Network and security devices
Local accounts on firewalls, VPN concentrators and appliances, where vendor default accounts live longest. The checker reads the system column to group the accounts; the findings come from the other columns, the same way for every system.
What the export usually carries
Network and security devices usually keep local accounts in their own configuration: the account name, role or privilege level and sometimes a last login. Password change dates are rarely exported, and vendor default accounts live longest here; an export may come from a configuration backup rather than a user report.
What the checker most often raises here
- 13. Vendor default or built-in account enabled: The account is a built-in or vendor default account (from the type column, or a whole account name such as admin, root, sa or guest) and does not read as disabled.
- 9. Shared or generic login used by people: The account type is a shared or generic login, from the type column or assumed from the name.
- 6. Password or key not changed within the period, or never: The last changed date is more than the period you set (default 365 days) before the as-at date, or the list says never. With PCI DSS ticked, a user account whose MFA does not read yes also fires at more than 90 days (8.3.9); with MFA not recorded that line is a question. For a system account under PCI DSS 8.6.3 the period is your targeted risk analysis, and the one you set stands in for it.
- 3. No owner named, or a team named with no accountable person: The account is not a personal account and its owner cell is blank, "unknown", "TBC" or similar, or names a team, a department or a mailbox with no accountable person named beside it. When an accountable, approver or owner of record column names a person for the team, this finding does not fire; with a staff list, that person is checked like any owner (left is finding 2, not in the list is a question).
Account types found here
- Built-in or vendor default accounta system account
- Break-glass or emergency accounta user account
- AI agent credentiala system account
- Automation or bot (scheduled jobs, RPA)a system account
- Service accounta system account
- API key or access keya system account
- OAuth client or app registrationa system account
- Device or workload identitya system account
- Mailbox or resource accounta user account
- Test accounta user account
- Shared or generic logina user account
- Administrator or privileged person accounta user account
- Contractor or guesta user account
- Person (employee)a user account
The system names in your export are matched to these classes by the browser dictionary; product names are never shown on these pages. A system the dictionary does not place reads as other, and every finding still works.