Views:

View details about the service accounts in your organization.

The Service Account tab allows you to view details of all service accounts in your organization. A service account is the primary security identity of a service that determines its access permissions to resources.
The following table details the columns on the Service Account tab.
Column name
Description
Service account name
Name of a service account in your organization.
Account privilege
Privilege level of an account. An account’s privilege level depends on its access rights and the objects it can access in Active Directory (on-premises).
The values are as follows:
  • High: The account can modify domain security settings, ACLs, or has full control over critical infrastructure.
    Examples: Domain Admins, Enterprise Admins, accounts with the Write DACL or Owner permission on Group Policies or Certificate Authorities.
  • Medium: The account can create, modify, or delete identity objects, for example, users, groups, computers.
  • Low: The account has read-only access to directory objects.
  • - (unavailable): The privilege level of the account is temporarily unavailable due to data sync or processing delays.
Status
Status of a service account. An enabled service account is allowed to sign in to the domain network.
Groups
Groups to which a service belongs.
Click on the number in the Groups column to view details about the groups to which the service account belongs.
Primary group
Default group to which a service account belongs.
User account control
Properties assigned to a service account to control access rights and behaviors, determine account type, and set restrictions.
Service account type
Type of a service account.
  • Standalone managed: runs on a server farm or behind a network load balancer
  • Group managed: runs on only one server
Service principal names
Service principal names associated with a service account. A service principal name is a unique identifier of a service instance.
Password last changed
Last time when the password of a service account was changed.
Created
Time when a service account was created.
Distinguished name
A fully qualified unique name that identifies a service account in a directory.