Automatically disable to report inactive account in Azure / Entra ID?

EnterpriseArchitect 4,866 Reputation points
2024-02-19T10:41:53.83+00:00

I'm curious if there's a built-in feature in Microsoft Entra ID or Azure AD that can automatically disable or remove users whose SignInActivity logs and LastSuccessfulSignInDate are empty.

I need to disable them if no activity has been logged in the last 30 days since their creation.

How can I accomplish this without using a sophisticated scripting process as my tenant is using Entra ID Premium P2 feature. https://learn.microsoft.com/en-us/graph/api/resources/signinactivity?view=graph-rest-1.0&WT.mc_id=M365-MVP-9501%3Fview%3Dgraph-rest-beta

Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
683 questions
Microsoft Entra External ID
Microsoft Entra External ID
A modern identity solution for securing access to customer, citizen and partner-facing apps and services. It is the converged platform of Azure AD External Identities B2B and B2C. Replaces Azure Active Directory External Identities.
2,675 questions
Microsoft Entra Private Access
Microsoft Entra Private Access
Microsoft Entra Private Access provides secure and deep identity-aware, Zero Trust network access to all private apps and resources.
43 questions
Microsoft Entra
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,870 questions
{count} votes

Accepted answer
  1. Domooney-MSFT 2,476 Reputation points Microsoft Employee
    2024-02-19T11:11:45.31+00:00

    Hi EnterpriseArchitect,

    Thank you for posting your query on Microsoft Q&A!

    We do have a feature within Entra ID Governance where you can use "Access Reviews" to automatically generate a report of inactive users and carry out some actions on them, see a blog post here on how to set it up - https://techcommunity.microsoft.com/t5/microsoft-entra-blog/step-by-step-guide-to-identify-inactive-users-by-using-microsoft/ba-p/3944705

    This would be the only out of the box solution that does not require automation / scripting.

    Do let me know if you have any further queries, I would be happy to help!

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    Kind Regards, Donal

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful