This IoE cannot work without a Microsoft Entra ID P1 or P2 license due to data availability restrictions by Microsoft.
A never used user is a user account created in Entra ID that never successfully authenticated for a certain number of days (90 days by default, customizable) since its creation.
They increase the attack surface for various reasons, such as:
Also, consider the related IoE "Dormant User" which identifies all previously active users who have since become inactive.
Note:
lastSuccessfulSignInDateTime
property within the signInActivity
property of User objects. Its advantage lies in reporting only successful sign-ins to avoid disruption arising from failed attempts, unlike the property lastSignInDateTime
. The lastSuccessfulSignInDateTime
property became available in December 2023.signInActivity
resource type, you need a Microsoft Entra ID P1 or P2 license for each tenant. Otherwise, this IoE cannot detect never used users and therefore skips the entire analysis.Tenable recommends that you regularly review and disable or delete never used users. After identifying them, take the following actions:
Name: Never Used User
Codename: NEVER-USED-USER
Severity: Low