Description:

Identifies accounts that have not had any activity for 30 days by looking at the Entra ID sign-in logs as well as the actual app usage of Outlook, SharePoint, OneDrive and Teams from the Microsoft App Usage Report.

Why:

Deleting or blocking accounts that haven't been used in the last 30 days, after checking with owners, helps prevent unauthorized use of inactive accounts. These accounts can be targets for attackers who are looking to find ways to access your data without being noticed.

Status detail shown in Augmentt: You have N accounts that have been inactive for 30 days

This check reports a count rather than a simple pass/fail. It is Configured when every in-scope item is compliant, Partially Configured when some are, and Not Configured when none are.

Scoring: Contributes up to 1 point to the Posture Recommendations score.

Category: Identity

Microsoft Licensing: Requires Premium (P1) licensing

Remediation in Augmentt: Guided remediation steps (Instructions tab)

Compliance Frameworks:

  • Essential Eight (Maturity Level 2) — 1648

  • Essential Eight (Maturity Level 3) — 1648

  • NIST CSF 2.0 — PR.AA-01

  • HIPAA Security Rule — 164.308(a)(3)(ii)(C)

  • CMMC Level 1 — AC.L1-b.1.i

  • CMMC Level 2 — AC.L2-3.1.1, IA.L2-3.5.6

Microsoft documentation: