Most machine identity programs rank risk by entitlement: how many scopes a token holds, how privileged the service account is, how sensitive the systems it can reach. That inventory is useful, and it is where nearly every tool stops. Rank the non-human identities by their permissions, remediate the top of the list, work down. The trouble is that the ranking can be confidently wrong.
The Scopes Are Only Half the Story
A service account has no intent of its own. Something invokes it: a person, a pipeline, another system. So the accounts and people who can invoke it shape its exposure as much as its permissions do. A modestly scoped token that a dozen contractors can trigger, or that sits on the laptop of a heavily targeted admin, is more dangerous than a powerful account only one hardened system ever calls. A machine identity inherits the risk of the humans and systems that can reach it. Rank by scopes alone and you will harden the wrong accounts first.
Follow the Access Back to People
The useful question is relational: for each machine identity, who and what can actually invoke it, and how exposed are they? That means mapping the access paths behind the account, not just scoring the account on its own. Abnormal baselines behavior across the identities in an environment, human and non-human, so a token suddenly invoked by an identity and context it has never been paired with stands out to an analyst, even when every permission checks out on paper.
The most dangerous machine identity in your environment probably isn't the most privileged one. It's the one the wrong person can reach.
See the latest from Abnormal's product and engineering teams.

