Somewhere in your environment right now, an AI agent, one of a growing population of non-human identities, has access to a system a human employee would need approval and training to touch. It got that access automatically, as part of being set up. Nobody interviewed it. Nobody onboarded it with a security briefing. And there’s a good chance nobody is watching what it does with the access it was given.
Identity teams are not short on data. They can inventory accounts, review permissions, run posture assessments, and generate long lists of risky configurations. What they still can’t determine is how identities are being used across the environment
The identity problem has changed. Visibility hasn’t.
Non-human identities now outnumber human identities 109 to 1, up from 82 to 1 just a year earlier. That population includes service accounts, workload identities, automation, and AI agents that often lack clear ownership, lifecycle controls, or a recognizable login pattern. And it’s growing faster than traditional entitlement and posture tools were built to track.
That creates a visibility gap. A directory can show that an account is old, privileged, or seemingly dormant. It won’t show whether the account still supports a production application, where it authenticates, whether a person is using it interactively, or what could break if its password is rotated. In Quest-led assessments, up to 60% of identities hold active privileges and access relationships with no observable activity. A last-logon attribute won’t settle it. Accounts get used in ways that never update the signals Active Directory and Entra ID rely on, so an identity can look dormant while holding privileged access and live dependencies.
The result is a familiar stalemate: security finds the issue, the application owner fears an outage, IAM lacks behavioral evidence, and the risk stays open — sometimes for years.
Granted access is not the same as observed access
Traditional governance and posture tools focus on what access exists and what an identity could potentially reach. Those insights don’t always describe use.
An access chain is an observed sequence of identity activity and relationships that moves across accounts, systems, and resources — formed through direct relationships (roles, groups, delegated permissions), inherited relationships (nested groups, accumulated access), or delegated activity (workloads, automation, APIs, and AI agents). Modeled attack paths show what may be possible. Observed access-chain intelligence adds evidence of where identities, particularly non-human identities, have been seen going, and which relationships deserve investigation.
This is the gap Quest Identity Insights was built to close. Quest Identity Insights provides continuous identity visibility and intelligence across hybrid Active Directory and Entra ID environments. It reveals observed identity relationships and access-chain patterns across human, non-human, and supported agentic identities, showing how identities are used, authenticated, and connected. It helps teams see where identity relationships create exposure, and what’s safe to change.
Where the exposure lives
When organizations begin analyzing identity behavior across non-human identities and AI agents, several patterns emerge:
- Agentic accounts with no owner and no oversight. An AI agent stood up to automate a workflow inherits broad permissions to do its job, then runs indefinitely with no documented purpose, no access review, and no one accountable for it.
- Service accounts that outlived their purpose. Nobody disables a service account when a project ends the way they’d disable a departing employee’s login. Accounts unused for years still carry valid, unrotated credentials and administrative group membership.
- Mixed-use identities blurring human and machine behavior. A service or workload identity labeled correctly can still be used incorrectly — with a person logging in through it interactively, over RDP, or with explicit credentials — creating shared credentials, weak accountability, and exposure that breaks auditability.
- Legacy authentication undermining modern controls. Microsoft is progressing toward an NTLM-independent future, and a policy setting can say one thing while endpoint evidence shows another. Organizations that don’t know where legacy authentication is still active risk finding out only when something breaks.
- Privilege that quietly outgrew its purpose. An account provisioned for one narrow task accumulates broader reach over time through group nesting and delegated permissions, until it can touch systems that have nothing to do with why it was created.
Why identity visibility and intelligence is emerging now
IAM, IGA, PAM, and directory tools remain essential. They define, govern, and assign access. But they were never built to show whether an identity is actively being used or what depends on it. Gartner established Identity Visibility and Intelligence Platforms (IVIP) as a new category in July 2025, recognizing the need for continuous identity context and intelligence beyond point-in-time configuration data. Market penetration is still below 5%. Organizations that act now can address identity blind spots before the category becomes mainstream.
What Quest Identity Insights does
Quest Identity Insights maintains an ongoing view of human, non-human, and supported agentic identities across Active Directory and Entra ID, combining identity inventory and configuration context with observed activity so teams understand how identities are used. That happens through six capabilities working together:
- Continuous identity visibility and intelligence — an ongoing, not point-in-time, view of identity configuration and behavior across the hybrid estate.
- Observed access-chain intelligence — an interactive graph view where teams select identities and resources, explore incoming and outgoing connections, apply filters, and examine authentication methods, access methods, timestamps, and repeated observations.
- Behavior-informed identity analysis — identifying usage-based dormancy, mixed-use accounts, observed NTLM activity, and non-human identities used outside their intended purpose, to separate meaningful exposure from configuration-only findings.
- Impact-based risk prioritization — Impact Scores and escalation categories that surface higher-impact identities and relationships that warrant deeper investigation.
- Identity exposure and drift management — dashboards, filters, and trends showing how activity, dependencies, and risk change over time, including identities that look inactive but continue to retain privileges.
- Evidence for informed action — bringing identity context, observed activity, and system dependencies together to support service-account cleanup, credential rotation, access reduction, and authentication modernization with more confidence.
In practice, that answers questions teams have been stuck on for years: Can I safely change this service account? Is this non-human identity being used as intended? Which observed access chains deserve investigation? Can we modernize authentication without guesswork? Each one gets answered the same way — by comparing what’s configured against what’s been observed.
