> For the complete documentation index, see [llms.txt](https://docs.oort.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.oort.io/understanding-check-failures/oort-insights/identity-posture-management-insights/nhi-with-deprovisioned-owners.md).

# NHI with Deprovisioned Owners

Non-Human Identities that are assigned to at least one owner that is deprovisioned present a security and posture risk. When an owner of an NHI leaves they may take sensitive credentials relating to the NHI with them. This leaves an open vulnerability in your environment that can be exploited by a disgruntled employee or bad actor to gain access to your systems.

**Recommended Actions**

When an owner leaves you should review if the NHI is still necessary. If the NHI is no longer necessary then it should be deprovisioned. If the NHI is still necessary then you should review all of the credentials like passwords, authenticators, and API keys tied to it and recycle them so that the ones present while the departed owner was here are no longer valid. You should also review the list of owners of the NHI to make sure it is still accurate.

**Compatibility**

[Microsoft Active Directory](/integrations/microsoft-active-directory.md)

[Microsoft Entra ID](/integrations/azure-active-directory-integration.md)
