Here is a question worth asking before your next audit. If you added up every account in your Active Directory and Microsoft 365 estate today, real users, service accounts, app registrations, OAuth grants, automation credentials, how far past your headcount would the number run?
For most organisations, nobody has counted in years. When they finally do, the number lands a long way past the payroll.
There is hard data behind that hunch now. Palo Alto Networks’ 2026 Identity Security Landscape, a survey of 2,930 security leaders, put the average at 109 machine identities for every human one. A year earlier it was 82 to 1. Roughly 79 of those 109 are now Al agents, and organisations expect that agent population to grow another 85% over the next twelve months.
Growth is not really the problem. The gap is. Only 37% of those organisations can revoke an Al agent’s credentials, barely 30% keep a tamper-proof log of what the agents do, and nine in ten had an identity-related breach in the past year (Palo Alto Networks, 2026).
The frontier gets the headlines. The basics get you breached. Governing autonomous Al agents is genuinely hard, and the industry is still working it out. It has earned the keynote slots. But you do not need an agent to get breached. The accounts attackers actually use tend to be the ones that were already sitting in your directory, quietly, for years.
Here is the part that surprises people. A modern intrusion rarely looks like someone kicking down a door. It looks like someone signing in. One dormant account with a weak password, or one service account nobody owns, and the attacker is inside as a legitimate user. From there it is less a hack than a walk.
A hop through a nested group here, an inherited permission there, every step perfectly allowed, until they are standing on domain admin.
Attackers do not break in so much these days. They sign in, and then they walk.

An attack path from an ordinary account to a privileged group. Each dotted line is a permission that was granted for a good reason once and never revisited.
What is quietly waiting in a mature estate
Run an honest look over a hybrid environment that has been live for a few years and the same things surface every time: Enabled accounts for people who left months, sometimes years, ago.
Service accounts with domain admin rights, their original passwords, and no owner left to ask.
Nested groups that hand finance access to people three teams away from finance.
App registrations and OAuth consents nobody remembers granting, a few able to read every mailbox. Privileged Microsoft 365 roles handed out “temporarily” and never taken back.
None of it shows up in daily operations. All of it shows up in exactly two places: an attacker’s reconnaissance, and an auditor’s report.
The compliance clock is already ticking
This is where it stops being a nice-to-have. Cyber Essentials expects accounts to be removed when they are no longer needed and admin rights reviewed on a schedule, across every identity rather than a chosen few.
ISO 27001’s Annex A asks for the same, with evidence to show for it. If your last access review looked only at user accounts, it covered a sliver of your directory, and assessors and cyber insurers have started asking about the rest.
You cannot fix what you cannot see
The catch is practical. Answering “what is actually in here?” by hand means weeks of PowerShell exports and spreadsheet reconciliation that are stale before they are finished, so it rarely gets done. A structured identity risk assessment does it differently. It gives you one honest score, then lets you open that number up by category.

A single risk score, then the detail behind it: inactive and never-logged-on accounts, unchanged passwords, over-privileged users and misconfigurations, each rated by severity and exposure.
You get a clear read of where you stand and a list you can work through in priority order, from the accounts that should be closed today to the group nesting that needs untangling this quarter.
Within an afternoon you will know how many identities really live in your estate, which ones nobody owns, and which ones an attacker would reach for first.
That is worth knowing whatever you decide to do next.
See Where Your Identity Estate Actually Stands
It’s free, and the findings are yours to keep. Get your free AD & M365 risk assessment from ManageEngine – runs on–premises on read–only access, so your directory data never leaves your environment.
Click here to find out more: Free Active Directory risk assessment – ManageEngine ADManager Plus





