{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/inventory-service-accounts-with-recent-authentication-context/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/inventory-service-accounts-with-recent-authentication-context/",
        "slug": "inventory-service-accounts-with-recent-authentication-context",
        "url": "https://update.dsesecurity.com/updates/inventory-service-accounts-with-recent-authentication-context/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/inventory-service-accounts-with-recent-authentication-context.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/inventory-service-accounts-with-recent-authentication-context/"
        },
        "title": "Inventory service accounts with their recent authentication context",
        "summary": "Use Investigate and protect Service Accounts to review this narrow operational decision without extending the source beyond its stated scope.",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "advisory",
            "name": "Advisory"
        },
        "featured": false,
        "image": {
            "theme": "identity-cloud",
            "label": "Identity & cloud",
            "alt": "Governed cloud identity system with connected service and lifecycle nodes.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            },
            {
                "slug": "microsoft-365-identity",
                "name": "Microsoft 365 & Identity",
                "url": "https://update.dsesecurity.com/topic/microsoft-365-identity/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-08-27T12:13:12+00:00",
        "modified_at": "2026-08-27T13:01:32+00:00",
        "reviewed_on": "2026-08-26",
        "reading_minutes": 3,
        "word_count": 509,
        "potentially_affected": "Teams, systems, services, or facilities within the stated scope of Investigate and protect Service Accounts",
        "dse_recommendation": "Compare the observed state with the cited official source, document applicability and exceptions, and test any approved change with rollback safeguards.",
        "primary_source": {
            "name": "Investigate and protect Service Accounts",
            "url": "https://learn.microsoft.com/en-us/defender-for-identity/service-account-discovery",
            "published_on": "2025-03-25",
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<p>Use this document to connect an official requirement or behavior to observable evidence: Inventory service accounts with their recent authentication context. Only the official source and traced locations below supply facts. Confirm applicability before acting.</p>\n<h2>Source fact:</h2>\n<p>The official <a href=\"https://learn.microsoft.com/en-us/defender-for-identity/service-account-discovery\" target=\"_blank\" rel=\"noopener noreferrer\">Investigate and protect Service Accounts</a> from Microsoft supports the following bounded statements:</p>\n<ul>\n<li>Service accounts often have elevated privileges but generally cannot use modern authentication protections such as MFA in the same way as human accounts. The research record locates this support at <strong>Opening risk overview</strong>.</li>\n<li>Automatic discovery identifies gMSA and sMSA accounts and user accounts meeting criteria such as an SPN plus password-never-expires, and presents recent authentication sources and destinations. The research record locates this support at <strong>Auto-discovery section</strong>.</li>\n</ul>\n<p>The source support ends with the statements listed above. Use them to examine identity alerts, investigations, remediation roles, evidence retention, escalation, exclusions, and incident workflows in the applicable environment, not to imply a wider guarantee.</p>\n<h2>What the source does not establish</h2>\n<p>Classification criteria identify candidates, not confirmed business purpose, ownership, necessity, or compromise. No current deployment state or change approval follows from the source alone. Validate Active Directory, Windows DNS, time, cloud portals, endpoint data, network telemetry, privileged access, and response staffing, and treat examples or options as conditional inputs rather than defaults.</p>\n<h2>Applicability questions</h2>\n<ul>\n<li>For source statement 1 at <strong>Opening risk overview</strong>, which observable configuration, record, or test can confirm applicability here?</li>\n<li>For source statement 2 at <strong>Auto-discovery section</strong>, which observable configuration, record, or test can confirm applicability here?</li>\n<li>Which deployed instance of identity alerts, investigations, remediation roles, evidence retention, escalation, exclusions, and incident workflows will be compared with the source, and why that instance?</li>\n<li>How will the review distinguish a source mismatch from a failure in Active Directory, Windows DNS, time, cloud portals, endpoint data, network telemetry, privileged access, and response staffing?</li>\n<li>Who approves the conclusion, exception, test window, and rollback threshold?</li>\n</ul>\n<h2>DSE recommendation:</h2>\n<p>DSE recommends using the cited source as the evidence anchor for this decision. Make the source, asset scope, owner, and expected outcome explicit in the review record. Record the source location, examined part of identity alerts, investigations, remediation roles, evidence retention, escalation, exclusions, and incident workflows, observed and expected states, owner, and reason for deviation.</p>\n<p>Do not move from citation to production in one step. Pilot the decision where practical, observe agreed signals, retain a reversal point, and verify Active Directory, Windows DNS, time, cloud portals, endpoint data, network telemetry, privileged access, and response staffing. Handle credentials, keys, recovery data, and personal information through approved secure channels.</p>\n<h2>Verification and evidence</h2>\n<p>Evidence should let another reviewer reproduce this decision. Retain observations beside the traced locations <strong>Opening risk overview</strong>; <strong>Auto-discovery section</strong>. Favor alert records, investigation timelines, analyst actions, tuning or exclusion approvals, remediation results, and case closure, linked to stable identifiers, time, and operator.</p>\n<p>Record the decision even when no change is made, including uncertainty and the next trigger. Use safe testing conditions for disruptive work, preserve rollback proof, and revisit the conclusion after relevant platform, dependency, vendor, or ownership changes.</p>\n<h2>Official references</h2>\n<ul>\n<li><a href=\"https://learn.microsoft.com/en-us/defender-for-identity/service-account-discovery\" target=\"_blank\" rel=\"noopener noreferrer\">Investigate and protect Service Accounts</a> — Microsoft</li>\n</ul>",
        "content_text": "Use this document to connect an official requirement or behavior to observable evidence: Inventory service accounts with their recent authentication context. Only the official source and traced locations below supply facts. Confirm applicability before acting.\nSource fact:\nThe official Investigate and protect Service Accounts from Microsoft supports the following bounded statements:\n\nService accounts often have elevated privileges but generally cannot use modern authentication protections such as MFA in the same way as human accounts. The research record locates this support at Opening risk overview.\nAutomatic discovery identifies gMSA and sMSA accounts and user accounts meeting criteria such as an SPN plus password-never-expires, and presents recent authentication sources and destinations. The research record locates this support at Auto-discovery section.\n\nThe source support ends with the statements listed above. Use them to examine identity alerts, investigations, remediation roles, evidence retention, escalation, exclusions, and incident workflows in the applicable environment, not to imply a wider guarantee.\nWhat the source does not establish\nClassification criteria identify candidates, not confirmed business purpose, ownership, necessity, or compromise. No current deployment state or change approval follows from the source alone. Validate Active Directory, Windows DNS, time, cloud portals, endpoint data, network telemetry, privileged access, and response staffing, and treat examples or options as conditional inputs rather than defaults.\nApplicability questions\n\nFor source statement 1 at Opening risk overview, which observable configuration, record, or test can confirm applicability here?\nFor source statement 2 at Auto-discovery section, which observable configuration, record, or test can confirm applicability here?\nWhich deployed instance of identity alerts, investigations, remediation roles, evidence retention, escalation, exclusions, and incident workflows will be compared with the source, and why that instance?\nHow will the review distinguish a source mismatch from a failure in Active Directory, Windows DNS, time, cloud portals, endpoint data, network telemetry, privileged access, and response staffing?\nWho approves the conclusion, exception, test window, and rollback threshold?\n\nDSE recommendation:\nDSE recommends using the cited source as the evidence anchor for this decision. Make the source, asset scope, owner, and expected outcome explicit in the review record. Record the source location, examined part of identity alerts, investigations, remediation roles, evidence retention, escalation, exclusions, and incident workflows, observed and expected states, owner, and reason for deviation.\nDo not move from citation to production in one step. Pilot the decision where practical, observe agreed signals, retain a reversal point, and verify Active Directory, Windows DNS, time, cloud portals, endpoint data, network telemetry, privileged access, and response staffing. Handle credentials, keys, recovery data, and personal information through approved secure channels.\nVerification and evidence\nEvidence should let another reviewer reproduce this decision. Retain observations beside the traced locations Opening risk overview; Auto-discovery section. Favor alert records, investigation timelines, analyst actions, tuning or exclusion approvals, remediation results, and case closure, linked to stable identifiers, time, and operator.\nRecord the decision even when no change is made, including uncertainty and the next trigger. Use safe testing conditions for disruptive work, preserve rollback proof, and revisit the conclusion after relevant platform, dependency, vendor, or ownership changes.\nOfficial references\n\nInvestigate and protect Service Accounts — Microsoft",
        "content_markdown": "Use this document to connect an official requirement or behavior to observable evidence: Inventory service accounts with their recent authentication context. Only the official source and traced locations below supply facts. Confirm applicability before acting.\n\n## Source fact:\n\nThe official [Investigate and protect Service Accounts](https://learn.microsoft.com/en-us/defender-for-identity/service-account-discovery) from Microsoft supports the following bounded statements:\n\n- Service accounts often have elevated privileges but generally cannot use modern authentication protections such as MFA in the same way as human accounts. The research record locates this support at Opening risk overview.\n\n- Automatic discovery identifies gMSA and sMSA accounts and user accounts meeting criteria such as an SPN plus password-never-expires, and presents recent authentication sources and destinations. The research record locates this support at Auto-discovery section.\n\nThe source support ends with the statements listed above. Use them to examine identity alerts, investigations, remediation roles, evidence retention, escalation, exclusions, and incident workflows in the applicable environment, not to imply a wider guarantee.\n\n## What the source does not establish\n\nClassification criteria identify candidates, not confirmed business purpose, ownership, necessity, or compromise. No current deployment state or change approval follows from the source alone. Validate Active Directory, Windows DNS, time, cloud portals, endpoint data, network telemetry, privileged access, and response staffing, and treat examples or options as conditional inputs rather than defaults.\n\n## Applicability questions\n\n- For source statement 1 at Opening risk overview, which observable configuration, record, or test can confirm applicability here?\n\n- For source statement 2 at Auto-discovery section, which observable configuration, record, or test can confirm applicability here?\n\n- Which deployed instance of identity alerts, investigations, remediation roles, evidence retention, escalation, exclusions, and incident workflows will be compared with the source, and why that instance?\n\n- How will the review distinguish a source mismatch from a failure in Active Directory, Windows DNS, time, cloud portals, endpoint data, network telemetry, privileged access, and response staffing?\n\n- Who approves the conclusion, exception, test window, and rollback threshold?\n\n## DSE recommendation:\n\nDSE recommends using the cited source as the evidence anchor for this decision. Make the source, asset scope, owner, and expected outcome explicit in the review record. Record the source location, examined part of identity alerts, investigations, remediation roles, evidence retention, escalation, exclusions, and incident workflows, observed and expected states, owner, and reason for deviation.\n\nDo not move from citation to production in one step. Pilot the decision where practical, observe agreed signals, retain a reversal point, and verify Active Directory, Windows DNS, time, cloud portals, endpoint data, network telemetry, privileged access, and response staffing. Handle credentials, keys, recovery data, and personal information through approved secure channels.\n\n## Verification and evidence\n\nEvidence should let another reviewer reproduce this decision. Retain observations beside the traced locations Opening risk overview; Auto-discovery section. Favor alert records, investigation timelines, analyst actions, tuning or exclusion approvals, remediation results, and case closure, linked to stable identifiers, time, and operator.\n\nRecord the decision even when no change is made, including uncertainty and the next trigger. Use safe testing conditions for disruptive work, preserve rollback proof, and revisit the conclusion after relevant platform, dependency, vendor, or ownership changes.\n\n## Official references\n\n- [Investigate and protect Service Accounts](https://learn.microsoft.com/en-us/defender-for-identity/service-account-discovery) — Microsoft"
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/inventory-service-accounts-with-recent-authentication-context/",
                "url": "https://update.dsesecurity.com/updates/inventory-service-accounts-with-recent-authentication-context/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-08-26"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/inventory-service-accounts-with-recent-authentication-context/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Inventory service accounts with their recent authentication context",
                        "item": "https://update.dsesecurity.com/updates/inventory-service-accounts-with-recent-authentication-context/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/inventory-service-accounts-with-recent-authentication-context/#article",
                "identifier": "https://update.dsesecurity.com/updates/inventory-service-accounts-with-recent-authentication-context/",
                "url": "https://update.dsesecurity.com/updates/inventory-service-accounts-with-recent-authentication-context/",
                "headline": "Inventory service accounts with their recent authentication context",
                "description": "Use Investigate and protect Service Accounts to review this narrow operational decision without extending the source beyond its stated scope.",
                "abstract": "Use Investigate and protect Service Accounts to review this narrow operational decision without extending the source beyond its stated scope.",
                "articleBody": "Use this document to connect an official requirement or behavior to observable evidence: Inventory service accounts with their recent authentication context. Only the official source and traced locations below supply facts. Confirm applicability before acting.\nSource fact:\nThe official Investigate and protect Service Accounts from Microsoft supports the following bounded statements:\n\nService accounts often have elevated privileges but generally cannot use modern authentication protections such as MFA in the same way as human accounts. The research record locates this support at Opening risk overview.\nAutomatic discovery identifies gMSA and sMSA accounts and user accounts meeting criteria such as an SPN plus password-never-expires, and presents recent authentication sources and destinations. The research record locates this support at Auto-discovery section.\n\nThe source support ends with the statements listed above. Use them to examine identity alerts, investigations, remediation roles, evidence retention, escalation, exclusions, and incident workflows in the applicable environment, not to imply a wider guarantee.\nWhat the source does not establish\nClassification criteria identify candidates, not confirmed business purpose, ownership, necessity, or compromise. No current deployment state or change approval follows from the source alone. Validate Active Directory, Windows DNS, time, cloud portals, endpoint data, network telemetry, privileged access, and response staffing, and treat examples or options as conditional inputs rather than defaults.\nApplicability questions\n\nFor source statement 1 at Opening risk overview, which observable configuration, record, or test can confirm applicability here?\nFor source statement 2 at Auto-discovery section, which observable configuration, record, or test can confirm applicability here?\nWhich deployed instance of identity alerts, investigations, remediation roles, evidence retention, escalation, exclusions, and incident workflows will be compared with the source, and why that instance?\nHow will the review distinguish a source mismatch from a failure in Active Directory, Windows DNS, time, cloud portals, endpoint data, network telemetry, privileged access, and response staffing?\nWho approves the conclusion, exception, test window, and rollback threshold?\n\nDSE recommendation:\nDSE recommends using the cited source as the evidence anchor for this decision. Make the source, asset scope, owner, and expected outcome explicit in the review record. Record the source location, examined part of identity alerts, investigations, remediation roles, evidence retention, escalation, exclusions, and incident workflows, observed and expected states, owner, and reason for deviation.\nDo not move from citation to production in one step. Pilot the decision where practical, observe agreed signals, retain a reversal point, and verify Active Directory, Windows DNS, time, cloud portals, endpoint data, network telemetry, privileged access, and response staffing. Handle credentials, keys, recovery data, and personal information through approved secure channels.\nVerification and evidence\nEvidence should let another reviewer reproduce this decision. Retain observations beside the traced locations Opening risk overview; Auto-discovery section. Favor alert records, investigation timelines, analyst actions, tuning or exclusion approvals, remediation results, and case closure, linked to stable identifiers, time, and operator.\nRecord the decision even when no change is made, including uncertainty and the next trigger. Use safe testing conditions for disruptive work, preserve rollback proof, and revisit the conclusion after relevant platform, dependency, vendor, or ownership changes.\nOfficial references\n\nInvestigate and protect Service Accounts — Microsoft",
                "datePublished": "2026-08-27T12:13:12+00:00",
                "dateModified": "2026-08-27T13:01:32+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/inventory-service-accounts-with-recent-authentication-context/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/inventory-service-accounts-with-recent-authentication-context/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Inventory service accounts with their recent authentication context"
                },
                "articleSection": [
                    "Cybersecurity",
                    "IT",
                    "Microsoft 365 & Identity"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Microsoft 365 & Identity",
                    "Guide",
                    "Advisory priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Microsoft 365 & Identity",
                        "url": "https://update.dsesecurity.com/topic/microsoft-365-identity/"
                    }
                ],
                "wordCount": 509,
                "timeRequired": "PT3M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Investigate and protect Service Accounts",
                    "url": "https://learn.microsoft.com/en-us/defender-for-identity/service-account-discovery",
                    "datePublished": "2025-03-25"
                }
            }
        ]
    }
}