Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Passwords and employee logins are no longer the main population of identities in many cloud environments. Software workloads, service accounts, applications and AI agents now authenticate, hold permissions and take actions, and they often do it without the joiner, mover and leaver processes that keep human accounts in check. The evidence supports two conclusions: this non-human layer is growing, and governance of it is often weak. It does not support a single global count of machine credentials, or the claim that every organization is losing visibility at the same rate. This article sets out what the layer contains, what the numbers show and don’t show, and which controls the standards and vendor documentation point to.

What does the expanding credential layer include?

“Credential layer” is a convenient umbrella, not a formal standard term. It covers three things that are easy to blur together, and separating them clarifies where visibility breaks down.

  • Identity: the software principal or actor, such as an application, microservice, container, service account or AI agent. Microsoft defines workload identities as identities assigned to software workloads such as apps, microservices and containers.
  • Credential or token: what the identity uses to authenticate or assert access. This can be a long-lived secret such as an API key or password, or a short-lived token issued on demand.
  • Permissions: what the identity is allowed to do once it is authenticated.

Not every machine identity is an API key. Workload identity systems can issue tokens without any long-lived secret, which is exactly the property NIST’s recent guidance favors (see below). Visibility therefore means more than a list of secrets. It means knowing which identities exist, who owns each one, what each can reach, and when its credentials should expire or be revoked.

Microsoft’s Digital Defense Report 2026 frames the defensive identity control plane as spanning both human and non-human identities, including applications and agents. The perimeter, in other words, is now defined by who and what can authenticate, not only by who is on the network.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How big is the non-human identity population?

No source establishes a universal figure. The best-documented data point is a vendor sample from Microsoft’s 2024 State of Multicloud Security Report, which drew on Microsoft Entra Permissions Management customer clouds and describes findings from 2023.

Measure Value Qualification
Identities discovered 209 million Across Entra Permissions Management customers’ clouds, 2023
Workload identities 174.3 million Same sample
Human identities 34.5 million Same sample

Workload identities outnumbered human ones by roughly five to one in that sample. Treat it as an indicator of direction, not a census: it covers one vendor’s customers who chose to deploy a permissions-management product, and it reflects 2023, not today.

How well do organizations manage non-human identity credentials?

The SANS Institute’s 2026 State of Identity Threat Detection and Response survey (key findings published March 2026) offers the clearest practitioner view. SANS describes its respondents as predominantly US-based, with additional participation from other regions, so these are survey findings and not universal rates.

  • 75% of surveyed organizations saw growth in non-human identities.
  • 73% reported using agentic AI or automations that require credentials.
  • 8% rotated most of their non-human identity credentials every 90 days.

Read together, these describe a population that is expanding while routine hygiene lags. They should not be merged into a single statistic. The Microsoft figures measure discovered identities in customer clouds, while the SANS figures measure what respondents say about their own organizations, and the two use different samples and years.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How often do organizations rotate non-human identity credentials?

Rarely on a tight schedule, according to the same survey: only 8% of respondents rotated most of these credentials every 90 days. The finding does not say how the other 92% rotate, whether they rely on short-lived tokens that never need rotation, or which credential types are involved. Low rotation frequency is a warning sign for static secrets, but it is not a problem for credentials that expire in minutes by design.

Why does visibility fail for workloads and agents?

Human accounts come with natural lifecycle signals: a hire date, a manager, a departure, a password reset prompt. Software identities usually have none of these. Microsoft’s 2024 multicloud report points to several consequences:

  • Silent inactivity. Workload identities can gradually become inactive without anyone noticing, and the report notes that inactive identities can create opportunities for lateral movement.
  • Monitoring gaps. Identities created by automation can be missed by the tools and reviews built around people.
  • Embedded credentials. Secrets written into code complicate cleanup, because revoking one means finding every place it was copied.

The practical result is that an inventory problem comes first, and a permissions and rotation problem follows. You cannot rotate, scope or retire an identity nobody knows about.

What do AI agents add?

Agents add an ownership and attribution problem on top of the existing one. Microsoft Learn’s Entra security for AI overview describes agent sprawl as expansion without adequate visibility, management or lifecycle controls. It also notes that agents may have their own identities or operate with a user’s capabilities, which complicates the question of who actually performed an action.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft Learn highlights two specific risks. Agents created for temporary purposes can remain in production long after the task ends, and their permissions can exceed what the task requires. Both are classic stale-identity and over-privilege failures, now occurring at a pace set by how easily people can create agents rather than by an access-request process.

Why are organizations still getting breached despite widespread ITDR adoption?

The available evidence does not give a complete causal answer, and it would be a mistake to invent one. What the SANS survey does show is that detection and containment are separate operational measures: 68% of organizations said they detect identity attacks within 24 hours, but only 55% said they contain them within that window. An alert that is not followed by fast revocation, session termination or permission removal leaves the attacker time to work.

That gap interacts with the findings above. If the identity behind an alert is unowned, holds a long-lived static secret, or has broader permissions than it needs, containment becomes slow and uncertain even when detection is fast. Teams evaluating their own exposure should therefore measure time to contain and time to revoke separately from time to detect.

What does NIST now recommend for workload credentials?

NIST published NISTIR 8587 on September 15, 2026, with implementation guidance on protecting tokens and assertions. It covers workload access, token verification, key management and lifecycle controls. The accompanying NIST Computer Security Resource Center announcement (created September 14 and updated September 16, 2026) says:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

“This document now integrates considerations for the use of tokens in workload identity scenarios – reinforcing the need for short-lived tokens rather than reliance on static credentials and secrets.”

This is attributed to the NIST IR 8587 announcement, not to an individual. The direction is clear: where the platform supports it, prefer tokens that expire quickly over secrets that live for months.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Practical controls the sources support

1. Discover and assign ownership

Inventory identities across cloud accounts, applications, service accounts and agent deployments, and record an accountable owner and a purpose for each. Microsoft documents the lifecycle and ownership risks, and NIST emphasizes lifecycle controls.

2. Reduce permissions

Review what each workload or agent can reach and cut it back to what the task needs. Microsoft Learn documents excessive agent permissions, and the Digital Defense Report 2026 emphasizes unnecessary privilege and identity hygiene.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

3. Prefer short-lived tokens and protect signing keys

Move from static credentials to short-lived workload tokens where supported. Where tokens are issued, protect the signing keys through secure storage, controlled usage and automated management, as NIST’s guidance describes.

4. Verify, log and correlate

Verify tokens and assertions, keep audit trails, and connect identity signals to the surrounding telemetry. NIST covers token verification and continuous monitoring. Microsoft’s Digital Defense Report 2026 highlights the value of correlating identity, cloud, endpoint, application, email and network signals.

5. Measure revocation, not just detection

Track how long it takes to contain a compromised identity and to revoke its credentials, separately from how long it takes to notice. The SANS 68% versus 55% gap shows why.

These are control directions drawn from standards and vendor documentation. None of the sources claims that a particular product delivers complete visibility on its own.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to evaluate a program or tool

The sources do not include a neutral vendor comparison, so no product ranking is offered here. They do support a set of questions that apply to any approach.

Axis What to ask
Coverage Which identity types and environments are seen: cloud workloads, service accounts, applications, agents?
Inventory and ownership Is the inventory complete, and does every identity have a named owner and purpose?
Lifecycle Are inactive or stale identities found and retired, including temporary agents?
Permission scope Can permissions be reviewed and reduced to actual need?
Credential lifetime Are short-lived tokens supported, signing keys protected, and revocation fast?
Attribution Do audit trails show whether an agent or the user it acts for performed an action?
Detection and containment Can misuse be spotted across connected telemetry and contained quickly?

What the evidence does and doesn’t establish

  • It supports growth in non-human identities and gaps in governance, particularly rotation, ownership and lifecycle.
  • It does not provide a global count of machine credentials.
  • It does not show that all organizations are affected equally; the SANS results are survey-based and US-weighted, and the Microsoft figures are a vendor customer sample from 2023.
  • It does not explain breaches despite ITDR adoption beyond the detection-versus-containment gap noted above.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.