Description:
Identifies accounts that have not had any activity for 30 days by looking at the Entra ID sign-in logs as well as the actual app usage of Outlook, SharePoint, OneDrive and Teams from the Microsoft App Usage Report.
Why:
Deleting or blocking accounts that haven't been used in the last 30 days, after checking with owners, helps prevent unauthorized use of inactive accounts. These accounts can be targets for attackers who are looking to find ways to access your data without being noticed.
Status detail shown in Augmentt: You have N accounts that have been inactive for 30 days
This check reports a count rather than a simple pass/fail. It is Configured when every in-scope item is compliant, Partially Configured when some are, and Not Configured when none are.
Scoring: Contributes up to 1 point to the Posture Recommendations score.
Category: Identity
Microsoft Licensing: Requires Premium (P1) licensing
Remediation in Augmentt: Guided remediation steps (Instructions tab)
Compliance Frameworks:
Essential Eight (Maturity Level 2) — 1648
Essential Eight (Maturity Level 3) — 1648
NIST CSF 2.0 — PR.AA-01
HIPAA Security Rule — 164.308(a)(3)(ii)(C)
CMMC Level 1 — AC.L1-b.1.i
CMMC Level 2 — AC.L2-3.1.1, IA.L2-3.5.6
Microsoft documentation:
