Operating system local accounts
Local administrator and service accounts on servers and endpoints, outside the directory. The checker reads the system column to group the accounts; the findings come from the other columns, the same way for every system.
What the export usually carries
Operating system local accounts come from a per-host listing: the account, whether it is enabled, password last set and group membership (local administrators). Last logon on a local account may only be recorded on that host, so a central export may show it blank.
What the checker most often raises here
- 13. Vendor default or built-in account enabled: The account is a built-in or vendor default account (from the type column, or a whole account name such as admin, root, sa or guest) and does not read as disabled.
- 7. Service or system account that allows interactive login: An application or system account (service account, API key, OAuth client, agent, automation or workload identity) whose interactive login column reads yes.
- 5. Privileged, and orphaned or dormant: The account is privileged (its privileged column reads yes, its member-of column names an administrative group, or it is an administrator, break-glass or built-in administrator account) and it carries finding 1, 2, 3 or 4.
- 4. Dormant for more than the threshold: The account is enabled or its status is not recorded, it is not a break-glass account, and its last used date is more than the threshold you set (default 90 days) before the as-at date. With CIS Controls ticked, more than 45 days (CIS 5.3) also fires; with PCI DSS ticked, more than 90 days (8.2.6) fires on user accounts. An account never used fires when its created date is older than the same periods. Exactly the period never fires.
Account types found here
- Built-in or vendor default accounta system account
- Break-glass or emergency accounta user account
- AI agent credentiala system account
- Automation or bot (scheduled jobs, RPA)a system account
- Service accounta system account
- API key or access keya system account
- OAuth client or app registrationa system account
- Device or workload identitya system account
- Mailbox or resource accounta user account
- Test accounta user account
- Shared or generic logina user account
- Administrator or privileged person accounta user account
- Contractor or guesta user account
- Person (employee)a user account
The system names in your export are matched to these classes by the browser dictionary; product names are never shown on these pages. A system the dictionary does not place reads as other, and every finding still works.