Skip to content

Security1 publisher2 min readPublished

Defender for Identity scores dormant AD accounts against a 90-day logon threshold

Microsoft's accounts posture assessment lists every Active Directory user account with no logon in the past 90 days and refreshes the score every 24 hours. Service accounts are excluded from that list.

The Watch · Security desk

Illustration accompanying Defender for Identity scores dormant AD accounts against a 90-day logon threshold

What happened

  • Defender for Identity's accounts posture assessment flags any Active Directory user account as stale when it has not logged in at all during the past 90 days.
  • Microsoft's implementation guidance is to disable an account confirmed unused, delete it after a monitoring period according to retention policy, and remove accounts belonging to former employees.
  • Assessments update in near real time, but the scores and statuses that a posture dashboard shows are only recalculated every 24 hours.
  • A second recommendation lists accounts holding a privileged Entra ID role such as Global Administrator that also belong to a highly privileged Active Directory group such as Domain Admins.
  • A third lists Active Directory service accounts that are members of privileged groups, counting nested membership as well as direct.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure A dormant service account that is not in a privileged group lands in neither list, so the credentials with the longest lifetimes and the least interactive monitoring can sit outside the scoring entirely.
  • constraint Anyone reporting cleanup progress inside a day has to cite the impacted entity queue, because the score will not have moved yet.
  • decision Hybrid admin design becomes a documented choice for the identity owner: cut privilege on one side, or keep the pair and write down the justification with PIM or just-in-time access around it.

Microsoft's stated reason for scoring dormancy is that stale accounts are potential targets that are not actively monitored. A compromised stale account can be used to gain unauthorized access, move laterally in the environment, or escalate privileges [3]. For the hybrid pairing, the documentation says compromise of a single account with privileges on both sides might allow lateral movement, privilege escalation, and access to sensitive resources across cloud and on-premises environments [9].

Microsoft says service accounts often hold long-lived credentials, are used by applications, scripts or automated tasks, and are not tied to a specific user. Malicious activity under them can go unnoticed and delay detection and response [12]. The remediation it gives for those is narrow. Remove the account from the privileged group if elevated access is not required, or disable it if it is unused [13].

The dual-privilege report is scoped tightly. Guests, external identities and accounts not synchronized to Microsoft Entra ID are excluded, and only enabled accounts holding privileges in both directories are included [8]. Microsoft's remediation is to reduce privileges in one or both environments. Dual privileges should be retained only where necessary, with documented justification. It also says to split cloud and on-premises roles across separate accounts or use just-in-time access, and to put Privileged Identity Management approval workflows around what stays [10]. Its worked example is a user who is Global Administrator in Entra ID and Domain Admin in Active Directory: one of the two roles should be reduced or replaced with delegated administrative access [10].

The cadence matters for anyone using this as a control. Assessments update in near real time and the list of impacted entities moves within a few minutes of a change, but a status can still take time before it is marked Completed [6]. The threshold itself is fixed at no logon at all in 90 days, so an account last used 89 days ago is not on the list [16]. The documentation does not say how much each recommendation contributes to the score [17].

What to watch

  • Whether Microsoft extends the stale accounts list to cover service accounts, which are excluded from it today.
  • Whether the assessments publish per-recommendation score weights, which would make the posture number auditable rather than indicative.
  • Whether the 90-day dormancy threshold becomes configurable to match tenant retention policy.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories