Snowflake forces passwordless service accounts, exposing identity management hurdles

Snowflake is eliminating password authentication for legacy service accounts, requiring migration to passwordless methods. The harder task for organizations is discovering what each account is used for, assigning ownership, and determining necessary access levels. The move follows a major credential-based breach that affected over 165 Snowflake customers.
Snowflake’s phased deprecation of legacy service accounts began with human users requiring multi-factor authentication in late 2025, then new nonhuman accounts were forced into the passwordless SERVICE type by mid-2026. The final phase, running through October 2026, targets the oldest remaining accounts, which often have undocumented dependencies and stale credentials. The breach that triggered this shift involved attackers using valid but unrotated passwords, affecting over 165 customers and exposing billions of records, including telecom call logs. Snowflake’s own system logs can identify which accounts still authenticate via password, but ownership and usage details must be reconstructed manually from tickets or institutional memory.
This mandate could reshape how organizations govern non-human identities, forcing them to move beyond reactive credential rotation toward continuous inventory and ownership tracking. Companies that fail to map dependencies may face sudden service outages when passwords are blocked, while those that succeed may reduce their exposure to credential-based attacks. The broader effect may be a cultural shift in cybersecurity, where service accounts receive the same scrutiny as human users, potentially lowering the risk of large-scale data theft across cloud platforms.