Govern and Posture

Nobody owns this account

Every service account, key and token gets a name against it.

Non-human accounts by classification, with the dormant one that still holds admin

What the industry reports

  • 82 to 1machine identities to human identities inside the average organizationCyberArk 2025 Identity Security Landscape
  • 44%growth in non-human identities in a single yearEntro Labs, H1 2025
  • 87%of the identities holding unused sensitive permissions are machinesSonrai, enterprise cloud tenants
The moment

The deploy account was created for a migration two years ago. The engineer who made it has left. It still holds Directory.ReadWrite.All.

For the platform team that inherited them.

Classification comes from behavior

Service, break-glass, shared mailbox and resource accounts are told apart by how they are used, whatever they were named.

They sit in the same graph as the people

A dormant deploy account holding Global Administrator is comparable to a person holding it, because reach is measured the same way for both.

Dormant comes with a date

Last sign-in travels with the account. An account with no sign-in in four hundred days is a different conversation from one running every hour.

What you get

Everything this covers.

  1. Discovery and inventory

    • Every service account, key and token in the directory and the applications
    • Accounts matched automatically, and linked by hand where they are not
    • Re-classified on every sync, one account at a time
    Three accounts resolving to one person, with the match method on each link
  2. Classification and ownership

    • Service, break-glass, shared mailbox and resource accounts told apart
    • Classification from how the account behaves
    Accounts broken down by classification, human and non-human
  3. Entitlements and reach

    • Non-human identities sit in the same graph as the people
    • Blast radius comparable between a person and a service account
    • A last sign-in date on every account, human or not
    What one compromised account reaches, through every group and role in between

See it on your own tenant.

Connect your directory and see findings the same day.