What is service-account access?¶
Service-account access is cloud activity performed through a non-human or workload identity assigned to software or automation. The identity can establish what process had authority and what it did; responsibility is traced through the people and systems that created, configured and changed it.
The event has an automated actor and a human history¶
Northstar Backup runs nightly on Azure using workload identity SP-482. At 02:00 it obtains access for a storage account and copies tender-notes.docx. The storage log names SP-482, not Priya, who changed the backup scope at 16:40 the day before.
Preserve identity, execution and control records¶
Obtain the workload/service-principal identifier, assigned roles and scope, credential or managed-identity history, token/sign-in events, execution host, scripts or configuration, schedule, deployment history and resource logs. Human administrator events explain who changed the process; they should not replace the workload as the recorded actor.
A descriptive name such as backup-user is not proof of purpose. One user-assigned identity may serve several resources, while a system-assigned identity may follow one resource's lifecycle. Compromise or exposed credentials can also make the identity act outside its intended process.
Microsoft workload identities - checked 2 September 2026
Microsoft Entra groups applications, service principals and managed identities as workload identities. Managed identities let supported Azure resources obtain tokens without developers handling a password, key or certificate; their sign-in and management activity can appear in separate records.
The point to remember
A service account identifies the automated actor. Join its permissions and resource events to the workload configuration, execution host and human change history.