NHI capabilities are under active development. Classification, ownership, and policy support for non-human identities will keep expanding: follow the release notes for updates.
What counts as an NHI
In C1, a non-human identity (NHI) is a resource classified as one of the following:- App registration — for example, an Entra enterprise app, OAuth app, GitHub App, or Databricks service principal.
- Assumable role — for example, an AWS IAM role or GCP workload identity.
- Managed identity
Find identities across your environment
Navigate to Identity security > Identities & NHI to view the dashboard. It has a tab for each identity category C1 tracks — Human users, Service, Secrets, Agents — plus a dedicated NHI tab scoped to the app registrations, assumable roles, and managed identities described above.- Type and subtype — the resource’s classification (app registration, assumable role, or managed identity) alongside a more specific detail string, such as
entra.enterprise_applicationoraws.role.lambda. - Owner — who owns the identity, if anyone. Unowned NHIs are one of the most common gaps this dashboard surfaces.
- Findings — any open findings tied to the identity, such as an unowned non-human identity.