Identity About to Expire

Risk Category

Lifecycle Management

Risk Description

Expiring NHIs may cause major operational issues and security gaps. Learn how to manage them before serious problems arise.

Why It’s a Risk

If an identity unexpectedly expires, critical processes and services may experience unplanned downtime, leading to operational inefficiencies and potentially affecting revenue and service delivery. Additionally, expired identities may inadvertently continue to function if expiration controls are not properly enforced, increasing the risk of unauthorized access.

Likelihood of Occurrence

MODERATE

Medium, particularly for organizations that rely on manual tracking of credential expirations.

Impact Level

MODERATE

Medium, as expired identities can lead to unplanned downtime, disrupt operations, and pose security risks.

Mitigation Strategy

Proactively manage identity expiration through advanced lifecycle management mechanisms including alerts and a streamlined process for renewing or decommissioning identities before they expire. Ensure continuous validation of expiring identities consumers through a Zero Trust approach to avoid access to expired credentials who continue to function.

Playbooks in Clutch

110

Applies for:

  • Cloud Service Provider

    AWSAzureGCP
  • Vault

    AWS Secrets ManagerGCP Secret ManagerHashicorp Vault
  • Source Manager

    BitbucketGithubGitlab
  • CI/CD

    CircleCIGithub ActionsJenkinsTeamcity
  • Password Manager

    1PasswordLastpass
  • EDR

    CrowdstrikeSentinelOneMicrosoft Defender
  • Data

    AWS RedShiftMongo DB AtlasMySQLPostgreSQLSnowflake
  • Network

    AkamaiCloudflare
  • PaaS

    AKSEKSGKEK8S
  • Collaboration

    Atlassian ConfluenceNotion
  • Project Management

    Atlassian Jira
  • Log Analytics

    DatadogElasticSplunk
  • IDP

    Google WorkspaceJumpCloudMicrosoft Entra IDOkta
  • CRM

    HubspotSalesforce
  • MDM

    IntuneJamf
  • IM

    Microsoft TeamsSnowflake
  • Ticketing

    ServiceNowZendesk
  • Automation

    TinesTorq
  • HRIS

    Bamboo HRHiBob
  • SIEM

    Exabeam (LogRhythm)Sumo Logic