# shared-account

Source: https://startwithidentity.com/glossary/shared-account/
Last updated: 2026-09-29
License: content by Start with Identity. Cite the source URL.

---

A shared account is a single set of credentials used by more than one person, or by a function rather than a person, such as a team mailbox, a kiosk or front-desk login, a vendor support account, or a generic administrator.

Shared accounts break accountability, because actions cannot be tied to an individual, and they tend to escape the controls applied to everyone else: they are exempted from MFA because nobody is there to answer the prompt, their passwords are rarely rotated because several people would need the new one, and they have no named owner to review them. That combination makes them a favorite target for [password spraying](https://startwithidentity.com/techniques/password-spraying/); in September 2026, a campaign against more than 5,700 Microsoft 365 accounts succeeded [only against functional accounts on default passwords with no MFA](https://startwithidentity.com/blog/2026-09-24-teamfiltration-spraying-found-seven-service-accounts-on-default-passwords/). Replace them with delegated access from individual accounts wherever the platform allows, block interactive sign-in for functional accounts that do not need it, and put any unavoidable shared credential behind a [PAM](https://startwithidentity.com/glossary/pam/) vault with check-out and session recording.

See also: [service account](https://startwithidentity.com/glossary/service-account/), [orphaned account](https://startwithidentity.com/glossary/orphaned-account/), [break-glass accounts](https://startwithidentity.com/glossary/break-glass/), [non-human identity](https://startwithidentity.com/glossary/nhi/)
