Find every privileged account — even the ones you forgot about
You can’t protect what you don’t know exists. Most organizations have far more privileged accounts than the spreadsheet says: domain admins created during long-forgotten projects, local administrators left on every server image, service accounts spun up by automation,root accounts on Linux hosts nobody’s logged into for years. Each is a blind spot — a credential nobody is rotating, monitoring, or auditing.
The alternative most teams default to is a tracking spreadsheet, a few one-off PowerShell scripts, and an annual review that’s out of date the day after it ends. Syteca Account Discovery replaces that with continuous, automated scanning across your Active Directory, Windows, and Linux estate — and onboards what it finds into the vault as managed secrets, even when you don’t currently know the account’s password. The existing credential is rotated during onboarding, so the moment an account enters the vault, only Syteca knows it.
- Build a complete, continuously-refreshed inventory of privileged accounts across AD, Windows, and Linux — without manual spreadsheets or one-off scripts.
- Onboard hundreds or thousands of accounts into PAM in a single pass, instead of adding each one by hand.
- Catch newly-created privileged accounts on a schedule, so nothing stays unmanaged for long.
- Identify orphaned, stale, or unauthorized privileged accounts during access reviews.
- Meet the “discover and protect all privileged accounts” expectation in PCI DSS, NIST 800-53, ISO 27001, and SOC 2 audits.
Discovery rule types
You discover accounts by creating and running rules of three types:View and edit rules
Open Account Discovery
Read the rule status
Edit a rule

The Rules tab on the Account Discovery page.
Add and run a rule
Start a new rule
Set the General options
- Active Directory Discovery — AD users in the Domain Admins or Enterprise Admins group.
- Computer Discovery — Windows local accounts with Administrator permissions or GPO-granted privileges (for example,
SeTcbPrivilege,SeBackupPrivilege). - Linux Discovery — Linux accounts; choose All Accounts (privileged, service, application) or Privileged Accounts (manually created non-daemon accounts and
root), and optionally include accounts with Public SSH keys.
Set the scope
- Linux Discovery: enter an IP range for scanning (for example
10.100.10.10-10.100.10.40) or a semicolon-separated list, and choose the Account type. - Active Directory / Computer Discovery: select the Source domain (from added LDAP targets) and optionally restrict to specific OUs or groups.
Select the account to scan with
- AD / Computer Discovery: one Active Directory or Windows account secret.
- Linux Discovery: one or more Unix account (SSH) secrets with private SSH keys.
Select the account to scan with
- AD / Computer Discovery: one Active Directory or Windows account secret.
- Linux Discovery: one or more Unix account (SSH) secrets with private SSH keys.
Schedule (optional)
Set notifications (optional)
Save and run
When a rule runs
Each run creates an Account Discovery task on the Tasks List tab of the System Health page, where you can cancel it (while Queued or In Progress), download its log (when Finished or Failed), or remove it. When the task finishes, the notification email is sent.Why a discovery task might fail
Why a discovery task might fail
- The scan secret’s most recent password/SSH key rotation failed.
- The credentials stored in the scan secret are invalid.
- The scan secret is checked out by another user.
- The account in the secret lacks the required domain admin privileges (Domain Admins / Enterprise Admins).
- The associated LDAP target no longer exists.
View and manage discovered accounts
On the Privileged Accounts tab (with Active Directory, Windows Local, and Linux sub-tabs), discovered accounts appear in a grid showing Login, User Name, Type (Linux only), Status, Computer (Windows/Linux), Discovered time, Last Onboarding Time, Secret Name, and Discovery Rule. Account statuses:
Discovered accounts on the Privileged Accounts tab.
Onboard discovered accounts
Select accounts to onboard
Set the secret properties
$DOMAIN\$LOGIN, $COMPUTER\$LOGIN) and optionally Change the destination folder (one you have Owner/Editor permission for).Choose the password settings
- Use automatically generated password (forced for Bulk Action).
- Use current password (not rotated during onboarding; not available for Linux service accounts).
- Specify new password manually (rotated during onboarding).
- Import Private Key (Linux accounts with public SSH keys).
Choose the rotation account
Configure the rest and onboard
Track progress