IP Library › Granted Patent US 12,432,220
Granted Patent B2
US 12,432,220 · App. 18/133,878 · Granted Sep 30, 2025

Dormant service account disablement system

Inventors: Melody Wilkins Sherer (Alexis, NC); Christina Finnell Clark (Terrell, NC); Derek Jia Liang Feng (Colma, CA); Jack T. Lockamy (Carrollton, TX); Ryan Bondura Essa (Jacksonville, FL); Jonathan Thole (Denver, CO)
Assignee: Bank of America Corporation
H04L63/108G06F21/50G06Q40/02H04L63/102H04L63/1408H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,432,220
App. No.
18/133,878
Granted
Sep 30, 2025
Kind
B2
Abstract

Various aspects of the disclosure relate to identifying and disabling dormant service accounts. An account management system automatically analyzes service account activity records to determine whether each service account defined for an enterprise network is in use. Automated monitoring applications may be used for identifying and authenticating events and/or authentications of service accounts across an enterprise network. When particular service accounts are identified as being potentially dormant, based on an identified date of last use meeting a threshold condition, the associated service accounts are flagged as being dormant. Setting an account as being dormant triggers solicitation of feedback confirming the dormant setting, which causes disablement of the service account. The account management system triggers decommissioning of the dormant service accounts upon expiration of a disablement threshold.

Claims (55)

1. A method comprising:

aggregating, automatically by service account monitoring engine, event activities of a plurality of service accounts on an enterprise network, wherein each service account comprises a machine user account in a user management system that enables autonomous operation of an autonomous job within the enterprise network and wherein operation of the autonomous job fails without a valid service account;

determining, based on aggregated information associated with the event activities of the plurality of service accounts, an identity of a plurality of potentially dormant service accounts;

verifying, automatically in response to generation of a listing of the plurality of potentially dormant service accounts, whether each potentially dormant service account is dormant or active;

disabling, automatically based on a received confirmation input confirming dormancy of a first potentially dormant service account, monitoring of the first potentially dormant service account;

disabling the first potentially dormant service account;

re-enabling, based on failure of an autonomous job whose operation is reliant upon the first potentially dormant service account, the first potentially dormant service account; and

decommissioning, at a directory service server and automatically based on expiration of a disablement time threshold, the first potentially dormant service account.

2. The method of claim 1 wherein aggregating event activities of the plurality of service accounts comprises:

retrieving, via the enterprise network, event logs associated with service account activities associated with each application of a plurality of applications associated with the plurality of service accounts; and

retrieving, via the enterprise network and from a directory service, service account event and activity records associated with each application of the plurality of applications.

3. The method of claim 2 , wherein the plurality of service accounts comprises a subset of the plurality of service accounts and wherein the subset of service accounts comprises a listing of service accounts having an active status.

4. The method of claim 1 , further comprising generating a historical data store of service account activities, the historical data store comprising event and activity information associated with each service account managed by a directory service.

5. The method of claim 4 , wherein determining an identity of a plurality of potentially dormant service accounts comprises identifying, from historical aggregated event data, service accounts having no logged activity within a first defined time period.

6. The method of claim 5 , wherein the first defined time period comprises 180 days.

7. The method of claim 1 , further comprising:

initiating, based on a re-enablement request, a re-enablement process to restore operation of a restored service account that had been previously disabled; and

re-enabling monitoring of a restored service account based on receiving a re-enablement request input.

8. The method of claim 1 , wherein a disablement event comprises setting an enablement flag within a directory service that is associated with a confirmed dormant service account and an enablement event comprises resetting the enablement flag.

9. A system comprising:

a directory service managing a plurality of service accounts, each service account corresponding to an automated job within an enterprise network, wherein the automated job is inoperable without an associated and enabled service account; and

a computing device comprising:

a processor; and

non-transitory memory storing instructions that, when executed by the processor, cause the computing device to:

aggregate, automatically by a service account monitoring engine, event activities of a plurality of service accounts on an enterprise network, wherein each service account comprises a machine user account in a user management system that enables autonomous operation of a computerized process within the enterprise network;

determine, based on aggregated information associated with the event activities of the plurality of service accounts, an identity of a plurality of potentially dormant service accounts;

verify, automatically in response to generation of a listing of the plurality of potentially dormant service accounts, whether each potentially dormant service account is dormant or active;

disable, automatically based on a received confirmation input confirming dormancy of a first potentially dormant service account, monitoring of the first potentially dormant service account;

re-enable, based on failure of an autonomous job whose operation is reliant upon the first dormant service account, the first potentially dormant service account; and

decommission, automatically based on expiration of a disablement time threshold, the first potentially dormant service account.

10. The system of claim 9 , wherein the instructions further cause the computing device to

retrieve, via the enterprise network, event logs associated with service account activities associated with each application of a plurality of applications associated with the plurality of service accounts; and

retrieve, via the enterprise network and from a directory service, service account event and activity records associated with each application of the plurality of applications.

11. The system of claim 10 , wherein the plurality of service accounts comprises a subset of the plurality of service accounts and wherein the subset of service accounts comprises a listing of service accounts having an active status.

12. The system of claim 9 , wherein the instructions further cause the computing device to generate a historical data store of service account activities, the historical data store comprising event and activity information associated with each service account managed by the directory service.

13. The system of claim 12 , wherein the instructions further cause the computing device to identify, from historical aggregated event data, service accounts having no logged activity within a first defined time period.

14. The system of claim 13 , wherein the first defined time period comprises 180 days.

15. The system of claim 9 , wherein the instructions further cause the computing device to:

initiate, based on a re-enablement request, a re-enablement process to restore operation of a restored service account that had been previously disabled; and

re-enable monitoring of a restored service account based on receiving a re-enablement request input.

16. The system of claim 9 , wherein a disablement event comprises setting an enablement flag within the directory service that is associated with a confirmed dormant service account and an enablement event comprises resetting the enablement flag.

17. A non-transitory computer readable medium storing instructions that, when executed by a processor, cause a computing platform to:

aggregate, automatically by service account monitoring engine, event activities of a plurality of service accounts on an enterprise network, wherein each service account comprises a machine user account in a user management system that enables autonomous operation of an autonomous job within the enterprise network and wherein operation of the autonomous job fails without a valid service account;

determine, based on aggregated information associated with the event activities of the plurality of service accounts, an identity of a plurality of potentially dormant service accounts;

verify, automatically in response to generation of a listing of the plurality of potentially dormant service accounts, whether each potentially dormant service account is dormant or active;

disable, automatically based on a received confirmation input confirming dormancy of a first potentially dormant service account, monitoring of a first dormant service account;

re-enable, based on failure of an autonomous job whose operation is reliant upon the first dormant service account, the first dormant service account; and

decommission, automatically based on expiration of a disablement time threshold, the first dormant service account.

18. The non-transitory computer readable medium of claim 17 , wherein the instructions further cause the computing platform to

retrieve, via the enterprise network, event logs associated with service account activities associated with each application of a plurality of applications associated with the plurality of service accounts; and

retrieve, via the enterprise network and from a directory service, service account event and activity records associated with each application of the plurality of applications.

19. The non-transitory computer readable medium of claim 17 , wherein the instructions further cause the computing platform to generate a historical data store of service account activities, the historical data store comprising event and activity information associated with each service account managed by a directory service.

20. The non-transitory computer readable medium of claim 17 , wherein the instructions further cause the computing platform to:

initiate, based on a re-enablement request, a re-enablement process to restore operation of a restored service account that had been previously disabled; and

re-enable monitoring of a restored service account based on receiving a re-enablement request input.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 12, 2023
From: SHERER, MELODY WILKINS; CLARK, CHRISTINA FINNELL; FENG, DEREK JIA LIANG; LOCKAMY, JACK T.; ESSA, RYAN BONDURA; THOLE, JONATHAN
To: BANK OF AMERICA CORPORATION
Reel/Frame 063305/0866 →
Continuity (1)
Related Publication 20240348617A1 · Oct 17, 2024
References Cited (16)
US 8503634B1 · Townsend, III · 2013 [cited by examiner]
US 9167047B1 · Sharma et al. · 2015 [cited by applicant]
US 9485271B1 · Roundy et al. · 2016 [cited by applicant]
US 10257201B2 · Parees et al. · 2019 [cited by applicant]
US 10567388B1 · Kruse · 2020 [cited by examiner]
US 10944759B2 · Hidden et al. · 2021 [cited by applicant]
US 11526385B1 · Mannar · 2022 [cited by examiner]
US 11615350B2 · Wisniewski · 2023 [cited by applicant]
US 20090137225A1 · Costanzo · 2009 [cited by examiner]
US 20170063873A1 · Hidden · 2017 [cited by examiner]
US 20190394240A1 · Israel et al. · 2019 [cited by applicant]
US 20200169529A1 · Teverovsky et al. · 2020 [cited by applicant]
US 20210157907A1 · Argoety · 2021 [cited by examiner]
US 20220060479A1 · Perkins · 2022 [cited by examiner]
US 20220391927A1 · Jain · 2022 [cited by examiner]
US 20230004556A1 · Campbell et al. · 2023 [cited by applicant]