Skip to main content
NEW: RSAC 2026 NHI Field Report. How Non-Human Identity became cybersecurity's central axis
Threat patterns

What is Overprivileged NHI?

Also known as: Over-privileged NHI · Overprivileged Non-Human Identity · OWASP NHI5

A machine identity whose IAM permissions exceed what the workload actually needs. OWASP NHI5:2025 flags this as a top-5 non-human identity risk because the blast radius on compromise is far larger than necessary — a read-only batch job running with admin rights will leak admin-level damage if the credential is stolen. Usually caused by copy-pasting policies, using default roles, or leaving expanded permissions behind after a one-time task.

More terms in Threat patterns

Browse the full glossary

30 terms organized by category.