BeyondTrust Extends Privileged Access Leadership

Share

The Problem: The Privileged Surface Changed. Controls Didn’t Keep Up.

The industry’s response has been to inventory them. But a longer list is not a control. The risk was never just that an identity exists; it is also, and especially, the privilege that identity holds and everything that privilege can reach. 

The recent wave of SaaS-to-SaaS software supply chain attacks made that abundantly clear. Attackers increasingly compromise the OAuth tokens trusted between applications, allowing legitimate access to data at scale. No malware, no escalation, no human in the loop. Every action reads as authorized because it was. Discovery and visibility alone do not stop an attack. Stopping the exfiltration requires controls to be executed ahead of the incident: access already scoped down, the token already rotated, or the unused identity already retired before the attacker arrived.

“Seeing non-human identities was only half the equation,” said Marc Maiffret, Chief Technology Officer, BeyondTrust. “The other half is doing something about the privilege they carry at scale: deciding who owns each one, pulling back the privilege they aren’t using, and retiring the ones that should not exist. And doing so without requiring teams to address them one by one with the limited time they have. That’s not paperwork you bolt onto a tool built for employee onboarding. That’s managing non-human identities at machine scale.”

Helping Customers Move from an Inventory List to Real Control

NHI Governance is built to execute the non-human equivalent of joiner, mover, leaver actions that actually reduce risk, in the right order:

  • Establish ownership. Every non-human identity is assigned to a person or a team who is accountable for it, so nothing runs unowned.
  • Decommission NHIs. Retire the stale, orphaned, and abandoned identities that make up most of the ungoverned population, so the attack surface shrinks instead of growing unchecked.
  • Secure AI Agents. Bring them under the same controls, with their own credentials and their own access.

Built on Two Decades of Privilege Enforcement

NHI Governance builds on that foundation by turning visibility and credential management into lifecycle governance that establishes ownership, enforces least privilege, and reduces identity-based risk.

Availability

NHI Governance is planned for US general availability in Fall 2026, with other global regions to follow. 

Featured News

Newsletter Subscription

Join our mailing list