how to audit stale access quarterly
Audits stale access (unused permissions, dormant accounts) every quarter. Covers detection queries, the review process, and cleanup. Use quarterly alongside the least-privilege review. Not for privileged admin audits.
TL;DR
Each quarter, pull accounts with no sign-in for 90+ days and permissions unused for 90+ days, send the lists to the owners/managers, and disable or remove what is confirmed stale. Stale access is the quiet half of least privilege; the review is the cleanup crew.
The error
(Recurring task; no error.)Steps
- Pull dormant accounts: Entra sign-in logs or AD lastLogonTimestamp for 90+ days inactive. Expected: list. Exclude service accounts and break-glass first.
- Pull unused permissions: app assignments and group memberships with no usage evidence (where the platform reports it). Expected: list. Focus on sensitive systems first.
- Send each list to the relevant manager or owner with a simple keep/remove choice and a deadline. Expected: sent. Make the default action "disable" for non-responses per policy.
- Disable (not delete) dormant accounts; remove confirmed-stale permissions. Expected: cleaned. Disable is reversible; delete is not.
- After 30 days with no issue, delete or further process the disabled accounts per retention policy. Expected: finalized. Document everything for the auditors.
When to use
- Quarterly stale-access cleanup
- Pre-audit hygiene
When not to use
- Active access reviews (different question: should they have it at all)
- Incident response
Compatibility
- Entra ID sign-in logs, AD lastLogonTimestamp; any ITSM for workflow
Variants
Parental/medical leave
Exclude known long-leave accounts from the dormant list; coordinate with HR.
Service accounts
Review separately with the owning team; inactivity may be normal.
Why it happens
People go on leave, change roles, and leave; their access stays. Attackers love dormant accounts because nobody notices them being used.
Edge cases
- lastLogonTimestamp replicates slowly (up to 14 days); use it for 90-day windows, not precise timing.
- Announce the process so a disabled account is a ticket, not a surprise.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_nOC5NivomhP3SV8yuHEbRg