More Info:

There should not be any inactive users

Risk Level

High

Address

Security

Compliance Standards

CISGCP

Triage and Remediation

Remediation

To remediate inactive users in Azure Active Directory (Azure AD) using the Azure console, follow these steps:

  1. Sign in to the Azure portal (portal.azure.com) using your Azure AD administrator account.

  2. In the left-hand menu, click on “Azure Active Directory” to open the Azure AD dashboard.

  3. In the Azure AD dashboard, click on “Users” to view the list of users in your directory.

  4. Sort the users by the “Last sign-in” column to identify the inactive users. Users with no sign-in activity will have a blank or old date in this column.

  5. Select the inactive users you want to remediate by clicking on their names or using the checkboxes beside their names.

  6. Once the users are selected, click on the “Delete” button at the top of the user list.

  7. In the confirmation dialog, review the selected users and click on “Delete” to remove them from Azure AD.

  8. After the users are deleted, you may want to review any associated resources or permissions they had and update or remove them accordingly.

  9. Additionally, consider enabling Azure AD Premium’s “Azure AD Identity Protection” feature to proactively detect and remediate risky sign-in activities.

By following these steps, you can remediate inactive users in Azure AD using the Azure console.