A post-go-live access audit finds that the built-in administrative account is still logging in weekly, even though every operator has had a named account since cutover. What is the correct reading of that finding?
Select an answer to reveal the explanation.
Short Explanation
Weekly logins by the built-in account mean the model is quietly dissolving: each one of those logins buries a real person inside a shared name. Check built-in usage after cutover and shut the habit down - named accounts you don't use are worse than named accounts you never made. That account is for the recovery day, not for Tuesdays.
Full Explanation
A built-in account is a bootstrap and recovery instrument; the finding shows the organization never graduated past it. Weekly successful logins under the built-in identity mean real work by real humans is running under a shared name again after cutover, which silently undoes the named-account model: accountability collapses into a trail segment that identifies nobody, rotating or revoking the built-in credential now means coordinating with daily routine, and the log's promise - a name behind every command - stops holding. That is why post-go-live checks include actively reviewing built-in account usage, not merely confirming its password is strong. The 'directory is failing' reading is testable but contradicted by evidence: fallback under a broken directory would show failed logins and incident tickets, not a calm weekly habit. 'Built-in is for daily administration' inverts the intent - it exists for moments named accounts cannot serve; making it the daily driver renders every other control decorative. A silent protocol-level reversion is not how the stack behaves: local versus directory authentication is a configuration choice per login path, and account use does not imply stack failure. Exam caveat: where policy keeps the built-in account alive for recovery, pair it with alerting on each use. Operational check: produce a report of built-in logins since cutover, identify the human behind each, issue their named accounts, and alert on future use.