Pro User
Timespan
explore our new search
​
Microsoft 365: Find Inactive Accounts
Microsoft 365 Admin Center
Oct 11, 2026 1:19 PM

Microsoft 365: Find Inactive Accounts

by HubSite 365 about Nick Ross [MVP] (T-Minus365)

Find and remove dormant accounts in Microsoft Three Sixty Five and Entra ID using Entra admin center and access reviews

Key insights

  • Dormant account: an identity that no longer signs in but still has access to data and services.
    Check the signInActivity.lastSignInDateTime value in Microsoft Entra ID to see the last interactive sign-in.
  • Risks: dormant accounts create easy attack paths and can expose mail, files, and admin roles.
    They also cause wasted subscription costs and messy audit trails.
  • How to find them: use the Entra admin center for quick filtering and use the Microsoft Graph API for tenant-wide lists.
    Example query: GET https://graph.microsoft.com/v1.0/users?$select=displayName,userPrincipalName,signInActivity
  • Review threshold: start with a 45-day review window and adjust per role or contract type.
    Don’t delete automatically after 90 days; identify expected exceptions like break-glass, service, and shared accounts.
  • Cleanup and automation: use dynamic groups and Entra ID access reviews to classify and remove or retain accounts safely.
    Reclaim unused licenses after validation to cut costs.
  • Multi-tenant monitoring: for MSPs, use centralized tools or Microsoft 365 Lighthouse to track dormant users and unused licenses across clients.
    Combine automated detection with periodic manual checks for edge cases.

Video overview

Nick Ross [MVP] (T-Minus365) published a practical YouTube video that walks administrators through finding and handling inactive Microsoft 365 accounts. In the presentation he defines what a dormant account is, outlines real-world attack paths that exploit them, and demonstrates tools inside the Microsoft Entra admin center to locate and manage these identities. Moreover, he shows how service providers can scale this work across many client tenants without manual checks. Overall, the video aims to reduce security exposure and wasted license spend through a repeatable process.

For context, the video includes clear chapters that cover definition, attack scenarios, discovery steps, cleanup actions, automation, and a multi-tenant monitoring demonstration. Consequently, IT teams can use the recording as both a how-to guide and a checklist for a governance review. Importantly, Ross emphasizes that not every dormant account should be deleted, and he offers a decision framework to avoid mistakes. He also previews practical automation such as dynamic groups and access reviews.

Why dormant accounts matter

Dormant accounts often remain enabled long after they are needed, which creates easy attack paths for intruders. For example, former employee accounts, stale partner or MSP accounts, forgotten service credentials, and guest identities can all be exploited if an attacker gains access. Therefore, discovering and classifying these accounts reduces risk and improves audit clarity. In addition, identifying inactive users helps organizations reclaim unused Microsoft 365 licenses and cut costs.

Ross explains that sign-in activity provides the primary signal for inactivity, while also warning that sign-in absence does not always equal unused access. For instance, background processes, delegated services, or mailbox access may continue without interactive sign-ins. As a result, cleanup decisions require careful cross-checking of mailboxes, Teams ownership, SharePoint files, and other workload traces. Thus, a measured approach helps reduce the chance of removing an account that still holds business value.

How to find inactive users

The video highlights two main discovery methods: the Microsoft Entra admin center for small to medium environments and the Microsoft Graph for larger or automated reviews. Ross points to the signInActivity data — specifically the lastSignInDateTime attribute — as the most reliable interactive sign-in indicator. Using the Entra UI makes it simple to view last sign-in columns and filter users, while Graph queries allow administrators to export and analyze activity across hundreds or thousands of accounts. Consequently, teams can generate a tenant-wide inventory faster than checking each account manually.

He also mentions Microsoft 365 Lighthouse as a built-in option for managed service providers that need a consolidated view across clients, though he demonstrates the same principles at scale with third-party tools. Importantly, Ross urges admins to avoid relying on a single metric: an empty or old signInActivity value should prompt further checks rather than immediate deletion. Therefore, combining sign-in data with workload-specific activity reduces false positives and protects business records.

Decision framework and tradeoffs

Ross recommends starting reviews with a pragmatic inactivity threshold, suggesting 45 days as a reasonable baseline for routine checks while noting that 90 days or longer may suit other environments. However, he warns that a single cutoff applied indiscriminately can lead to removing break-glass accounts, service accounts, or shared mailboxes that must remain enabled. Thus, the tradeoff is clear: shorter thresholds reduce exposure but increase the risk of disrupting legitimate services, whereas longer windows lower disruption risk but leave more potential attack surface.

To balance these factors, the video proposes a classification step before action, separating expected dormant accounts from those that require investigation. In addition, Ross shows how to use context — such as license assignment, mailbox contents, or ownership tags — to inform decisions. Consequently, organizations can make safer choices and document their actions to support audits and recovery if needed.

Ongoing cleanup and MSP considerations

For continuous governance, Ross demonstrates automation with dynamic groups and access reviews to keep dormant accounts under control without constant manual effort. These features let teams periodically re-evaluate membership and remove or disable accounts after human approval, which reduces the risk of accidental deletion. Moreover, he addresses the business challenge of cutting wasted licensing costs by identifying unused seats and reclaiming them with policy-driven actions.

Finally, Ross outlines options for managed-service providers to monitor dormant users across multiple tenants, showing how centralized tools can surface issues quickly and at scale. While third-party solutions can accelerate visibility, they require careful configuration and trust models to avoid creating new security liabilities. In sum, the video offers a practical, balanced approach to detecting, classifying, and cleaning dormant Microsoft 365 accounts while recognizing the operational tradeoffs and governance challenges involved.

Microsoft 365 Admin Center - Microsoft 365: Find Inactive Accounts

Keywords

inactive Microsoft 365 accounts, find inactive Office 365 users, Azure AD inactive users, identify inactive M365 accounts, remove dormant Microsoft 365 accounts, list inactive Microsoft 365 users, Microsoft 365 inactive user report, cleanup inactive Office 365 accounts