All IAM glossary termsPrivileged Access · glossary
Machine identity management
Also known as: Machine Identity Management · MIM
Definition
Machine identity management applies joiner/mover/leaver discipline to non-human identities — every service account, key, certificate, and workload identity gets an owner, a justified scope, a rotation schedule, and a deprovisioning path.
In more depth
It is the governance answer to NHI sprawl. Secrets move into a vault with rotation; workloads use attested identity (SPIFFE/SPIRE, IRSA) instead of static credentials; an inventory tracks what exists, who owns it, and when it was last rotated.
The most-missed control is deprovisioning — orphaned service accounts whose workload was decommissioned but whose credentials still authenticate.
Want the work, not just the definition?