Resources | Blog

June 2, 2025

Why dormant Office 365 users are an attacker’s dream; and how to clean them up

Table of contents

Here is the bird’s eye view of the issue in hand.

One in three internal users in a typical enterprise tenant is a “ghost.” Those idle accounts rarely have MFA, often inherit admin-level rights, and make perfect launch pads for ransomware crews. The fix is continuous discovery + automatic remediation; ideally with the entire workflow baked into your identity-security platform.

Unosecur has launched a feature that can help you out with it. Read about it here.

How big is the ghost-user problem?

If the host of O365 Suite can accumulate that much identity debris, every other large tenant almost certainly does too.

Why do dormant Office 365 users pile up so quickly?

Why attackers love orphaned identities

  1. They’re invisible. Until yours is a real-time continuous identity and access monitoring system, no one would notice a dormant sales intern suddenly logging in from another country at 3 a.m.
  2. They pre-date MFA. Stale accounts often slip through password-only legacy protocols (IMAP/POP, SMTP).
  3. Privilege drift is real. The longer an account sits around, the more nested groups and shared links it accumulates.
  4. Great for lateral movement. Once inside, adversaries harvest mail, OneDrive data, and Teams chats, then pivot on-prem.

Put simply, forgotten users give bad actors a low-noise, high-impact beachhead.

The three-step clean-up strategy

Continuous discovery, not annual audits
Flag any human or service account with no interactive sign-in or token activity for ≥ 90 days (or whatever threshold your auditors prefer).

Validate before you obliterate
Cross-check with HR and line managers. Is the identity tied to a legal hold, returning contractor, or break-glass admin?

Automate the full remediation loop
Disable the account, revoke refresh tokens, strip licences and group memberships, and log every action for SOX/GDPR/HIPAA evidence.

Manual scripts can get you part-way there, but the sheer volume in a Fortune 500 tenant makes automation essential.

How Unosecur’s Office 365 Connector does the heavy lifting

Security teams go from “We’ll run an audit script next quarter” to “We eliminated three dormant admins before lunch.”

Dormant Office 365 accounts aren’t trivial housekeeping; they’re a standing invitation for ransomware crews and insider threats. Moving from periodic clean-ups to real-time, closed-loop remediation eliminates that risk and keeps regulators satisfied.

Ready to see how many ghosts are haunting your tenant? Book a 15-minute demo of the Unosecur O365 Connector and watch them disappear.

Ready To Secure Your Identities?

Blue cardholder with translucent card showing icons and the text 'unosecur'.
FAQs

Everything you Need to Know

Inactive accounts often lack Multi-Factor Authentication (MFA) and monitoring, providing attackers a low-resistance entry point for lateral movement and privilege escalation. - Identify inactive users - Disable unused accounts - Enforce MFA requirements - Audit access logs

Threat actors use compromised credentials to bypass Identity and Access Management (IAM) controls, mimicking legitimate users to execute the MITRE ATT\&CK lateral movement phase. - Monitor login attempts - Track unusual behavior - Detect privilege changes - Log session activity

Yes, these accounts violate strict access control requirements within NIST (National Institute of Standards and Technology) frameworks and regulatory standards like GDPR or HIPAA. - Map access rights - Perform regular reviews - Document removal process - Secure sensitive data

Organizations should integrate HR systems with IT directory services to automate the account deprovisioning process through robust identity lifecycle management. - Automate account deletion - Sync HR databases - Revoke all permissions - Disable active sessions

Eliminating unnecessary identities minimizes the number of potential entry points available for automated vulnerability scanning and sophisticated campaigns like Midnight Blizzard. - Reduce entry points - Close security gaps - Simplify audit trails - Hardening cloud environments