TechNewsReel
Live

Snowflake to Ban Service Account Passwords by October 2026

The data cloud giant is forcing a migration to passwordless authentication to curb credential theft and identity debt.

TechNewsReel Newsroom · August 26, 2026

Snowflake is implementing a three-phase authentication rollout to eliminate password-based logins for legacy service accounts. The move aims to secure non-human identities by forcing a transition to passwordless methods by October 2026.

Under the new mandate, existing 'LEGACY_SERVICE' users are being migrated to a new 'SERVICE' user type, which does not support passwords. The rollout is structured in three distinct stages. Phase 1, running from September 2025 to January 2026, requires multi-factor authentication (MFA) for human users within Snowsight. Phase 2, spanning May to July 2026, mandates that all new non-human users be created as the passwordless 'SERVICE' type. The final stage, Phase 3, occurs between August and October 2026, when Snowflake will enforce the total migration of all remaining legacy service accounts off password authentication.

The Security Driver

This policy shift follows a series of high-profile data thefts, including the UNC5537 campaign. In those attacks, threat actors utilized valid, leaked credentials for service accounts that lacked both MFA and network restrictions. According to BleepingComputer, some of these stolen credentials remained valid for more than three years after being harvested by infostealer malware, highlighting a critical gap in how organizations manage non-human identities.

The Risk of Identity Debt

For many enterprises, the primary challenge is not the technical implementation but the existence of "identity debt." Service accounts are frequently created for specific automated tasks but often lack proper documentation, assigned owners, or rotation policies. This creates a significant operational risk; if undocumented accounts are disabled during the Phase 3 enforcement, critical business processes could break without warning.

Ido Shlomo, Co-founder and CTO of Token Security, noted the danger of reactive management, stating, "An inventory assembled in October, because a deadline forced it, is not governance."

Migration Paths

To facilitate the transition, Snowflake has provided four passwordless alternatives for organizations to adopt: workload identity federation, external OAuth, key-pair authentication, and programmatic access tokens. Each method removes the reliance on static passwords, thereby reducing the risk of credential stuffing and theft.

What's Next

Organizations must now begin the process of auditing their non-human identities to identify which legacy accounts are still active and which dependencies they support. The window for migration is open, but the hard deadline arrives in late 2026. Companies that fail to map their service account dependencies before the Phase 3 window may face unexpected outages as password-based access is systematically disabled.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.