Service account
An account used by software rather than a person, which needs a named owner, only the privileges its service requires, a managed credential and a place in access review.
A service account is an identity that software uses to authenticate to other systems, such as a web application reaching its database or a backup job reading file shares. NIST SP 800-53 Rev. 5 lists service accounts among the account types managed under AC-2, Account Management, and the ISC2 exam outline names “Service accounts management” in 5.5.
The risk is that nobody notices them. A service account does not leave, often holds broad rights, and its password is often old and known to more people than it should be. Good practice commonly includes a named human owner, only the privileges the service needs (least privilege), no interactive sign-in where the platform allows it, and a credential that is managed rather than written into code, for example held in a password vault and rotated. Where an interactive factor cannot apply, compensating controls include a narrow scope, limits on where the account may connect from, and monitoring. In Kerberos environments, weak service account passwords are the target of the attack commonly called Kerberoasting, and an account whose owner has gone becomes an orphaned account.
Exam relevance: a scenario is likely to present service accounts left out of access review, or excused from strong authentication because no person uses them. Candidates are expected to reject that exemption and to name the controls that take its place.