## TL;DR
Each quarter, pull accounts with no sign-in for 90+ days and permissions unused for 90+ days, send the lists to the owners/managers, and disable or remove what is confirmed stale. Stale access is the quiet half of least privilege; the review is the cleanup crew.

## The error
```text
(Recurring task; no error.)
```

## Steps
1. Pull dormant accounts: Entra sign-in logs or AD lastLogonTimestamp for 90+ days inactive. Expected: list. Exclude service accounts and break-glass first.
2. Pull unused permissions: app assignments and group memberships with no usage evidence (where the platform reports it). Expected: list. Focus on sensitive systems first.
3. Send each list to the relevant manager or owner with a simple keep/remove choice and a deadline. Expected: sent. Make the default action "disable" for non-responses per policy.
4. Disable (not delete) dormant accounts; remove confirmed-stale permissions. Expected: cleaned. Disable is reversible; delete is not.
5. After 30 days with no issue, delete or further process the disabled accounts per retention policy. Expected: finalized. Document everything for the auditors.

## When to use
- Quarterly stale-access cleanup
- Pre-audit hygiene

## When not to use
- Active access reviews (different question: should they have it at all)
- Incident response

## Compatibility
- Entra ID sign-in logs, AD lastLogonTimestamp; any ITSM for workflow

## Variants
### Parental/medical leave
Exclude known long-leave accounts from the dormant list; coordinate with HR.
### Service accounts
Review separately with the owning team; inactivity may be normal.

## Why it happens
People go on leave, change roles, and leave; their access stays. Attackers love dormant accounts because nobody notices them being used.

## Edge cases
- lastLogonTimestamp replicates slowly (up to 14 days); use it for 90-day windows, not precise timing.
- Announce the process so a disabled account is a ticket, not a surprise.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_nOC5NivomhP3SV8yuHEbRg
