Service accounts

Not every account belongs to a person. Systems have accounts too, so that software can talk to other software.

They are consistently the worst-looked-after identities in most organisations. They are created quickly during a project, given more permission than needed because narrowing it takes time, and then they outlive everybody involved. Nobody rotates the password because nobody knows what will break. Nobody removes it because nobody is sure what it is for. Every one needs a named human owner, or it becomes a permanent way in that nobody is responsible for.

Checked against the primary source.

More on Identity & access