Skip to content

Commit 20c3ef4

Browse files
Merge pull request #5170 from DeCohen/WI493426-remove-preview-tag-remove-inactive-service-account
Wi493426 remove preview tag remove inactive service account
2 parents 34ee409 + be0cabc commit 20c3ef4

File tree

2 files changed

+10
-10
lines changed

2 files changed

+10
-10
lines changed

defender-for-identity/remove-inactive-service-account.md

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -1,18 +1,18 @@
11
---
2-
title: 'Security Assessment: Remove Inactive Service Account (Preview)'
2+
title: 'Security Assessment: Remove Inactive Service Account'
33
description: Learn how to identify and address inactive Active Directory service accounts to mitigate security risks and improve your organization's security posture.
44
ms.date: 08/17/2025
55
ms.topic: how-to
66
#customer intent: As a security administrator, I want to improve security posture in my organization by removing inactive service accounts
77
---
88

9-
# Security Assessment: Remove Stale Service Accounts (Preview)
9+
# Security Assessment: Remove Inactive Service Accounts
1010

11-
This recommendation lists Active Directory service accounts detected as stale within the past 90 days.
11+
This recommendation lists Active Directory service accounts detected as inactive within the past 90 days.
1212

13-
## Why do stale service accounts pose a risk?
13+
## Why do inactive service accounts pose a risk?
1414

15-
Unused service accounts create significant security risks, as some of them can carry elevated privileges. If attackers gain access, the result can be substantial damage. Stale service accounts might retain high or legacy permissions. When compromised, they provide attackers with discreet entry points into critical systems, granting far more access than a standard user account.
15+
Unused service accounts create significant security risks, as some of them can carry elevated privileges. If attackers gain access, the result can be substantial damage. Inactive service accounts might retain high or legacy permissions. When compromised, they provide attackers with discreet entry points into critical systems, granting far more access than a standard user account.
1616

1717
This exposure creates several risks:
1818

@@ -25,9 +25,9 @@ This exposure creates several risks:
2525

2626
To use this security assessment effectively, follow these steps:
2727

28-
1. Review the recommended action at [https://security.microsoft.com/securescore?viewid=actions ](https://security.microsoft.com/securescore?viewid=actions) for Remove stale service account.
28+
1. Review the recommended action at [https://security.microsoft.com/securescore?viewid=actions ](https://security.microsoft.com/securescore?viewid=actions) for Remove inactive service account.
2929

30-
1. Review the list of exposed entities to discover which of your service accounts are stale and have not performed any login activity in the last 90 days.
30+
1. Review the list of exposed entities to discover which of your service accounts are inactive and haven't performed any login activity in the last 90 days.
3131

3232
1. Take appropriate actions on those entities by removing the service account. For example:
3333

defender-for-identity/whats-new.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -98,11 +98,11 @@ Previously, Defender for Identity tenants received Microsoft Entra ID risk level
9898

9999
For UEBA tenants without a Microsoft Defender for Identity license, synchronization of Microsoft Entra ID risk level to the IdentityInfo table remains unchanged.
100100

101-
### New security assessment: Remove stale service accounts (Preview)
101+
### New security assessment: Remove inactive service accounts
102102

103-
Microsoft Defender for Identity now includes a new security assessment that helps you identify and remove inactive service accounts in your organization. This assessment lists Active Directory service accounts that have been stale for the past 90 days, to help you mitigate security risks associated with unused accounts.
103+
Microsoft Defender for Identity now includes a new security assessment that helps you identify and remove inactive service accounts in your organization. This assessment lists Active Directory service accounts that have been inactive for the past 90 days, to help you mitigate security risks associated with unused accounts.
104104

105-
For more information, see: Security Assessment: [Remove Stale Service Accounts (Preview)](/defender-for-identity/remove-inactive-service-account)
105+
For more information, see: Security Assessment: [Remove Inactive Service Accounts (Preview)](/defender-for-identity/remove-inactive-service-account).
106106

107107
### New Graph based API for response actions (preview)
108108

0 commit comments

Comments
 (0)