Dormant Service Accounts Are Putting Your Business at Risk – Here’s How to Stop It

“You can’t secure what you can’t see – and attackers know it.”

In the depths of your Active Directory (AD) environment, service accounts silently linger – forgotten, unmanaged, and dangerously privileged. Created for tasks long past, these accounts are often ignored in routine security reviews. But for cybercriminals, they’re not just remnants of legacy systems – they’re prime entry points for stealthy attacks.

The Forgotten Threat Lurking in Plain Sight

Service accounts aren’t like regular user accounts. They don’t log off at the end of the workday, they don’t reset their passwords every three months, and no one complains when they get locked out. That makes them invisible… and dangerous.

Dormant or orphaned service accounts – created for decommissioned apps, old automation scripts, or test environments – can sit untouched for years. Their inactivity doesn’t make them harmless. In fact, that’s exactly what makes them such appealing targets for threat actors.

Why Dormant AD Service Accounts Matter

Botnet Exploits the Forgotten

In early 2024, a massive botnet comprising over 130,000 devices was discovered hammering Microsoft 365 service accounts in a password-spraying campaign. The attackers bypassed multi-factor authentication (MFA) by exploiting environments still using basic authentication. The result? Widespread compromise that went undetected for weeks.

This kind of exploitation is no longer theoretical – it’s operational.

How Attackers Exploit Dormant Accounts

Silent Elevation – Accounts initially granted minimal access can accumulate permissions over time through nested groups or legacy configurations – a phenomenon known as privilege creep.

Credential Hunting – Attackers who gain a foothold via phishing or social engineering often look for poorly monitored service accounts to escalate privileges and move laterally.

Bypassing MFA – Service accounts are rarely configured for MFA, and if they rely on basic authentication, they become even easier to exploit.

The Risks of Dormant Service Accounts

Here’s why ignoring service accounts is a mistake no security team can afford:

1. Unauthorised Access

Left active with old credentials, these accounts offer threat actors a silent backdoor into your environment – one that’s often missed in monitoring tools.

2. Privilege Abuse

An attacker compromising a dormant account with elevated privileges can cause data breaches, service disruptions, and even gain domain-level control.

3. Regulatory Non-Compliance

Many standards (PCI DSS, HIPAA, GDPR) require regular auditing and access reviews. Forgotten service accounts can result in fines and reputational damage if breached.

How to Find What’s Lurking

Security begins with visibility. You can’t protect what you don’t know exists.

Here are key steps to uncover dormant or risky service accounts:

Query AD for SPN-Enabled Accounts – These are typically used for inter-service authentication and are often overlooked.

Filter for Non-Expiring Passwords – A red flag for dormant or insecure accounts.

Audit Scripts and Scheduled Tasks – Look for hard-coded credentials referencing legacy accounts.

Review Privilege Inheritance – Accounts may have inherited elevated permissions over time without anyone noticing.

Security Best Practices: How to Lock Down Service Accounts

Enforce Least Privilege

Only give accounts the access they need—nothing more. Avoid assigning service accounts to broad groups like Domain Admins.

Use Managed Service Accounts (MSAs/gMSAs)

These accounts rotate their own passwords and can’t be used for interactive logins, reducing risk and easing management.

Regularly Audit Account Usage

Track when service accounts last logged in, what they accessed, and whether permissions have drifted.

Rotate and Secure Passwords

Avoid hard-coded credentials. Use long, complex passphrases or automate password rotation using secure tooling.

Disable Interactive Login

Service accounts should never be used to log in directly. Prevent it at the policy level.

Organise Into OUs

Placing service accounts in dedicated organisational units makes it easier to apply security policies and detect anomalies.

Review Access and Dependencies

If an account is no longer used, disable or delete it. Don’t let technical debt create an open door for attackers.

Don’t Wait for the Stink to Start

Like a lunchbox left in a school locker over the summer, the risk from dormant service accounts only gets worse the longer it’s ignored. The more forgotten logins that live in your environment, the more opportunities you hand to an attacker.

Ready to Shut the Back Door?

Dormant service accounts are more than an IT hygiene issue – they’re a serious threat vector. If you’re ready to take control of your AD environment and reduce risk, we’re here to help.

Contact us today for expert advice and tools that secure your service accounts, simplify compliance, and harden your Active Directory.