matthew_pahls
Lookout
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Content to Moderator
‎Aug 08, 2022
12:50 PM
Service Accounts
At what point do you consider an account dormant and disable it? What are you using to determine if an account is not being used?
Reply
1 Solution
Accepted Solutions
mkscarberry
Lookout
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Content to Moderator
‎Aug 08, 2022
02:33 PM
In AAD and AD, we check for last logged in. If >90 days, we disable the account. If after 90 days no one claims it, we move the account into OU=Disabled. After 366 days in OU=Disabled, we purge it.
Reply
2 Replies
mkscarberry
Lookout
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Content to Moderator
‎Aug 08, 2022
02:33 PM
In AAD and AD, we check for last logged in. If >90 days, we disable the account. If after 90 days no one claims it, we move the account into OU=Disabled. After 366 days in OU=Disabled, we purge it.
Reply
aparker81
Deckhand III
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Content to Moderator
‎Jun 21, 2023
10:46 AM
Agreed. We take the same approach.
