Free NHI Risk Assessment
Discover risky service accounts, keys and AI agents in minutes
- Read-only
- Runs in your browser
- No data leaves your machine
- No installation required
Request your free assessment
Tell us where to reach you, and we'll set up your assessment.
What the assessment gives you
Get a clear picture of your NHI exposure in minutes
Inventory NHI
Service accounts, API keys and AI agents in one list, with an owner for each.
Fix the biggest risks first
Spend limited security time on the identities most likely to lead to a breach.
Shrink your attack surface
Remove the unused and orphaned identities attackers rely on.
Uncover machine identity risk in minutes
Sample report
- 921
- NHIs discovered
- 526
- High-risk findings
- 44%
- Unused
- 33%
- Owned by no one
67 shadow AI products in active use, 26 of them agentic
Top findings
- ORPH-02Owner is a deprovisioned user
- PRIV-02Global admin policy on an app principal
- AGE-01Credential over 365 days without rotation
- CONSENT-01Users trying to authorize an unapproved app
Inventory
| Identity type | Entra | Gateway | Total |
|---|---|---|---|
| Service account | 2 | · | 2 |
| App registration | 313 | · | 313 |
| API token | · | 7 | 7 |
| AI agentObserved runtime | 14 | 553 | 567 |
| MCP serverObserved runtime | · | 32 | 32 |
| Total NHIs | 329 | 592 | 921 |
What the assessment shows you
Get visibility into NHI risk across platforms
NHI Posture Discovery pulls service accounts, API tokens, OAuth apps and AI agents from multiple identity sources, including Microsoft Entra ID, Okta, AWS and GitHub, into one inventory.
Your team learns how many machine identities it has and which ones still matter, so cleanup can start without putting production at risk.
| Identity | Source | Risk |
|---|---|---|
| svc-backup-prod | Entra ID | |
| deploy-bot | GitHub | |
| ci-runner-role | AWS | |
| copilot-mail-agent | Entra ID | |
| okta-hr-sync | Okta |
- Critical
- 38
- 14 fewer
- High
- 164
- 41 fewer
- Medium
- 324
- 22 fewer
Prove your NHI risk is shrinking
Findings are grouped into Critical, High and Medium severity. Show your leadership team how many critical risks exist today and how many were resolved since the last run.
Saved snapshots compare each run with the one before, showing what is new and what was fixed.
Data sources it reads
Works from exports you already have
Identity providers
Microsoft Entra ID, Okta, PingOne, SecureAuth IdP
Cloud and code
AWS (IAM and CloudTrail), GitHub
AI, endpoint, and network telemetry
Microsoft Purview (Copilot), Microsoft Defender, CrowdStrike, Zscaler, Cisco Umbrella, Palo Alto Networks
Questions this assessment answers
How many non-human identities do we actually have?
Service accounts, API tokens, OAuth apps and AI agents from 10 identity sources come together in one inventory. Your team gets a real count, so you can stop stitching together exports from every console.
Which ones are still in use, and which are safe to remove?
Each identity is checked against real sign-in and audit activity. Dormant accounts stand out clearly, so your team can clean them up knowing production doesn't depend on them.
Who owns each service account and AI agent?
Owners are matched to identities automatically and can be confirmed during the session. Each fix has a named person behind it, which makes the next access review move faster.
Which machine identities have more access than they need?
The assessment flags privileged accounts and roles with broad rights. Shrinking that access limits how far an attacker can get from one stolen credential.
Which credentials never expire or have been exposed?
Long-lived keys and tokens that haven't been rotated are listed along with the evidence behind each finding. These credentials work like passwords with no MFA in front of them, so fixing them closes some of the easiest ways in.
Where do several risks combine into an easy entry point?
Compounding risks are surfaced first, such as an account that is both privileged and unused. These are the entry points attackers look for, so your team starts where the danger is highest.
Which AI tools and agents can reach our mail and files?
AI apps in your IdP and Copilot and Gemini agents are mapped to the data they can access. Security teams can set limits while AI use is still small and easier to manage.
Which risky apps are users approving, or trying to approve?
Repeated attempts to approve unapproved apps are flagged along with any high-risk access already granted. It's an early warning of shadow AI demand and of consent phishing aimed at your users.