Shared Account
A shared account is a single set of credentials used by more than one person, or by a function rather than a person, such as a team mailbox, a kiosk or front-desk login, a vendor support account, or a generic administrator.
Shared accounts break accountability, because actions cannot be tied to an individual, and they tend to escape the controls applied to everyone else: they are exempted from MFA because nobody is there to answer the prompt, their passwords are rarely rotated because several people would need the new one, and they have no named owner to review them. That combination makes them a favorite target for password spraying; in September 2026, a campaign against more than 5,700 Microsoft 365 accounts succeeded only against functional accounts on default passwords with no MFA. Replace them with delegated access from individual accounts wherever the platform allows, block interactive sign-in for functional accounts that do not need it, and put any unavoidable shared credential behind a PAM vault with check-out and session recording.
See also: service account, orphaned account, break-glass accounts, non-human identity
Related on Start with Identity
- GlossaryDeprovisioning
Removing access when a user leaves or changes roles. Failed deprovisioning leaves orphaned accounts that auditors flag and attackers exploit. SCIM with HR-drive
- GlossaryIAM
Identity and Access Management. Workforce identity for employees, contractors, and partners. Covers authentication, authorization, lifecycle, and audit. Distinc
- GlossaryJust-in-Time (JIT) Access
Granting elevated permissions only when needed, for a limited duration, and revoking them automatically. JIT eliminates standing privilege, the largest contribu
- Blog1Password buys Apono, moving from credential vault to access control plane
Reported at 250 to 300 million dollars, the deal gives 1Password just-in-time privileged access across AWS, Azure, GCP, Kubernetes, Snowflake, and Databricks, a
- CVEBeyondTrust PRA and Remote Support unauthenticated command injection
Privileged Remote Access and Remote Support accepted a malicious client request and ran OS commands as the site user. Unauthenticated. CVSS 9.8. CISA KEV. A PAM
- BlogPalo Alto Networks closes its 25 billion dollar CyberArk acquisition
The largest deal in security industry history closed on 11 February 2026. CyberArk shareholders took 45 dollars cash plus 2.2005 Palo Alto shares per ordinary s