is what's happening on the slide at the moment.
It's, I'm typing in inside of PowerShell, just a few commandlets. And again, I'm Microsoft biased, so we see something Connect MG Graph. To connecting, let's see if I can stop it perfectly. So what's happening, I'm connecting against Microsoft Graph, against Entra ID, the major identity provider that many of us has. And the problem is, I was the human who's sitting in front of the device, but the system, Entra ID, is not seeing my identity. It's seeing just something, financial analytic dashboard. Is that something which is a human? Not really.
It's something inside of your systems, an analytic dashboard, some things which get maybe the numbers from your organization. How much revenue you make? Is this information of how much revenue you make something that should go public? Maybe not. Someday it will be public, but at a specific point, if it will be public today, and it's still not public available, there can be insider trades, various information that should not be handled. I'm authenticated as my dashboard. So I'm as a human who maybe not have this information. I'm a developer in a company.
I should not have permission on our financial revenue information. But sadly, I am authenticated as this dashboard. So I know all of my revenue information for the organization, and I'm signed in. And what I can also do is then updating all of the stuff that this financial dashboard has permission to it. So not really good to have it. So this was just a demonstration of, let's say, the old staff world, non-human identity.
It was, at the end of the day, just the access to a client secret, to a secret which gives me the power to sign in as a username and a password against my identity provider. Was there any kind of MFA? No. Is somebody governing it? Not really. Is there some kind of protection? Not really. So at the end of the day, what's happening here, it's a simple thing everybody knows, but the less people realize and implementing it inside of the journey through AI, the basic functionalities, losing the credential, losing the secret of a non-human identity can leak into a big problem for your organization.
So go a step back, the fancy AI stuff. I know everybody's running for fancy AI, but you should maybe go a step back and thinking about, hey, this fancy AI stuff, the identity technology in the background already exists many, many years before. Did you take care of that in the past? Not that much from what I see during our assessments that we are performing with organizations. And now AI is happening. Is it getting easier, complicated?
No, it's getting easier, I would say. So this is just an example how it affects not just your business life, but also maybe your personal life. How easy it is to combine all of the connections in the background. This is just a really simple example what you can have here is, hey, I'm connected my Gemini account with my flights. And maybe behind my flights, there's also my payment method. Is it something that an AI agent should handle alone by themself? Did I trust him really to give my payment information? Personally, no. If you want to do it, have fun with that.
But also thinking for your personal life, thinking about organizational stuff, it could be a problem. Something that I found also out was I was using multiple AIs, no authentication. Not cool. No authentication means at the end of the day, yeah, everybody can access to this endpoint. Is this cool? Not really. Is this just a basic thing that everybody should be aware of it?
Yeah, this is why I'm bringing it into the session. There are maybe application which are in the front end visible, easy to configure.
Hey, there's an MCP server, blah, blah, blah. Public DNS, giving a name, no authentication.
Yeah, cool. Gemini can do and maybe others can signing into your connector, which is maybe payment information for your organization and have access to the stuff. Is it cool?
No, not really. Another example is for Claude. They did a fantastic job with connectors. They make it even simple for you to reach your payment information. Do you see it? PayPal? It's just a few clicks and then Claude has access to your PayPal. Is this fine? Do you really want this? Do you want to govern it?
Of course you should govern it because it would be really sad that let's say Claude make a decision in one year to do some stupid stuff that, hey, organization or personal life people who has access, give Claude access to their PayPal, could maybe do something in the background that Claude make the decision, hey, I'm buying PayPal with PayPal money from all of my users. Not really cool. Something you should take care and have in your mind. This is something you should thinking about.
So what are the different kind of solutions, how to protect against that and protecting you for this and making sure that you have solutions for this? So first of all, in best situations is no secrets.
Whenever possible, whenever a developer is asking for, hey, I need a client idea and some kind of secrets, you should first refuse it and tell them, hey, there's maybe a better option because with secrets, there's a lot of functionalities in the backgrounds that you need to govern them, that you need to roll over them, that you secure them, that they are not published on GitHub, like what's happening, what was the service that was last week breached by a public API key? There was a big one. Sorry? One example, yeah. There was also another, yeah, but it's fine.
So it's also something that you need to protect and first reject it and say, hey, is there maybe a better solution for this? Have some conditions when they are assigning. Many tools, AI agents, where you can define, hey, from which location under what kind of conditions you are allowed to sign in. You don't want to have that your PayPal MCP server is accessing your data from China, from Russia, from wherever in the world. This is something maybe you want to limit it. There are really great conditions behind it. Governance.
Use the same governance functionalities that you apply for normal users to your AI agents or to also your non-human identities. Logging. Everybody's doing logging, I would say. Who is really reading the logs? Not that much. Not that many persons. But this is really helpful that you can understand, hey, where are my agents are coming from, what they are really doing, and then you can make decision and define, hey, is this something approved? Is this something unapproved? Maybe I need to design, maybe redefine, and maybe I need to also apply new conditions to it. Logging is really helpful.
I know nobody loves logging, but we should apply this and also read them. Knowledge. Train your people, train your developer, train your administrator to apply all of, no secrets, condition, governance, logging, that they not just say, hey, please give me user client idea and a secret.
And then, yeah, here, it has a lot of permission. Have fun with that. Not cool. Train them and say to them, hey, you're with great power, great responsibility is coming.
Yeah, they should know this and apply to them and say, hey, okay, I give it to you, but you are now the owner of it. You are now responsible. Whatever happening here, it could be a new problem. Ownership.
Again, tell them, if you know, if you have it, you own it, whatever happening there, you can make maybe responsible for that. And yeah, train your developer.
So yeah, it's again, make sure because architects, designers, they are not really thinking about what's happening with, they are just thinking about the cool, shiny AI stuff. Your developers need to implement them and implement all of the stuff at once in a really good way. And last but not least, detect what's happening there.
Again, there are many fantastic tools on the market, which helps you to analyze what kind of permission your non-human identities have and what they are doing. Because at the end of the day, if there's a non-human identity with that much permission, but it never used them, it's maybe fine and you can clean it up. But what is if a non-human identity has just this kind of permissions, but they are really high critical, they can destroy your full business environment. Just one single non-human identity, one single AI agent can destroy your full infrastructure if you do not take care of this.
Just a few highlights. I hopefully everybody knows of them. At the end of the day, thinking about, take a step back, don't look at the shiny future around AI. Go back to the basic and say, hey, how my non-human identities are interacting with each other. And I hope this was some insights, you hear a lot of topics during this conversation, during this conference. I hope you take something back and if you're leaving the door, it's not refreshing your mind, it's like, okay, going a step back, thinking about what are my non-human identities in my organization. That's me.
Thank you very much for being on time. I don't know, do we, we don't have any questions online just yet. Do we have any questions in the room for Tim?
Come on, it was an amazing presentation. You guys must have some kind of question.
Okay, let me ask you one. Many organizations still have limited visibility into their service accounts and their application identities. In your experience, what is the biggest blind spot that attackers exploit most frequently in AD and intra-ID environments?
Um, it's around the basic applications that everybody say, hey, yeah, they are there since many, many years. We believe they are governed. Nobody has ownership. Make sure which application has no ownerships and then really analyze, oh, maybe they was created 10 years before. These are the first one that you really should take care of it. Fantastic.
Okay, everyone, round of applause again for Tim Wolf. Thank you. Thank you.