Hello @Helen Chaytor
I'll take your questions in turn:
1. You can't apply MFA to this account as it is used non-interactively by the SIS service to connect to the servers and workstations on your internal network, and since it's non-interactive, there's no way to present any MFA prompt or accept a response.
2. I'm not quite sure what you mean by "token life". The account you need is one that is internal to your network, and is typically one in Active Directory, so it can be configured by your organisation with any restrictions that are considered suitable.
3. The use of this account, which is active only on your on-premise network, cannot be monitored from within Hornbill. This account is not used to access Hornbill and is not a Hornbill account in any way. For example, if someone logged on to a on-premise server using this account, no Hornbill system would have any visibility of that action. You could configure account logon auditing within your environment, but that is not an ITOM or Hornbill function.
Graham