UGC Approved Journal no 63975(19)
New UGC Peer-Reviewed Rules

ISSN: 2349-5162 | ESTD Year : 2014
Volume 13 | Issue 9 | September 2026

JETIREXPLORE- Search Thousands of research papers



WhatsApp Contact
Click Here

Published in:

Volume 13 Issue 9
September-2026
eISSN: 2349-5162

UGC and ISSN approved 7.95 impact factor UGC Approved Journal no 63975

7.95 impact factor calculated by Google scholar

Unique Identifier

Published Paper ID:
JETIR2609191


Registration ID:
585732

Page Number

b806-b816

Share This Article


Jetir RMS

Title

Detecting “Shadow Identity”: Models for Discovering Unmanaged Authentication Outside Central Identity Providers

Abstract

Enterprise identity governance is designed around a limited number of central Identity Providers (IdPs), such as Okta, Microsoft Entra ID and Ping ID. Enterprise identity governance is based on as few as necessary identity providers (IdPs) that federate human sign-on using single sign-on (SSO), SAML and OpenID Connect (OIDC). However, a significant and ever-increasing portion of authentication is not sent across this plane. All of these credentials sit outside of the central IdP's view and control: local operating-system accounts, statically embedded service-account credentials, unmanaged software-as-a-service (SaaS) logins, developer-issued API keys, OAuth grants negotiated between objects directly in the running applications, and ever more independent artificial-intelligence (AI) agents that log on via local or scripted access paths. This group of ungoverned, un-Federated authentication occurs, in this paper, in a manner that is referred to as “shadow identity.” We formalize the problem of detecting shadows, place it in the context of three related fields in the exterior community: Non-human identity (NHI) governance, workload attestation standards, and graph-based identity analytics, propose a layered detection architecture, the Multi-Source Shadow Identity Detection (MSSID) framework. MSSID combines network- or endpoint-level telemetry, cross-source log correlation, construction of heterogeneous identity graphs, and three complementary detection models: a coverage-gap model, a graph-neural-network-style (GNN-style) behavioral anomaly model and an attestation-consistency model, to uncover authentication activity that has escaped the radar of the centralized governance approach. In addition to the proposal for the architecture, we deploy three reference copies of all three proposed detection models and test them end-to-end in a controlled synthetic test domain with 1,590 identity nodes and 190 shadow instances, distributed across all six taxonomy classes we define, which is currently not available in the public domain. The operating system used in this system has implemented it with a precision of 0.89, a recall of 0.72, an F1 score of 0.79, a cover ratio of 0.90 compared with the seeded ground truth, a mean simulated time to discovery of 1.0 day for the fusion operating point, and 90.5% accuracy for attribution. The results per class support the main design claims of the framework: The predominant model for none of the six classes of shadow identity; and the contributions of the three models are remarkably complementary rather than redundant. These results are not reported as a measure of validated results in the field; rather, the reports are the only measure of internal coherence and potential for production deployment at testbed scale. Finally, we conclude with a discussion about evasion resistance, the implications for governance, limitations, and a research agenda for detecting shadows of identities under attestation in a privacy-preserving and explainable way.

Key Words

shadow identity; non-human identity; identity and access management (IAM); identity threat detection and response (ITDR); graph neural networks; workload identity; SPIFFE/SPIRE; zero trust; unmanaged authentication; shadow IT

Cite This Article

"Detecting “Shadow Identity”: Models for Discovering Unmanaged Authentication Outside Central Identity Providers", International Journal of Emerging Technologies and Innovative Research (www.jetir.org), ISSN:2349-5162, Vol.13, Issue 9, page no.b806-b816, September-2026, Available :http://www.jetir.org/papers/JETIR2609191.pdf

ISSN


2349-5162 | Impact Factor 7.95 Calculate by Google Scholar

An International Scholarly Open Access Journal, Peer-Reviewed, Refereed Journal Impact Factor 7.95 Calculate by Google Scholar and Semantic Scholar | AI-Powered Research Tool, Multidisciplinary, Monthly, Multilanguage Journal Indexing in All Major Database & Metadata, Citation Generator

Cite This Article

"Detecting “Shadow Identity”: Models for Discovering Unmanaged Authentication Outside Central Identity Providers", International Journal of Emerging Technologies and Innovative Research (www.jetir.org | UGC and issn Approved), ISSN:2349-5162, Vol.13, Issue 9, page no. ppb806-b816, September-2026, Available at : http://www.jetir.org/papers/JETIR2609191.pdf

Publication Details

Published Paper ID: JETIR2609191
Registration ID: 585732
Published In: Volume 13 | Issue 9 | Year September-2026
DOI (Digital Object Identifier): https://doi.org/10.56975/jetir.v13i9.585732
Page No: b806-b816
Country: hyderabad, telangana, India .
Area: Engineering
ISSN Number: 2349-5162
Publisher: IJ Publication


Preview This Article


Downlaod

Click here for Article Preview

Download PDF

Downloads

00012

Print This Page

Current Call For Paper

Jetir RMS