Cloud platform
Cloud console users, access keys and service identities; the credential report carries last used and last rotated per key. The checker reads the system column to group the accounts; the findings come from the other columns, the same way for every system.
What the export usually carries
A cloud platform credential report usually carries one line per user with console password enabled, password last used, password last changed, MFA active, and per access key: active, last rotated and last used. Keys are dated per key, not per user, so a user with two keys has two dates; password last used covers console sign-in only and says nothing about key use. Roles and workload identities often appear in a different listing with their own last used field.
What the checker most often raises here
- 6. Password or key not changed within the period, or never: The last changed date is more than the period you set (default 365 days) before the as-at date, or the list says never. With PCI DSS ticked, a user account whose MFA does not read yes also fires at more than 90 days (8.3.9); with MFA not recorded that line is a question. For a system account under PCI DSS 8.6.3 the period is your targeted risk analysis, and the one you set stands in for it.
- 8. Credential stored in code, a config file or a script: The stored-in column reads code, a config file, a script, or a document (a spreadsheet, a wiki, an email or a chat).
- 5. Privileged, and orphaned or dormant: The account is privileged (its privileged column reads yes, its member-of column names an administrative group, or it is an administrator, break-glass or built-in administrator account) and it carries finding 1, 2, 3 or 4.
- 2. Owner has left, or owner not recognised: The account is not a personal account, its owner names a person, and the staff list is pasted: when the list says that person has left it is a gap; when the owner is not in the list at all it is a question ("owner not recognised, confirm"). Without a staff list this finding never fires.
Account types found here
- Built-in or vendor default accounta system account
- Break-glass or emergency accounta user account
- AI agent credentiala system account
- Automation or bot (scheduled jobs, RPA)a system account
- Service accounta system account
- API key or access keya system account
- OAuth client or app registrationa system account
- Device or workload identitya system account
- Mailbox or resource accounta user account
- Test accounta user account
- Shared or generic logina user account
- Administrator or privileged person accounta user account
- Contractor or guesta user account
- Person (employee)a user account
The system names in your export are matched to these classes by the browser dictionary; product names are never shown on these pages. A system the dictionary does not place reads as other, and every finding still works.