Skip to content
CLD-035 Cloud Services

Cloud ServicesCLD-035

What is service-account access?

Service-account access is access carried out by a non-human account created for an application, system or automated process.

It is commonly used to run scheduled tasks, move data, manage infrastructure, connect systems or perform background operations.

What this means in practice

A service account may create, edit, copy, delete or transmit data without a user manually signing in at that time. It may operate continuously, at fixed times or when another event triggers it.

Service accounts often have names that look technical, generic or system-generated. They may authenticate using keys, certificates, tokens or platform-managed credentials rather than a password and multi-factor authentication.

For investigators, identify who created the service account, what system used it, what permissions it held and whether those permissions changed.

In an organisational environment, the customer may hold the best records about the application, owner, business purpose and expected behaviour. The cloud provider may hold the technical audit trail.

Where a service account has broad permissions, consider whether it could have altered logs, files, users or security settings.

What this does not show on its own

The dangerous assumption is that every account in a cloud log represents a person.

Equally, do not attribute the action directly to the administrator who created the account. The person may have authorised the process without causing each later event.

What to do next

Look for account-creation records, role assignments, key or credential issue, application configuration, scheduled jobs and audit logs showing the actions performed.

Do not assume that an action attributed to a service account was automatically legitimate. The account may be misconfigured, compromised or used outside its intended purpose.

Key takeaway

Treat service-account activity as automated system activity first, then establish who configured, controlled or abused the account before attributing responsibility.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.