Ensuring shells are not given to system accounts upon login makes it more difficult for attackers to use system accounts.
Check
Verify SUSE system accounts do not have an interactive login shell with the following command:
Run the following command to list any system account (UID < 1000) that has an interactive shell, excluding authorized system utility accounts (root, sync, shutdown, halt):