Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • The Challenges of Service Account Management current page
Link copied

The Challenges of Service Account Management

Jul 16, 2018
Author:
Chris Stoneff
Chris Stoneff
VP Security Solutions, Development
Blog banner default
The Challenges of Service Account Management
Chris Stoneff
Chris Stoneff
VP Security Solutions, Development

When I talk to many people about privileged identity management they think first about local accounts. So I explain the next level of privileged identity management. It involves not only managing privileged accounts, but also where they’re used. This means locating every account, figuring out where and how they’re used, and then changing their credentials everywhere. All without causing an outage.

Many servers use local accounts - like root on Linux and administrator on Windows - to run persistent applications, whether or not someone logs into the machine. For example, a web site would be an example of a persistent application. So would a database or other line-of-business application.

Here’s where service accounts come in. Service accounts are needed for these persistent applications so that they can perform actions on behalf of the users of the application. In effect, these accounts are proxies for performing limited actions for users that have no access to sensitive data and systems.

In many cases, the mechanics of service accounts means that an account must be known and verifiable to not only the application, but to everything that the application interacts with. Consequently the service account is generally a powerful Windows domain, Kerberos, LDAP or database access credential.

Privileged identity management involves not only managing privileged accounts, but also where they’re used.

Service Account Credentials Must Change Regularly

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

Service account-based applications must keep a copy of the credentials needed to perform their actions. These credentials are generally encrypted or obfuscated. But they must be available on demand by the application or service.

The consequence of the service account structure means that any password change of a Superuser credential must be done not only in the authentication system (i.e. Active Directory), but also in every service/application that stores the password for that same credential. So not only must you update the authenticator, but also all references. Updating all the places where a service account is stored is known as propagation.

How Service Accounts Cause Trouble for IT

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

To successfully change the password of an account, you must not only change it where it is being stored. You must also change it every place that references that account. If you miss any of the places that have a stored password, the wrong password will be used and that service will not work properly. In some cases, the use of an incorrect password by a service can cause the operating system to think that account is under attack and lock out the account. This last scenario means that every service that uses that locked out account will now fail too.

So the first challenge of service account management is discovery and correlation. That means understanding which credentials are in their systems, as well as where they are being used. The second challenge is propagation - understanding how to change the references to those credentials and not miss any.

The Solution for Proper Service Account Management

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

If you’re tasked with changing credentials on a regular basis, but consistently run into problems because these changes cause outages, don’t lose hope. Our Privileged Password Management solution can automate this job quickly and at scale, with minimal to no human interaction.

Have a look and then contact us to learn more about service account management.

Service Accounts – Don’t Overlook this Hidden Privileged Access Risk

Blog

Service Accounts – Don’t Overlook this Hidden Privileged Access Risk

Service Account Best Practices: How to Manage and Secure Them

Blog

Service Account Best Practices: How to Manage and Secure Them

Password Safe

Resources

Password Safe

Latest Posts
  • Hooked on Identity: Abusing SAML Assertion Inline Hooks in Okta
    Jun 9, 2026 Hooked on Identity: Abusing SAML Assertion Inline Hooks in Okta
    Blog
    6m
  • Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Jun 8, 2026 Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Blog
    5m
  • The Most Common & Most Dangerous Types of Shadow IT
    Jun 5, 2026 The Most Common & Most Dangerous Types of Shadow IT
    Blog
    19m
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
  • A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    May 26, 2026 A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    Blog
    3m
Related
  • Remote Support: An Important Step on the Ladder to ITSM Maturity
    Oct 8, 2019 Remote Support: An Important Step on the Ladder to ITSM Maturity
    Blog
    1m
  • Defending your business this Data Privacy Day
    Oct 20, 2017 Defending your business this Data Privacy Day
    Blog
    1m
Share this Article
  • Link
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.