Identity Sprawl is Becoming a Cloud Infrastructure Problem

Identity Sprawl is Becoming a Cloud Infrastructure Problem

Identity once felt contained. Most organizations could look at a directory and understand the major groups that needed access. Employees, contractors, and privileged administrators were difficult to manage, but the model was familiar. Identity sat alongside the security architecture as a control over who could reach each system.

Cloud changed that model quietly. Modern environments depend on trust decisions created constantly. Teams grant access to keep work moving. Months pass, the original reason fades, and the permission remains because removing it might disrupt a process. The trust relationship becomes part of how the environment operates.

The scale is significant. Microsoft Entra Permissions Management discovered 209 million identities across customers’ cloud environments in 2023, of which only 34.5 million were human. Workload identities now make up much of many cloud estates, moving identity risk beyond the workforce and into the infrastructure itself.

Cloud moved trust into relationships

Traditional infrastructure relied heavily on boundaries. Modern infrastructure relies on relationships. Applications work because other systems accept their requests. Deployments move because automation has permission to act.

Difficulty arises when those relationships span systems evolving at different speeds. Across APAC, cloud-native platforms often co-exist with older operations and local data requirements. Identity must bridge both environments, even when no team can see the full chain of trust.

Complexity often comes from architecture serving legitimate business needs. Platforms expand to support growth. Engineering teams automate to speed delivery. Cloud services become operational dependencies because they solve real problems. Years later, the organization inherits an identity landscape far removed from the model it originally designed.

Attackers follow trust paths

Attackers do not need to understand an entire cloud environment. They need to find the relationship that moves them closer to something valuable.

A compromised workload identity is useful because the environment already trusts it. Access granted for a legitimate reason may still appear ordinary in a review. Risk comes from how far that trust can carry an attacker who understands the path.

Trusted identities can move through relationships the organization created for itself, often without the friction defenders expect from an external intrusion. During cloud investigations, identity and infrastructure frequently converge because movement through the environment follows a path through trust.

Growth carries old access forward

Identity sprawl usually begins with a business trying to move faster. Access is granted because work needs to continue, while removing it later feels riskier than leaving it alone.

The original context disappears slowly. The environment carries old trust decisions forward as if they still serve their initial purpose. Governance strains when identities are created faster than teams can understand them.

Periodic access reviews still matter, but they were designed for a more stable environment. Cloud infrastructure changes constantly, and an identity created for one purpose may survive after that purpose changes. Attackers look for relationships the organization has stopped questioning.

Identity has become infrastructure

Security teams often discuss identity as one control among many. In cloud environments, identity determines whether infrastructure can function. Systems operate because they know what to trust, and those decisions shape behaviour during an attack.

Well-designed trust helps the business move quickly. Poorly understood trust can provide an attacker with a path through the environment. Organizations adapting effectively treat identity decisions as architecture decisions, designing trust while platforms take shape. Retrofitting it later becomes much harder.

Ownership must also move closer to the teams designing and operating infrastructure. Every platform change can alter the trust model. Security remains essential, but it cannot be the only group responsible for understanding how access and authority move across the environment.

Architecture Must Map What Access Enables

When identity becomes part of architecture, the work extends beyond deciding whether an account should exist. Security and platform teams must understand what each identity makes possible across permissions, systems, and connected services.

A cloud environment can appear well-governed in an access review while carrying trust paths nobody has mapped. Identity sprawl becomes an attack surface along those paths, especially where access has outlived its original purpose.

For APAC organizations, the discipline is essential because modernisation is rarely uniform. Cloud platforms, regional operations, and legacy dependencies often coexist. Identity connects those environments and deserves the same architectural attention given to networks, data, and applications.

The Next Identity Risk

Many organizations still manage identity using assumptions shaped by an earlier generation of infrastructure. Cloud environments have changed faster than the operating models supporting them.

The number of identities will keep growing because modern systems authenticate constantly, often without a person involved. Teams need continuous visibility into permissions, ownership, behaviour, and the trust paths connecting systems.

Risk rises when an attacker can understand a chain of trust faster than the organization can map it. Closing that gap requires security, platform, cloud, and application teams to manage identity as a shared part of infrastructure design.

Author

Dipesh Kaura

Dipesh Kaura is the Country Director (India and SAARC) at Securonix.

Chat with CIONow.in

Scaling Media with Smart Tech & Leadership...