Skip to content

Service and shared accounts: inventory, ownership and managed passwords

Accounts that aren't one person: services, scheduled tasks, devices and shared logins. How to inventory them with an owner and purpose, choose the right principal type (virtual account, sMSA, gMSA, or a user account as the last resort), set up and run a group Managed Service Account end to end, and control shared accounts so their secrets change when people leave.

Level
Advanced
Length
About 65 minutes
Contents
3 lessons · 1 video · final exam
Status
Published · updated 3 Oct 2026

Skills you'll practise

  • Build a service account inventory with owner, purpose, hosts, rights and password age, and rank its risks
  • Choose between a virtual account, sMSA, gMSA and a user account using where the service runs and who manages the password
  • Create, install, test and retire a gMSA, including the KDS root key and the hosts allowed to retrieve its password
  • Recognise gMSA limits: interval set only at creation, forest-unique names, failover clusters and encryption types
  • Control shared accounts: individual accounts first, vaulting, and changing secrets when someone leaves

Course outline

  1. 1.Service and shared accountsVideo · 2 min
  2. 2.Know your non-person accountsLesson · 20 min
  3. 3.Choosing a principal, and running a gMSALesson · 26 min
  4. 4.Shared accounts and migrating old servicesLesson · 19 min
  5. 5.Service and shared accounts: inventory, ownership and managed passwords: knowledge checkKnowledge check · 18 questions
  6. 6.Final exam9 questions · passing it completes the course, so people who already know the material can test out

Sources it draws on

The lessons and questions are written from these references, so learners can go back to the original.

See it with your own jobs and topics

Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.