63 views
2 hours ago

BeyondTrust launches NHI Governance to secure non-human identities

Marc Maiffret, Chief Technology Officer, BeyondTrust.
Marc Maiffret, Chief Technology Officer, BeyondTrust.

BeyondTrust has launched NHI Governance on its Pathfinder platform, a new solution designed to manage non-human identities (NHIs) across cloud, SaaS, and on-premises environments. As API keys and AI agents increasingly outnumber human employees, this tool establishes ownership, enforces least privilege, and decommissions stale identities to reduce the enterprise attack surface.

The Problem: The Privileged Surface Changed. Controls Didn’t Keep Up.

Service accounts, API keys, OAuth clients, workload identities, and AI agents now hold most of the standing privilege in the enterprise, and they outnumber the people. BeyondTrust Phantom Labs™ research found that non-human identities already vastly outnumber human ones, with enterprise AI agents growing more than 460% year over year. Almost none are ever assigned an owner; their privileges are rarely reviewed, attested, or rightsized; and their credentials are seldom rotated or retired. They are granted access on the day they are created and often retain that access indefinitely.

The industry’s response has been to inventory them. But a longer list is not a control. The risk was never just that an identity exists; it is also, and especially, the privilege that identity holds and everything that privilege can reach.

The recent wave of SaaS-to-SaaS software supply chain attacks made that abundantly clear. Attackers increasingly compromise the OAuth tokens trusted between applications, allowing legitimate access to data at scale. No malware, no escalation, no human in the loop. Every action reads as authorized because it was. Discovery and visibility alone do not stop an attack. Stopping the exfiltration requires controls to be executed ahead of the incident: access already scoped down, the token already rotated, or the unused identity already retired before the attacker arrived.

“Seeing non-human identities was only half the equation,” said Marc Maiffret, Chief Technology Officer, BeyondTrust. “The other half is doing something about the privilege they carry at scale: deciding who owns each one, pulling back the privilege they aren’t using, and retiring the ones that should not exist. And doing so without requiring teams to address them one by one with the limited time they have. That’s not paperwork you bolt onto a tool built for employee onboarding. That’s managing non-human identities at machine scale.”

Helping Customers Move from an Inventory List to Real Control

NHI Governance is built to execute the non-human equivalent of joiner, mover, leaver actions that actually reduce risk, in the right order:

  • Establish ownership. Every non-human identity is assigned to a person or a team who is accountable for it, so nothing runs unowned.
  • Enforce least privilege. Lock down the identities that hold real privilege, and constrain what each one can reach, closing the paths to privilege it was never meant to have.
  • Decommission NHIs. Retire the stale, orphaned, and abandoned identities that make up most of the ungoverned population, so the attack surface shrinks instead of growing unchecked.

Secure AI Agents. Bring them under the same controls, with their own credentials and their own access.

Built on Two Decades of Privilege Enforcement

For more than two decades, BeyondTrust has helped organizations reduce identity-based risk by governing privileged access across their most critical systems. Non-human identities are no exception. Identity Security Insights already provides industry-leading visibility and intelligence across non-human identities and the privileges they hold, while BeyondTrust Password Safe  secures, manages, and rotates the credentials behind them.

NHI Governance builds on that foundation by turning visibility and credential management into lifecycle governance that establishes ownership, enforces least privilege, and reduces identity-based risk.

Part of the BeyondTrust Pathfinder platform, NHI Governance builds on the recent introduction of AI Agent Security, further unifying discovery, governance, and enforcement within a single platform to secure privilege consistently across every identity capable of privileged action.

Leave a Reply

Latest from Blog

(L-R) Ehab Aljabri, Projects Manager, Fujairah Digital Government; Yousuf Alkaabi, Government Communication Manager, Fujairah Digital Government; Dr. Ahmed Hassan Almurshidi, Director of Fujairah Geographic Information System Center, and Sheikh Eng. Mohammed bin Hamad bin Saif Alsharqi, General Director of Fujairah Digital Government, met with Marwan Zeineddine, Managing Director, SAP UAE, and SAP executives at the launch of the SAP YPP initiative.
(L-R) Ehab Aljabri, Projects Manager, Fujairah Digital Government; Yousuf Alkaabi, Government Communication Manager, Fujairah Digital Government; Dr. Ahmed Hassan Almurshidi, Director of Fujairah Geographic Information System Center, and Sheikh Eng. Mohammed bin Hamad bin Saif Alsharqi, General Director of Fujairah Digital Government, met with Marwan Zeineddine, Managing Director, SAP UAE, and SAP executives at the launch of the SAP YPP initiative.

Don't Miss

BeyondTrust’s 13th annual Microsoft vulnerabilities report reveals drop in total volume, but surge in critical risk

BeyondTrust, the global leader in privilege-centric identity security protecting Paths to Privilege, has
Fletcher Davis, Director of Research for BeyondTrust Phantom Labs

AI coding agent flaw exposed: GitHub tokens at risk

Researchers at BeyondTrust Phantom Labs have identified a critical command injection vulnerability

Welcome to

By signing or creating an account you agree with our Code of conduct & Privacy policy