Non-human and AI agent identity, by ear
15 episodes, in order. Service accounts, secrets, workload identity, and the newer problem of giving AI agents scoped, auditable access. Start at the top if the topic is new to you, or jump to the stage that matches where you are.
Start here: the basics
- 1Analyst Chat #234: Identity Management in a World of Automated Systems - Machine IdentitiesKuppingerCole Analyst Chat · 2024-10-21 · 21 min · Learner
What machine identities are, why they matter in modern IT, and why lifecycle management and regulation shape how they must be managed.
Martin Kuppinger (KuppingerCole Analysts)nhi - 2NHI Workshop - What Are NHIs, Criticality, Risks and ChallengesThe Non-Human & AI Identity Podcast · 2025-11-10 · 23 min · Learner
A panel introduction to what non-human identities are, why they are critical, and the main risks and challenges they create.
- 3#365 - Exploring the Future of Machine Identity with Felix GaehtgensIdentity at the Center · 2025-08-04 · 62 min · Learner
How machine identities differ from human ones, why legacy practices fail them, and why teams are moving to dynamic, ephemeral machine credentials.
Felix Gaehtgens (former Gartner analyst)nhi
In practice: rollouts and operations
- 4401 Access Denied Podcast Ep. 76 | Discovering and Stealing Secrets with Mackenzie Jackson401 Access Denied · 2023-03-22 · 33 min · Practitioner
The main ways attackers find and exploit secrets and credentials leaked in source code, and how developers can defend against those attacks.
Mackenzie Jackson (GitGuardian)secrets management - 5Shadow Admins: The Non-Human Identities Hiding in Your Entra TenantEntra.Chat · 2026-06-20 · 69 min · Practitioner
How service principals, app registrations, and agent identities become hidden admins, which API permissions to hunt for, and why to replace secrets with managed identities.
Erika Zelicnhi - 6Analyst Chat #264: Persistent Identity, Ephemeral Secrets - Workload Identities in the Age of AIKuppingerCole Analyst Chat · 2025-08-11 · 22 min · Practitioner
Why workload identities should be treated as privileged, how long-lived secrets widen the attack surface, and how ephemeral secrets, SPIFFE/SPIRE, and policy-as-code help.
Martin Kuppinger (KuppingerCole Analysts)secrets management - 7Root Causes 640: What is SPIFFE?Root Causes: A PKI and Security Podcast · 2026-07-15 · Practitioner
What SPIFFE is, how it places a workload or AI agent identifier inside a certificate, and how policy engines can allow-list those identifiers.
- 8The Co-Inventor of Tor on Why Your NHI Strategy Is Already BehindThe Identity Jedi Show · 2026-05-26 · 63 min · Practitioner
Why non-human identity risk built up while human identity matured, covering service accounts, unrotated API keys, hardcoded credentials, and zero trust for AI agents.
David Goldschlag (Aembit)nhi - 9EIC NHI Workshop - How Attackers Compromise NHIsThe Non-Human & AI Identity Podcast · 2025-09-17 · 21 min · Practitioner
A conference session on the methods attackers use to compromise non-human identities.
Going deeper: standards, architecture, and attacks
- 10Securing Non-Human Identities in the Age of Agentic AI with Sarah Cecchetti, Director of Product Management at SemperisHybrid Identity Protection Podcast · 2026-04-28 · 43 min · Architect
Where authentication and authorization standards fall short for non-human identities and AI agents, and which emerging frameworks and external guardrails aim to close the gap.
- 11#390 - Identity Management for Agentic AI with Tobin SouthIdentity at the Center · 2025-12-08 · 56 min · Architect
Identity challenges raised by AI agents, the role of MCP, and recursive delegation and scope attenuation, drawing on the OpenID Foundation agentic AI whitepaper.
Tobin South (OpenID Foundation AI Identity Management Community Group)agentic identity - 12Agentic AI and the Authorization Gap No One Closed with Geoffrey Mattson, CEO of SecureAuthHybrid Identity Protection Podcast · 2026-06-09 · 35 min · Architect
Why per-action, real-time authorization fits AI agents, where MCP vendors fall short of their own OAuth spec, and what practical agent rollout guardrails look like.
- 13#422 - Decoded - Securing AI Agents with Standards You Already HaveIdentity at the Center · 2026-05-15 · 78 min · Architect
How existing OAuth specifications such as JWT authorization grant, token exchange, and client ID metadata, plus SPIFFE, apply to securing AI agents as workloads.
Pieter Kasselman (Defakto)agentic identity - 14Analyst Chat #317: MCP Is Just Another API, and That's the Bad NewsKuppingerCole Analyst Chat · 2026-09-29 · 52 min · Architect
Why MCP security is an API, identity, and authorization problem, covering unauthenticated MCP servers, tool poisoning, prompt injection, and practical next steps.
Alexei Balaganski (KuppingerCole Analysts) - 15One Compromised Agent ID Blueprint Can Cross Tenant BoundariesEntra.Chat · 2026-07-12 · 54 min · Architect
How Entra Agent ID blueprints, agent identities, and agent users relate, and how stolen blueprint credentials could reach agent identities in other tenants.
Katie Knowles (Datadog)agentic identity
How this list was built
Episodes are chosen for what they teach, not for who published them, and ordered so each one builds on the last. Each note is written from the episode's published show notes and checked against the episode page. Vendor-produced shows are labelled on their directory profiles. Know a better episode for a step on this path? Email [email protected].