Non-human identities (NHIs)—service accounts, application identities, API keys—have become the most prevalent identity types across corporate environments. They also tend to behave differently from the humans they serve. A person might log in from home, a coffee shop, an airport, and three different countries in a single month. A service principal that authenticates your third-party integrations, on the other hand, usually connects from the same handful of places, day after day, for as long as it exists.
That predictability is exactly what makes location such a useful, underused signal for securing identities.
The problem we kept running into with NHI Security
If an attacker—human or an increasingly capable AI agent—gets their hands on an NHI, the credential itself is often still perfectly valid. Nothing about it looks wrong. What is wrong, usually, is where it’s suddenly being used from.
Most teams already have detection that will flag it. But the gap isn’t visibility.
Identity Security has spent a decade getting very good at verifying people—MFA, step-up challenges, device trust, risk-based prompts. None of these controls fully transfer to NHIs. But while a human’s context is unpredictable by design, an NHI’s is narrow and stable, which makes location a far stronger signal for an NHI than it ever was for a person.
An AI-powered attacker doesn’t wait for a SOC team to triage and respond to an alert. It moves laterally, escalates privileges, and reaches crown jewels in moments. For an NHI with no real-time controls, that window between detection and response is where the damage happens.
The good news: you can stop it before it happens.
Many cloud NHIs authenticate from a limited set of source IPs. We examined the authentication pattern of a few types of NHIs across roughly 150 customer environments while building this. The pattern held up: close to three-quarters of those cloud NHIs operated from 25 or fewer distinct addresses, and one in five only ever authenticated from a single one. In other words, for many NHIs, “where it’s allowed to connect from” is a genuinely small, stable list, which is exactly the kind of thing that’s easy to restrict once you know it.
Entra ID, AWS and other identity providers already let you restrict an identity to a defined set of source addresses, natively and in real time. But building these policies properly, one identity at a time, doesn’t scale. You’d need to review authentication logs, work out the baseline activity, set the the policy, and repeat that across every NHI you have, on every platform you run. Most teams simply don’t get past the first handful.
The missing piece was not the control. It was making it usable at scale.
Silverfort’s geofencing automation layer
Our geofencing automation capability for cloud NHIs analyzes each NHI’s real authentication history to understand where it has actually been authenticating from. Based on that, it puts together a recommended policy: the specific set of IP addresses and subnets that identity has legitimately used to authenticate.
The policy runs natively in your IdP, with Silverfort doing the automation, so you don’t have to build each policy by hand. Silverfort’s automation layer gives you the ability to protect NHIs at scale, at a fraction of the time, and with the confidence that it won’t break your workflows. The result is practical, real-time protection.
Geofencing for cloud NHIs is currently available for Entra ID and AWS, with more platforms on the way.
Extending NHI protection to all environments
Alongside this new cloud capability, Silverfort virtually fences service accounts in Active Directory. This means that AD service accounts can be restricted only to their legitimate sources, destinations, and protocols. Any other authentication attempt can be denied, reducing the risk of leveraging service accounts for lateral movement.
The principle is the same across AD and cloud: discover the non-human identity, analyze its behavior, set a boundary around its legitimate activity, and protect it at the moment of authentication.
To learn more about Silverfort’s NHI Security capabilities, take a tour here.

