← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

Snowflake to deprecate password-based authentication for service accounts by October 2026

🔄 Updated 1h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Snowflake is deprecating password authentication for service accounts.
  • Legacy service accounts will migrate to a new SERVICE type.
  • The final phase of deprecation is August-October 2026.
  • This change addresses credential compromise risks.

Snowflake Ends Password-Based Authentication for Service Accounts

Snowflake is implementing a phased deprecation of password-based authentication for its service accounts. This initiative will transition all legacy service users to a new 'SERVICE' type, which inherently blocks password authentication. The final phase of this rollout is scheduled for August to October 2026, by which time all covered Snowflake accounts must migrate off password authentication for their legacy service accounts.

Background on the Change

This security enhancement follows a significant incident where valid, often years-old, customer credentials were used to access over 165 Snowflake customer organizations, leading to the theft of billions of records. The incident highlighted common identity failures, including credentials remaining valid after exposure, lack of multi-factor authentication, and absent network restrictions. The deprecation directly addresses these vulnerabilities by forcing customers to adopt more secure authentication methods.

Phased Rollout Details

The deprecation process has been rolled out in three phases. The first phase, from September 2025 to January 2026, required human users to present a second factor. The second phase, from May to July 2026, mandated that all newly created non-human users be of the 'SERVICE' type, which cannot use a password. The upcoming third phase, from August to October 2026, targets the oldest legacy service accounts, requiring them to migrate from password authentication.

Implications for Customers

While the technical migration to block password authentication is straightforward, the primary challenge for customers lies in identifying the purpose of each service account, assigning ownership, and determining necessary access levels. These older accounts are more likely to have leaked or unrotated credentials, changed owners, and undocumented dependencies, making the transition a complex management task.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~10 min · 8 stories · Aug 26

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Snowflake is deprecating password-based authentication for legacy service accounts, migrating them to a new SERVICE type that does not store passwords. This change, prompted by a security incident involving compromised credentials, aims to improve security by eliminating long-standing identity vulnerabilities.