Skip to content

Commit dfe7576

Browse files
committed
release note: remove inactive service accounts
1 parent b98ea44 commit dfe7576

File tree

4 files changed

+47
-0
lines changed

4 files changed

+47
-0
lines changed
456 KB
Loading
Lines changed: 38 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,38 @@
1+
---
2+
title: 'Security Assessment: Remove Inactive Service Account (Preview) '
3+
description: Learn how to identify and address inactive Active Directory service accounts to mitigate security risks and improve your organization's security posture.
4+
ms.date: 08/04/2025
5+
ms.topic: how-to
6+
---
7+
8+
# Security Assessment: Remove Inactive Service Accounts (Preview)
9+
10+
This recommendation lists Active Directory service accounts detected as inactive (stale) within the past 180 days.
11+
12+
## Why do inactive service accounts pose a risk?
13+
14+
Unused service accounts can pose significant security risks to your organization, as some of these accounts can possess elevated privileges, which, if accessed by an attacker, could result in substantial damage. Therefore, it's imperative to identify and address any unused or orphaned service accounts.
15+
16+
## How do I use this security assessment to improve my organizational security posture?
17+
18+
To use this security assessment effectively, follow these steps:
19+
20+
1. Review the recommended action at [https://security.microsoft.com/securescore?viewid=actions ](https://security.microsoft.com/securescore?viewid=actions ) for Remove inactive service account.
21+
1. Review the list of exposed entities to discover which of your service account is inactive.
22+
23+
:::image type="content" source="media/remove-inactive-service-account/remove-inactive-service-accounts.png" alt-text="Screenshot that shows the recommendation action to remove inactive service accounts." lightbox="media/remove-inactive-service-account/remove-inactive-service-accounts.png":::
24+
25+
1. Take appropriate actions on those entities by removing the service account. For example:
26+
27+
- **Disable the account:** Prevent any usage by disabling the account identified as exposed.
28+
29+
- **Monitor for impact:** Wait several weeks and monitor for operational issues, such as service disruptions or errors.
30+
31+
- **Delete the account:** If no issues are observed, delete the account and fully remove its access.
32+
33+
> [!NOTE]
34+
> Assessments are updated in near real time, and scores and statuses are updated every 24 hours. The list of impacted entities is updated within a few minutes of your implementing the recommendations. The status might take time until it's marked as **Completed**.
35+
36+
## Related articles
37+
38+
- [Learn more about Microsoft Secure Score](/defender-xdr/microsoft-secure-score)

ATPDocs/toc.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -249,6 +249,8 @@ items:
249249
href: security-assessment-clear-text.md
250250
- name: LAPS usage assessment
251251
href: security-assessment-laps.md
252+
- name: Remove inactive service accounts
253+
href: remove-inactive-service-accounts.md
252254
- name: Riskiest lateral movement paths
253255
href: security-assessment-riskiest-lmp.md
254256
- name: Unsecure Kerberos delegation assessment

ATPDocs/whats-new.md

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -25,6 +25,13 @@ For updates about versions and features released six months ago or earlier, see
2525

2626
## August 2025
2727

28+
29+
# New security assessment: Remove inactive service accounts (Preview)
30+
31+
Microsoft Defender for Identity now includes a new security assessment that helps you identify and remove inactive service accounts in your environment. This assessment lists Active Directory service accounts that have been inactive (stale) for the past 180 days, helping you mitigate security risks associated with unused accounts.
32+
33+
For more information see: [Security Assessment: Remove Inactive Service Accounts (Preview)](remove-inactive-service-account.md)
34+
2835
### Sensor version 2.246
2936

3037
This version includes bug fixes and stability improvements for the Microsoft Defender for Identity sensor.

0 commit comments

Comments
 (0)