performing-service-account-audit

Inventory service accounts across AD, cloud IAM, databases, and applications and classify risk from ownership, privileges, password posture, and activity.

2|Updated Apr 14, 2026
One-click install
npx skills add https://github.com/Acczdy/MoZiSec --skill performing-service-account-audit
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: performing-service-account-audit
Source: https://github.com/Acczdy/MoZiSec/tree/main/iam/.claude/skills/performing-service-account-audit
Command: npx skills add https://github.com/Acczdy/MoZiSec --skill performing-service-account-audit

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

Auditing service accounts is complex and error-prone when ownership, privileges, and rotation policies are scattered across Active Directory, cloud IAM, databases, and applications.

Core Features & Use Cases

  • Discover and inventory service accounts across AD, cloud IAM, databases, and apps (including SPNs and gMSA candidates).
  • Assess ownership, privileges, password posture, last activity, and interactive logon to classify risk and generate remediation guidance.
  • Generate a structured audit report aligned to compliance standards (NIST, PCI DSS, SOX) with actionable remediation steps.
  • Use Case: When performing a quarterly security audit, automatically identify orphaned and over-privileged accounts and propose concrete mitigations.

Quick Start

Identify and inventory service accounts across AD, cloud IAM, databases, and apps.

Frequently Asked Questions about performing-service-account-audit

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I audit service accounts across Active Directory and cloud IAM?

To audit service accounts, you identify and inventory accounts across AD, cloud IAM, databases, and apps, then assess ownership, privileges, and password posture to classify risk and generate a remediation report.

What is the best way to identify orphaned and over-privileged service accounts?

Identifying orphaned and over-privileged service accounts involves assessing ownership, last activity, and interactive logon records to classify risk and propose concrete mitigations aligned with least-privilege controls.

Does this approach detect Kerberoast and gMSA candidates during a service account audit?

Detecting Kerberoast and gMSA candidates is part of the inventory process, discovering service accounts across AD, cloud IAM, databases, and applications to assess their password posture and privilege levels.

Can I generate a compliance audit report for service accounts aligned with NIST or PCI DSS?

Generating a compliance audit report for service accounts aligned with NIST, PCI DSS, or SOX involves classifying account risks and delivering actionable remediation steps to enforce rotation and least-privilege controls.

What do I need to inventory service accounts before enforcing password rotation policies?

Inventorying service accounts before enforcing password rotation requires access to AD, cloud IAM, databases, and applications to assess current password posture, ownership, and interactive logon activity for risk classification.

Why are service account audits prone to errors when ownership is scattered across platforms?

Service account audits are error-prone when ownership, privileges, and rotation policies are scattered across Active Directory, cloud IAM, databases, and applications, making centralized inventory and risk assessment essential.