DiscoverEntra.ChatThe Hidden Risks of Non-Human Identities in Your Tenant
The Hidden Risks of Non-Human Identities in Your Tenant

The Hidden Risks of Non-Human Identities in Your Tenant

Update: 2025-09-06
Share

Description

In this episode of Entra.Chat, I dive into the critical world of app governance with experts Jay Gundotra and Sander Berkouwer, who unpack the hidden risks of non-human identities in Microsoft Entra.

From shocking real-world breaches like Midnight Blizzard to a hilarious tale of a theme parkโ€™s water supply mishap, we explore why securing your cloud apps is more urgent than ever. Tune in to discover practical tips and tools to safeguard your organization without losing your giraffes!

Subscribe with your favorite podcast player or watch on YouTube ๐Ÿ‘‡

About Jay Gundotra

Jay is the CEO and technical founder of E-Now. He has a long history as an Exchange and Active Directory engineer, which led him to found his company and focus on solving complex identity and application governance challenges for enterprises.

LinkedIn - https://www.linkedin.com/in/jay-gundotra-19079a/

About Sander Berkouwer

Sander Berkouwer is a 17-year Microsoft MVP veteran and an accomplished identity architect. With deep expertise from being "in the trenches," he partners with Jay to educate the community and build solutions for managing non-human identities and service principals.

LinkedIn - https://www.linkedin.com/in/sanderberkouwer/

๐Ÿ”— Related Links

* AppGov Community - https://community.appgovscore.com/

* How Ownerless Apps in Entra ID Increase Your Attack Surface

* Securing Workload Identities in Entra ID: A Practical Guide for IT and Security Teams

๐Ÿ“— Chapters

00:00 Intro 01:55 What is App Governance? 04:02 The Origin Story of Focusing on App Governance 08:35 Why App Security is Critical Today 14:15 The Dangers of Over-Privileged Apps 20:38 The Giraffe Story: When Cleanup Goes Wrong 24:42 What Should a Successful Organization Do? 30:22 The Full Application Lifecycle: Onboarding to Offboarding 35:38 Building the AppGov Community 45:04 The Importance of Education and Automation

Podcast Apps

๐ŸŽ™๏ธ Entra.Chat - https://entra.chat

๐ŸŽง Apple Podcast โ†’ https://entra.chat/apple

๐Ÿ“บ YouTube โ†’ https://entra.chat/youtube

๐Ÿ“บ Spotify โ†’ https://entra.chat/spotify

๐ŸŽง Overcast โ†’ https://entra.chat/overcast

๐ŸŽง Pocketcast โ†’ https://entra.chat/pocketcast

๐ŸŽง Others โ†’ https://entra.chat/rss

Merill's socials

๐Ÿ“บ YouTube โ†’ youtube.com/@merillx

๐Ÿ‘” LinkedIn โ†’ linkedin.com/in/merill

๐Ÿค Twitter โ†’ twitter.com/merill

๐Ÿ•บ TikTok โ†’ tiktok.com/@merillf

๐Ÿฆ‹ Bluesky โ†’ bsky.app/profile/merill.net

๐Ÿ˜ Mastodon โ†’ infosec.exchange/@merill

๐Ÿงต Threads โ†’ threads.net/@merillf

๐Ÿค– GitHub โ†’ github.com/merill



Get full access to Entra.News - Your weekly dose of Microsoft Entra at entra.news/subscribe
Commentsย 
In Channel
loading
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

The Hidden Risks of Non-Human Identities in Your Tenant

The Hidden Risks of Non-Human Identities in Your Tenant

Merill Fernando