REGISTER REVISED SEPTEMBER 2026

What is a local account?

ILM Reference editors · Last reviewed September 2026

SUMMARYREV. 2026-09

A local account is a user account created and stored inside an application or system rather than in the central directory or identity provider. Because the identity provider does not manage it, disabling a leaver's directory account does not disable it. Local accounts are a main source of orphan accounts.

What are common examples?

  • An application's built-in admin account.
  • A vendor support login created in the app.
  • A break-glass account for emergencies.
  • Accounts in legacy apps that predate SSO.

Why are local accounts a risk?

They bypass central controls such as MFA and offboarding, and often carry high privilege. Orchid Security describes 'local, service, and app-native accounts' that 'bypass central controls, accumulating privilege without visibility'.

How do you find them?

Pull the account list from inside each application, then reconcile it to the directory. Veza states it reveals local, machine and service accounts outside identity platforms where it has an integration; Orchid Security states it surfaces local user activity inside applications it discovers. See the orphan accounts guide.

FAQ

Should local accounts be eliminated?

Where the app supports SSO, yes for normal users. Some local accounts (break-glass, service) remain necessary; give each a named owner, rotate credentials and review them.

Sources

Reviewed Sep 2026

Related