This is a clear explanation of a problem most small businesses don't realise they have. In the Microsoft 365 tenants I review, non-human identities often hide in plain sight: old app registrations in Microsoft Entra ID, a scanner or backup tool connected years ago, or a third-party app granted broad permissions and never reviewed.
The "assign a human owner to every NHI" point is the one I would underline. When nobody owns an app registration, nobody notices when its secret is about to expire, or worse, when it quietly still has access to every mailbox long after the tool was replaced.
For smaller organisations without dedicated identity teams, where would you suggest starting? A simple quarterly review of app registrations and their permissions feels like the most realistic first step.