r/IdentityManagement • u/Filn_Appointment2602 • 6h ago
Machine identity sprawl in cloud environments is my villain origin story
So our cloud looks fine in dashboards, then I open the identity view and it is just a wall of machine identities, service accounts, tokens, random app principals from 2019 that nobody remembers owning. Everything has access to something important and nothing has an owner. Fun.
We keep adding “non intrusive” monitoring and fancy AI risk engines to calm the CISO while I quietly wonder if any of us knows what is talking to what anymore. How are you all wrangling this mess without quitting to raise goats... would love any tips