{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/investigate-active-directory-accounts-with-no-logon-in-90-days/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/investigate-active-directory-accounts-with-no-logon-in-90-days/",
        "slug": "investigate-active-directory-accounts-with-no-logon-in-90-days",
        "url": "https://update.dsesecurity.com/updates/investigate-active-directory-accounts-with-no-logon-in-90-days/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/investigate-active-directory-accounts-with-no-logon-in-90-days.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/investigate-active-directory-accounts-with-no-logon-in-90-days/"
        },
        "title": "Investigate Active Directory accounts with no logon in 90 days",
        "summary": "Use Accounts security posture assessments to review this narrow operational decision without extending the source beyond its stated scope.",
        "format": {
            "slug": "explainer",
            "name": "Explainer"
        },
        "priority": {
            "slug": "advisory",
            "name": "Advisory"
        },
        "featured": false,
        "image": {
            "theme": "identity-cloud",
            "label": "Identity & cloud",
            "alt": "Governed cloud identity system with connected service and lifecycle nodes.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            },
            {
                "slug": "microsoft-365-identity",
                "name": "Microsoft 365 & Identity",
                "url": "https://update.dsesecurity.com/topic/microsoft-365-identity/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-08-27T12:13:03+00:00",
        "modified_at": "2026-08-27T13:04:09+00:00",
        "reviewed_on": "2026-08-26",
        "reading_minutes": 3,
        "word_count": 507,
        "potentially_affected": "Teams, systems, services, or facilities within the stated scope of Accounts security posture assessments",
        "dse_recommendation": "Compare the observed state with the cited official source, document applicability and exceptions, and test any approved change with rollback safeguards.",
        "primary_source": {
            "name": "Accounts security posture assessments",
            "url": "https://learn.microsoft.com/en-us/defender-for-identity/security-posture-assessments/accounts",
            "published_on": "2026-08-18",
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<p>Frame this document as a source-led configuration and assurance check: Investigate Active Directory accounts with no logon in 90 days. Only the official source and traced locations below supply facts. Confirm applicability before acting.</p>\n<h2>Source fact:</h2>\n<p>The official <a href=\"https://learn.microsoft.com/en-us/defender-for-identity/security-posture-assessments/accounts\" target=\"_blank\" rel=\"noopener noreferrer\">Accounts security posture assessments</a> from Microsoft supports the following bounded statements:</p>\n<ul>\n<li>The stale-account recommendation lists Active Directory user accounts that have not logged in during the previous 90 days. The research record locates this support at <strong>Stale account recommendation description</strong>.</li>\n<li>The page says impacted entities can update within minutes after remediation while assessment scores and statuses update every 24 hours. The research record locates this support at <strong>Opening update-cadence note</strong>.</li>\n</ul>\n<p>These statements are the factual basis for this document. Do not extend them into a broader assurance. Review directory identities, posture assessments, exposed relationships, recommendations, ownership, remediation, and exception tracking only where the source and recorded environment align.</p>\n<h2>What the source does not establish</h2>\n<p>A 90-day threshold is a detection criterion, not proof that an account lacks a valid owner, seasonal purpose, or recovery dependency. The citation is not a substitute for observed state, authorization, compliance evidence, or dependency health. Examine Active Directory data quality, Windows DNS, sensor coverage, time, synchronization, cloud processing, and accountable identity owners before translating the source into an operational decision.</p>\n<h2>Applicability questions</h2>\n<ul>\n<li>For source statement 1 at <strong>Stale account recommendation description</strong>, which observable configuration, record, or test can confirm applicability here?</li>\n<li>For source statement 2 at <strong>Opening update-cadence note</strong>, which observable configuration, record, or test can confirm applicability here?</li>\n<li>Which deployed instance of directory identities, posture assessments, exposed relationships, recommendations, ownership, remediation, and exception tracking will be compared with the source, and why that instance?</li>\n<li>How will the review distinguish a source mismatch from a failure in Active Directory data quality, Windows DNS, sensor coverage, time, synchronization, cloud processing, and accountable identity owners?</li>\n<li>Who approves the conclusion, exception, test window, and rollback threshold?</li>\n</ul>\n<h2>DSE recommendation:</h2>\n<p>DSE recommends using the cited source as the evidence anchor for this decision. Start with applicability, then compare the observed state with the cited source. Record the source location, examined part of directory identities, posture assessments, exposed relationships, recommendations, ownership, remediation, and exception tracking, observed and expected states, owner, and reason for deviation.</p>\n<p>Do not move from citation to production in one step. Pilot the decision where practical, observe agreed signals, retain a reversal point, and verify Active Directory data quality, Windows DNS, sensor coverage, time, synchronization, cloud processing, and accountable identity owners. Handle credentials, keys, recovery data, and personal information through approved secure channels.</p>\n<h2>Verification and evidence</h2>\n<p>Keep the source locations <strong>Stale account recommendation description</strong>; <strong>Opening update-cadence note</strong> adjacent to the sanitized artifacts used for comparison. Prefer affected-entity lists, directory attributes, relationship paths, assessment timestamps, remediation tests, and accepted exceptions, with enough identity and timing data for an independent recheck.</p>\n<p>Retain the starting state, authorization, execution record, outcome, deviation, and final state as one review package. Move disruptive checks to an approved test path. Reopen the decision when versions, design, dependencies, ownership, or official guidance changes.</p>\n<h2>Official references</h2>\n<ul>\n<li><a href=\"https://learn.microsoft.com/en-us/defender-for-identity/security-posture-assessments/accounts\" target=\"_blank\" rel=\"noopener noreferrer\">Accounts security posture assessments</a> — Microsoft</li>\n</ul>",
        "content_text": "Frame this document as a source-led configuration and assurance check: Investigate Active Directory accounts with no logon in 90 days. Only the official source and traced locations below supply facts. Confirm applicability before acting.\nSource fact:\nThe official Accounts security posture assessments from Microsoft supports the following bounded statements:\n\nThe stale-account recommendation lists Active Directory user accounts that have not logged in during the previous 90 days. The research record locates this support at Stale account recommendation description.\nThe page says impacted entities can update within minutes after remediation while assessment scores and statuses update every 24 hours. The research record locates this support at Opening update-cadence note.\n\nThese statements are the factual basis for this document. Do not extend them into a broader assurance. Review directory identities, posture assessments, exposed relationships, recommendations, ownership, remediation, and exception tracking only where the source and recorded environment align.\nWhat the source does not establish\nA 90-day threshold is a detection criterion, not proof that an account lacks a valid owner, seasonal purpose, or recovery dependency. The citation is not a substitute for observed state, authorization, compliance evidence, or dependency health. Examine Active Directory data quality, Windows DNS, sensor coverage, time, synchronization, cloud processing, and accountable identity owners before translating the source into an operational decision.\nApplicability questions\n\nFor source statement 1 at Stale account recommendation description, which observable configuration, record, or test can confirm applicability here?\nFor source statement 2 at Opening update-cadence note, which observable configuration, record, or test can confirm applicability here?\nWhich deployed instance of directory identities, posture assessments, exposed relationships, recommendations, ownership, remediation, and exception tracking will be compared with the source, and why that instance?\nHow will the review distinguish a source mismatch from a failure in Active Directory data quality, Windows DNS, sensor coverage, time, synchronization, cloud processing, and accountable identity owners?\nWho approves the conclusion, exception, test window, and rollback threshold?\n\nDSE recommendation:\nDSE recommends using the cited source as the evidence anchor for this decision. Start with applicability, then compare the observed state with the cited source. Record the source location, examined part of directory identities, posture assessments, exposed relationships, recommendations, ownership, remediation, and exception tracking, observed and expected states, owner, and reason for deviation.\nDo not move from citation to production in one step. Pilot the decision where practical, observe agreed signals, retain a reversal point, and verify Active Directory data quality, Windows DNS, sensor coverage, time, synchronization, cloud processing, and accountable identity owners. Handle credentials, keys, recovery data, and personal information through approved secure channels.\nVerification and evidence\nKeep the source locations Stale account recommendation description; Opening update-cadence note adjacent to the sanitized artifacts used for comparison. Prefer affected-entity lists, directory attributes, relationship paths, assessment timestamps, remediation tests, and accepted exceptions, with enough identity and timing data for an independent recheck.\nRetain the starting state, authorization, execution record, outcome, deviation, and final state as one review package. Move disruptive checks to an approved test path. Reopen the decision when versions, design, dependencies, ownership, or official guidance changes.\nOfficial references\n\nAccounts security posture assessments — Microsoft",
        "content_markdown": "Frame this document as a source-led configuration and assurance check: Investigate Active Directory accounts with no logon in 90 days. Only the official source and traced locations below supply facts. Confirm applicability before acting.\n\n## Source fact:\n\nThe official [Accounts security posture assessments](https://learn.microsoft.com/en-us/defender-for-identity/security-posture-assessments/accounts) from Microsoft supports the following bounded statements:\n\n- The stale-account recommendation lists Active Directory user accounts that have not logged in during the previous 90 days. The research record locates this support at Stale account recommendation description.\n\n- The page says impacted entities can update within minutes after remediation while assessment scores and statuses update every 24 hours. The research record locates this support at Opening update-cadence note.\n\nThese statements are the factual basis for this document. Do not extend them into a broader assurance. Review directory identities, posture assessments, exposed relationships, recommendations, ownership, remediation, and exception tracking only where the source and recorded environment align.\n\n## What the source does not establish\n\nA 90-day threshold is a detection criterion, not proof that an account lacks a valid owner, seasonal purpose, or recovery dependency. The citation is not a substitute for observed state, authorization, compliance evidence, or dependency health. Examine Active Directory data quality, Windows DNS, sensor coverage, time, synchronization, cloud processing, and accountable identity owners before translating the source into an operational decision.\n\n## Applicability questions\n\n- For source statement 1 at Stale account recommendation description, which observable configuration, record, or test can confirm applicability here?\n\n- For source statement 2 at Opening update-cadence note, which observable configuration, record, or test can confirm applicability here?\n\n- Which deployed instance of directory identities, posture assessments, exposed relationships, recommendations, ownership, remediation, and exception tracking will be compared with the source, and why that instance?\n\n- How will the review distinguish a source mismatch from a failure in Active Directory data quality, Windows DNS, sensor coverage, time, synchronization, cloud processing, and accountable identity owners?\n\n- Who approves the conclusion, exception, test window, and rollback threshold?\n\n## DSE recommendation:\n\nDSE recommends using the cited source as the evidence anchor for this decision. Start with applicability, then compare the observed state with the cited source. Record the source location, examined part of directory identities, posture assessments, exposed relationships, recommendations, ownership, remediation, and exception tracking, observed and expected states, owner, and reason for deviation.\n\nDo not move from citation to production in one step. Pilot the decision where practical, observe agreed signals, retain a reversal point, and verify Active Directory data quality, Windows DNS, sensor coverage, time, synchronization, cloud processing, and accountable identity owners. Handle credentials, keys, recovery data, and personal information through approved secure channels.\n\n## Verification and evidence\n\nKeep the source locations Stale account recommendation description; Opening update-cadence note adjacent to the sanitized artifacts used for comparison. Prefer affected-entity lists, directory attributes, relationship paths, assessment timestamps, remediation tests, and accepted exceptions, with enough identity and timing data for an independent recheck.\n\nRetain the starting state, authorization, execution record, outcome, deviation, and final state as one review package. Move disruptive checks to an approved test path. Reopen the decision when versions, design, dependencies, ownership, or official guidance changes.\n\n## Official references\n\n- [Accounts security posture assessments](https://learn.microsoft.com/en-us/defender-for-identity/security-posture-assessments/accounts) — Microsoft"
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/investigate-active-directory-accounts-with-no-logon-in-90-days/",
                "url": "https://update.dsesecurity.com/updates/investigate-active-directory-accounts-with-no-logon-in-90-days/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-08-26"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/investigate-active-directory-accounts-with-no-logon-in-90-days/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Investigate Active Directory accounts with no logon in 90 days",
                        "item": "https://update.dsesecurity.com/updates/investigate-active-directory-accounts-with-no-logon-in-90-days/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/investigate-active-directory-accounts-with-no-logon-in-90-days/#article",
                "identifier": "https://update.dsesecurity.com/updates/investigate-active-directory-accounts-with-no-logon-in-90-days/",
                "url": "https://update.dsesecurity.com/updates/investigate-active-directory-accounts-with-no-logon-in-90-days/",
                "headline": "Investigate Active Directory accounts with no logon in 90 days",
                "description": "Use Accounts security posture assessments to review this narrow operational decision without extending the source beyond its stated scope.",
                "abstract": "Use Accounts security posture assessments to review this narrow operational decision without extending the source beyond its stated scope.",
                "articleBody": "Frame this document as a source-led configuration and assurance check: Investigate Active Directory accounts with no logon in 90 days. Only the official source and traced locations below supply facts. Confirm applicability before acting.\nSource fact:\nThe official Accounts security posture assessments from Microsoft supports the following bounded statements:\n\nThe stale-account recommendation lists Active Directory user accounts that have not logged in during the previous 90 days. The research record locates this support at Stale account recommendation description.\nThe page says impacted entities can update within minutes after remediation while assessment scores and statuses update every 24 hours. The research record locates this support at Opening update-cadence note.\n\nThese statements are the factual basis for this document. Do not extend them into a broader assurance. Review directory identities, posture assessments, exposed relationships, recommendations, ownership, remediation, and exception tracking only where the source and recorded environment align.\nWhat the source does not establish\nA 90-day threshold is a detection criterion, not proof that an account lacks a valid owner, seasonal purpose, or recovery dependency. The citation is not a substitute for observed state, authorization, compliance evidence, or dependency health. Examine Active Directory data quality, Windows DNS, sensor coverage, time, synchronization, cloud processing, and accountable identity owners before translating the source into an operational decision.\nApplicability questions\n\nFor source statement 1 at Stale account recommendation description, which observable configuration, record, or test can confirm applicability here?\nFor source statement 2 at Opening update-cadence note, which observable configuration, record, or test can confirm applicability here?\nWhich deployed instance of directory identities, posture assessments, exposed relationships, recommendations, ownership, remediation, and exception tracking will be compared with the source, and why that instance?\nHow will the review distinguish a source mismatch from a failure in Active Directory data quality, Windows DNS, sensor coverage, time, synchronization, cloud processing, and accountable identity owners?\nWho approves the conclusion, exception, test window, and rollback threshold?\n\nDSE recommendation:\nDSE recommends using the cited source as the evidence anchor for this decision. Start with applicability, then compare the observed state with the cited source. Record the source location, examined part of directory identities, posture assessments, exposed relationships, recommendations, ownership, remediation, and exception tracking, observed and expected states, owner, and reason for deviation.\nDo not move from citation to production in one step. Pilot the decision where practical, observe agreed signals, retain a reversal point, and verify Active Directory data quality, Windows DNS, sensor coverage, time, synchronization, cloud processing, and accountable identity owners. Handle credentials, keys, recovery data, and personal information through approved secure channels.\nVerification and evidence\nKeep the source locations Stale account recommendation description; Opening update-cadence note adjacent to the sanitized artifacts used for comparison. Prefer affected-entity lists, directory attributes, relationship paths, assessment timestamps, remediation tests, and accepted exceptions, with enough identity and timing data for an independent recheck.\nRetain the starting state, authorization, execution record, outcome, deviation, and final state as one review package. Move disruptive checks to an approved test path. Reopen the decision when versions, design, dependencies, ownership, or official guidance changes.\nOfficial references\n\nAccounts security posture assessments — Microsoft",
                "datePublished": "2026-08-27T12:13:03+00:00",
                "dateModified": "2026-08-27T13:04:09+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/investigate-active-directory-accounts-with-no-logon-in-90-days/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/investigate-active-directory-accounts-with-no-logon-in-90-days/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Investigate Active Directory accounts with no logon in 90 days"
                },
                "articleSection": [
                    "Cybersecurity",
                    "IT",
                    "Microsoft 365 & Identity"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Microsoft 365 & Identity",
                    "Explainer",
                    "Advisory priority"
                ],
                "genre": "Explainer",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Microsoft 365 & Identity",
                        "url": "https://update.dsesecurity.com/topic/microsoft-365-identity/"
                    }
                ],
                "wordCount": 507,
                "timeRequired": "PT3M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Accounts security posture assessments",
                    "url": "https://learn.microsoft.com/en-us/defender-for-identity/security-posture-assessments/accounts",
                    "datePublished": "2026-08-18"
                }
            }
        ]
    }
}