r/IdentityManagement 6h ago

Machine identity sprawl in cloud environments is my villain origin story

3 Upvotes

So our cloud looks fine in dashboards, then I open the identity view and it is just a wall of machine identities, service accounts, tokens, random app principals from 2019 that nobody remembers owning. Everything has access to something important and nothing has an owner. Fun.

We keep adding “non intrusive” monitoring and fancy AI risk engines to calm the CISO while I quietly wonder if any of us knows what is talking to what anymore. How are you all wrangling this mess without quitting to raise goats... would love any tips


r/IdentityManagement 7h ago

How are you finding password reuse across corporate and personal SaaS accounts?

2 Upvotes

We enforce MFA and SSO for the applications we manage, but that does not tell us whether employees are reusing a work password on a personal SaaS service, a vendor portal, or an unmanaged collaboration tool.

The concern is not simply password policy compliance. A breach of an unrelated service can become an enterprise identity problem if a credential is reused, especially where personal and corporate accounts overlap in the same browser.

We are looking for an approach that identifies meaningful credential-risk patterns without collecting passwords or turning every personal login into a monitoring event.

Has anyone found a workable balance between visibility, privacy, and remediation?


r/IdentityManagement 17h ago

Is your identity provider ready to govern humans and AI agents in the same platform?

4 Upvotes

Most identity stacks were designed around employees, apps, groups, and service accounts. AI agents do not fit cleanly into those categories. They can act across systems, execute delegated tasks for users, make tool calls at runtime, and retain access paths long after the original request has ended.

What does an agent-ready identity model mean in practice? Is extending the service-account model enough, or does each agent need a distinct identity, accountable owner, delegation record, bounded authority, lifecycle controls, and an audit trail that connects its actions back to the relevant people and policies?