Agentic & Non-Human Identity Security · Microsoft

Raj Penchala

Securing non-human and agentic identities — where identity meets AI.

Machine identities outnumber humans 82:1 — and AI agents just added autonomy. I secure them.

Latest articles

RSS
Non-Human Identity

What 614 Non-Human Identities Taught Me — and the False Positive That Almost Cried Wolf

I pointed nhi-scan at a real Entra tenant with 614 non-human identities. The 80:1 ratio became a worklist — and the top finding was a false positive: 53 "long-lived secrets" that were really 1. What a real NHI scan reveals, and why context beats raw counts.

4 min read
Non-Human Identity

Making an NHI Scanner Production-Ready: What a 600-Identity Run Taught the Tool

Running my NHI tool against a real 600+ identity Entra tenant exposed three things unit tests missed: it didn't run on Windows, the enriched scan took 40 minutes, and it mistook managed identities for stored secrets. The fixes — including a 20x speedup — and why dogfooding matters.

3 min read
Non-Human Identity

What an AI Agent Must Never Be Allowed to Do

Buried in a Microsoft Graph reference is a list of permissions that cannot be granted to an AI agent identity at all. Read backwards, it's the first enforced authority model for agents — six prohibitions worth applying to every agent platform you run, not just Entra.

5 min read
MCP

MCP Triage: Turning Scanner Noise Into a Six-Item To-Do List

MCP security scanners are smoke alarms that go off every time you make toast — one audit found 21 of 27 alerts were false. mcp-triage is the layer that sits on top of any scanner and sorts the noise into the handful that matter, then governs the fleet against the OWASP MCP Top 10.

5 min read
Non-Human Identity

Drift Detection for Agent Identities: When Reach Grows and the Tier Doesn't Move

An AI agent's reach is the one thing that can grow without anyone touching the identity — give it a new tool or connector and its blast radius expands while privilege, credential age, and owner all look unchanged. Here's why point-in-time posture scans miss it, and how to close the gap.

3 min read
Non-Human Identity

A Control Framework for Non-Human & Agentic Identity

A practitioner control framework for governing non-human and agentic identities: eight principles, a four-tier risk model, thirty-five controls across eight domains, an agentic threat model, and a maturity model — mapped to OWASP NHI Top 10, NIST AI RMF, CSF 2.0, and 800-53.

13 min read
Non-Human Identity

The Non-Human Identity Reckoning — and Why Agents Make It Urgent

Non-human identities are the enterprise's largest and least-governed identity population, and AI agents just added autonomy to the problem. Here is why the next identity crisis is already here — and the discipline that answers it.

3 min read
Agent 365

Understanding Azure AI Foundry Agent Identities, Blueprints, and Entra ID Object Relationships

A practical identity architecture guide for security, governance, and troubleshooting

9 min read
Microsoft

AI Red Teaming for M365 Copilot & Bing Chat Applications

These applications fall into two distinct layers — each requiring different red teaming, and both are required.

8 min read
Microsoft

The MDASH Blueprint: Defence at AI Speed

A visual blueprint of MDASH — Microsoft's Multi-Model Agentic Scanning Harness — an autonomous system that discovers, validates, and proves software vulnerabilities at AI speed. The system, not the model, is the product.

3 min read