[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fSWIBOUzy1fgN5VSQloZ1h0EMfONMq2bXjAUCJvIe6Yk":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":41},"ba63f93b-af01-483e-8378-b9c3e8796b74","ghost-service-accounts-expose-m365-environments-to-data-theft","2a018a8e-b3b9-4d88-8abe-65e826770812","Ghost Service Accounts Expose M365 Environments to Data Theft","The root cause of this threat is the failure to properly manage and decommission service accounts throughout their lifecycle, leaving 'ghost' accounts with persistent access to sensitive Microsoft 365 data long after they are needed. Unlike human user accounts, service accounts are frequently excluded from standard offboarding and audit processes, creating invisible attack surfaces that threat actors can exploit. This matters because a single overlooked service account can grant broad access to organizational data, bypassing all user-level security controls that have been carefully implemented. The Chile incidents demonstrate that identity hygiene is not just about active employees — every privileged identity, human or non-human, must be continuously governed.","**Immediate actions:**\n- Conduct a full audit of all M365 service accounts and immediately disable or remove any that lack a verified, active business owner.\n- Revoke and rotate credentials for all service accounts that have not been reviewed within the past 90 days.\n\n**Long-term improvements:**\n- Implement a formal identity lifecycle management policy that explicitly covers service and non-human accounts, including scheduled access reviews.\n- Integrate service account discovery and governance into the employee offboarding and project decommissioning workflows.\n- Apply the principle of least privilege to all service accounts, restricting permissions to only the minimum required resources.\n\n**Detection measures:**\n- Enable Microsoft 365 Unified Audit Logging and configure alerts for unusual data access or bulk download activity originating from service accounts.\n- Deploy a Privileged Access Management (PAM) solution to continuously monitor, record, and alert on service account usage and privilege escalation.",[12,13,14,15,16,17,18,19,20],"CIS Control 5 – Account Management","CIS Control 6 – Access Control Management","NIST SP 800-53 AC-2 (Account Management)","NIST SP 800-53 AC-6 (Least Privilege)","NIST SP 800-53 IA-4 (Identifier Management)","NIST CSF PR.AC-1 (Identities and credentials are managed)","ISO\u002FIEC 27001 A.9.2 – User Access Management","GDPR Article 32 – Security of Processing (access control obligations)","MITRE ATT&CK T1078.004 – Valid Accounts: Cloud Accounts","published","2026-09-24T19:20:31.574434+00:00","2026-09-24T19:20:31.202+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fwww.darkreading.com\u002Fcyberattacks-data-breaches\u002Fghost-service-accounts-m365-data-theft-chile","ghost-service-accounts-enable-m365-data-theft-in-chile-75c374","Ghost Service Accounts Enable M365 Data Theft in Chile",[29,35],{"id":30,"name":31,"slug":32,"description":33,"color":34},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":36,"name":37,"slug":38,"description":39,"color":40},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",[]]