
Nick Ross [MVP] (T-Minus365) published a practical YouTube video that walks administrators through finding and handling inactive Microsoft 365 accounts. In the presentation he defines what a dormant account is, outlines real-world attack paths that exploit them, and demonstrates tools inside the Microsoft Entra admin center to locate and manage these identities. Moreover, he shows how service providers can scale this work across many client tenants without manual checks. Overall, the video aims to reduce security exposure and wasted license spend through a repeatable process.
For context, the video includes clear chapters that cover definition, attack scenarios, discovery steps, cleanup actions, automation, and a multi-tenant monitoring demonstration. Consequently, IT teams can use the recording as both a how-to guide and a checklist for a governance review. Importantly, Ross emphasizes that not every dormant account should be deleted, and he offers a decision framework to avoid mistakes. He also previews practical automation such as dynamic groups and access reviews.
Dormant accounts often remain enabled long after they are needed, which creates easy attack paths for intruders. For example, former employee accounts, stale partner or MSP accounts, forgotten service credentials, and guest identities can all be exploited if an attacker gains access. Therefore, discovering and classifying these accounts reduces risk and improves audit clarity. In addition, identifying inactive users helps organizations reclaim unused Microsoft 365 licenses and cut costs.
Ross explains that sign-in activity provides the primary signal for inactivity, while also warning that sign-in absence does not always equal unused access. For instance, background processes, delegated services, or mailbox access may continue without interactive sign-ins. As a result, cleanup decisions require careful cross-checking of mailboxes, Teams ownership, SharePoint files, and other workload traces. Thus, a measured approach helps reduce the chance of removing an account that still holds business value.
The video highlights two main discovery methods: the Microsoft Entra admin center for small to medium environments and the Microsoft Graph for larger or automated reviews. Ross points to the signInActivity data — specifically the lastSignInDateTime attribute — as the most reliable interactive sign-in indicator. Using the Entra UI makes it simple to view last sign-in columns and filter users, while Graph queries allow administrators to export and analyze activity across hundreds or thousands of accounts. Consequently, teams can generate a tenant-wide inventory faster than checking each account manually.
He also mentions Microsoft 365 Lighthouse as a built-in option for managed service providers that need a consolidated view across clients, though he demonstrates the same principles at scale with third-party tools. Importantly, Ross urges admins to avoid relying on a single metric: an empty or old signInActivity value should prompt further checks rather than immediate deletion. Therefore, combining sign-in data with workload-specific activity reduces false positives and protects business records.
Ross recommends starting reviews with a pragmatic inactivity threshold, suggesting 45 days as a reasonable baseline for routine checks while noting that 90 days or longer may suit other environments. However, he warns that a single cutoff applied indiscriminately can lead to removing break-glass accounts, service accounts, or shared mailboxes that must remain enabled. Thus, the tradeoff is clear: shorter thresholds reduce exposure but increase the risk of disrupting legitimate services, whereas longer windows lower disruption risk but leave more potential attack surface.
To balance these factors, the video proposes a classification step before action, separating expected dormant accounts from those that require investigation. In addition, Ross shows how to use context — such as license assignment, mailbox contents, or ownership tags — to inform decisions. Consequently, organizations can make safer choices and document their actions to support audits and recovery if needed.
For continuous governance, Ross demonstrates automation with dynamic groups and access reviews to keep dormant accounts under control without constant manual effort. These features let teams periodically re-evaluate membership and remove or disable accounts after human approval, which reduces the risk of accidental deletion. Moreover, he addresses the business challenge of cutting wasted licensing costs by identifying unused seats and reclaiming them with policy-driven actions.
Finally, Ross outlines options for managed-service providers to monitor dormant users across multiple tenants, showing how centralized tools can surface issues quickly and at scale. While third-party solutions can accelerate visibility, they require careful configuration and trust models to avoid creating new security liabilities. In sum, the video offers a practical, balanced approach to detecting, classifying, and cleaning dormant Microsoft 365 accounts while recognizing the operational tradeoffs and governance challenges involved.
inactive Microsoft 365 accounts, find inactive Office 365 users, Azure AD inactive users, identify inactive M365 accounts, remove dormant Microsoft 365 accounts, list inactive Microsoft 365 users, Microsoft 365 inactive user report, cleanup inactive Office 365 accounts