## TL;DR
Pull 90 days of successful sign-ins from the System Log, build the distinct list of users who appeared, and subtract it from the full user directory. The remainder is your dormant set. Then segment it before acting: service accounts, people on leave, and contractors between engagements look dormant but are legitimate, while true orphans should be disabled or deprovisioned.

## Steps
1. In Okta Admin go to Reports > System Log. Filter event type user.session.start over the last 90 days. Expected: a stream of successful sign-in events.
2. Export the sign-in events and build the distinct list of user logins that appear. Expected: a deduplicated list of active users.
3. Export the full user directory and subtract the active list. Expected: the difference is the dormant set, accounts with zero sign-ins in 90 days.
4. Segment the dormant list: service accounts, on-leave employees, contractors between engagements, and true orphans each need different handling. Expected: every account has a category, not just a name.
5. Act per category: disable or deprovision orphans, confirm service accounts are documented with an owner, and set a reminder to re-check next quarter. Expected: the dormant count drops and the remainder is justified in writing.

## Use this when
- Running a quarterly access review or recertification campaign
- Auditors ask for evidence of stale-account cleanup
- Investigating whether old contractor or vendor accounts are still live

## Not for this skill when
- You need real-time alerting on suspicious logins (this is a periodic review, not monitoring)
- The account in question signed in recently (use the System Log directly for that)
- You only care about admin accounts (scope the directory export to admins instead)

## Compatibility
- Okta Identity Engine, any workforce tenant with System Log retention covering 90 days
- Large tenants: use the System Log API rather than the UI export

## Variants
### Doing this repeatedly: automate it
Schedule the report monthly and alert account owners when an account crosses 90 days, instead of running it by hand each quarter.
### Auditors want the evidence trail
Keep the export, the category decisions, and the disable actions together as the review artifact.

## Why it happens
Dormant accounts are the quietest attack surface: nobody watches them, so attackers love them. A 90-day window is the common audit threshold because it catches real orphans without flagging people on normal leave.

## Edge cases
- API-only service accounts never trigger user.session.start. Track their last credential use separately.
- Users on parental or medical leave look dormant. Confirm with HR before disabling anything.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_ktrBbdnZBX5c8teMXybxZw
