You can limit service account damage by isolating identities, enforcing least privilege, using short-lived credentials, monitoring, and blocking lateral spread.
Lorem ipsum dolor sit amet, consectetur elit, sed do eiusmod tempor incididunt ut labore.