Microsoft Defender for Identity
Identity protection

Service Account Discovery

In brief

The documentation explains that custom classification rules can identify service accounts Defender for Identity does not detect automatically, such as accounts using an `srv` prefix.

What Defender admins need to know

Administrators can review the guidance to improve service account identification; no required action is stated.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Define Service Account classification rules

Service account classification rules let you define your own criteria for identifying service accounts. These rules help you include service accounts that Defender for Identity doesn't identify automatically. For example, some organizations name all their service accounts with a prefix like srv. Defender for Identity doesn't automatically detect such naming conventions. By creating a classification rule based on that pattern, you can include those accounts in the Service accounts view. Classification rules are applied only to accounts that are not already automatically identified by Defender for Identity. Accounts detected automatically aren't evaluated by classification rules.

Classification rules work alongside Defender for Identity’s automatic discovery and provide a more complete and customized view of service accounts in your environment.