The discovery and management of service accounts are the main focus of this document. Within this context, we are mostly concerned with the management of Windows service accounts, because -- unlike on other platforms -- on the Windows operating system, to start a process in the security context of a given account, the password for that account must be provided. This creates the need to manage passwords for service accounts on Windows (on other platforms, service accounts normally do not have a password).

This document is intended for a technical audience which has been tasked with replacing static, manually maintained embedded Windows service account credentials with an automated process where these credentials are periodically changed to new, random values.

