All baseline controls
Identityhigh priority

Dormant accounts are disabled

Enabled identities beyond the inactivity window. Part of the standard Alignr Baseline library for proactive technical alignment.

Join Waitlist for Early Access
WHAT THIS CONTROL CHECKS

Enabled identities beyond the inactivity window

An account with no sign-in for longer than the configured window should be disabled, not left enabled and unattended — the classic shape of an incomplete offboarding or a forgotten test account.

Interpret the result in context

A missing sign-in timestamp is not proof of inactivity. Non-interactive service identities, leave and emergency accounts require review before an account is disabled.

YOUR STANDARD

Configure the expectation.

Use this baseline as a starting point. You can also build your own controls and standards from integration data, with client-specific requirements and documented exceptions.

Dormant after (days)

90Default · permitted range 1–365

How long an account may go without an interactive sign-in before it should have been disabled.

FROM FINDING TO ACTION

Review. Remediate. Verify.

Use one-click remediation where the integration and action support it, or the evidence to guide the technician’s next step.

  1. 01

    Compare the last interactive sign-in with the configured window.

  2. 02

    Confirm ownership and business use, including service dependencies.

  3. 03

    Disable the account where appropriate, then refresh the evidence and record the decision.

A completed action is only part of the record. Refresh the supporting evidence to establish whether the finding has cleared.

Make your baseline part of every client review.

Connect checks, findings and remediation to the same client record.

Join Waitlist for Early Access