TL;DR: Unosecur reports that dormant Office 365 users remain a hidden access path because inactive accounts often retain MFA gaps, legacy protocol access and privilege drift. Periodic clean-up assumes identities stay visible long enough to review, but stale accounts turn governance into after-the-fact archaeology.
At a glance
What this is: This is an analysis of why dormant Office 365 accounts become attacker entry points, with the key finding that stale users often retain access, privileges and weak controls long after they stop being used.
Why it matters: IAM and NHI teams need to treat dormant accounts as active attack surface because unused identities can still carry tokens, group memberships and access paths that expand blast radius.
By the numbers:
- 34% of internal accounts inactive, but still enabled.
- 88% of companies admit they still have stale accounts in 2025.
👉 Read Unosecur's analysis of dormant Office 365 users and attacker access paths
Context
Dormant Office 365 users are accounts that are no longer actively used but still exist, often with the same permissions, token access and directory memberships they had when they were last active. That creates a governance gap because identity systems usually optimise for login events, not for silent abandonment.
In cloud collaboration environments, unused accounts can persist across mail, files and chat, which means they remain reachable even when the human behind them has moved on. The article argues that periodic audits are too slow for that model, and that continuous discovery plus closed-loop remediation is now the practical baseline for identity governance.
This is an NHI-adjacent identity hygiene problem as much as a workforce IAM problem because the risk comes from lifecycle failure: identities outlive their business purpose and retain access after accountability has faded.
Key questions
Q: What breaks when Office 365 dormant accounts are left in place?
A: Dormant accounts keep valid access paths alive even after ownership has been lost, which means a mailbox, guest identity, or service principal can still be abused later. The failure is lifecycle drift: offboarding, role cleanup, and token revocation do not happen in time, so the tenant retains usable access long after the business need has ended.
Q: Why do stale accounts increase breach impact in cloud collaboration environments?
A: They increase impact because the identity may still reach mail, files and chat while also carrying inherited permissions into connected systems. That means one forgotten account can expose data, support lateral movement and create a trusted beachhead that blends into normal tenant activity. The longer the account survives, the more useful it becomes to an attacker.
Q: How should teams decide whether a dormant account can stay enabled?
A: Teams should decide by validating business need, legal hold status, contractor return plans and break-glass ownership before keeping anything active. If none of those apply, the account should be disabled and its tokens, licences and memberships removed as part of the same lifecycle action. A dormant identity should be an exception, not a default.
Q: What is the difference between periodic audits and continuous discovery for stale identities?
A: Periodic audits look for stale accounts at fixed intervals, which means the control is always behind the risk. Continuous discovery watches for inactivity and residual access as it emerges, so remediation can happen while the identity still matters. In practice, continuous discovery turns identity cleanup from a report into an operating process.
Technical breakdown
Why stale Office 365 identities become low-noise entry points
Dormant users are attractive because they blend into normal tenant activity while still carrying valid credentials, group memberships and application entitlements. Attackers prefer them because they often lack current monitoring, may still authenticate through legacy protocols such as IMAP, POP or SMTP, and can be used without triggering the same alerts as an actively managed account. The technical issue is not just inactivity, but the mismatch between account lifecycle state and access persistence.
Practical implication: treat inactivity thresholds as a detection signal, not as a deprovisioning decision by themselves.
How privilege drift expands the blast radius of forgotten accounts
As accounts age, they accumulate nested group membership, shared links and sometimes elevated rights that no longer match the original job role. That is privilege drift, and it matters because an identity that looks dormant can still be the shortest path to mailbox content, OneDrive files and collaboration data. Once compromised, such accounts can also support lateral movement into on-premises systems where cloud identities are bridged to other enterprise controls.
Practical implication: recertify dormant accounts for both direct access and inherited permissions before deciding whether they can remain enabled.
Why closed-loop remediation matters more than manual cleanup
Manual scripts and quarterly review cycles do not scale when the tenant contains thousands of stale users. A usable remediation loop must first validate whether an identity is a legal hold, contractor return case or break-glass account, then disable the account, revoke refresh tokens, remove licences and strip group memberships in one sequence. Without that closed loop, identity cleanup creates evidence gaps and leaves residual access behind.
Practical implication: automate identity offboarding so the removal of access, tokens and entitlements happens together, with audit evidence captured at the same time.
Threat narrative
Attacker objective: The attacker wants a trusted identity that bypasses normal scrutiny and opens access to business data, collaboration systems and downstream enterprise paths.
- Entry begins with a dormant Office 365 user that still has valid authentication paths, group memberships or token-bearing sessions despite being unused.
- Credential access is easiest when the account still supports legacy protocols or weakly monitored sign-ins, allowing an attacker to impersonate a legitimate user.
- Escalation occurs through inherited permissions and privilege drift, which can expose mail, files, collaboration channels and connected internal systems.
- Impact follows when the attacker uses the dormant account as a low-noise beachhead for ransomware, data harvesting or further lateral movement.
Breaches seen in the wild
- Dropbox Sign breach 2024: A compromised back-end service account gave attackers Dropbox Sign customer data, including API keys, OAuth tokens and MFA information.
- SonicWall SSL VPN account compromises 2025: Attackers used valid credentials to log in to more than 100 SonicWall SSL VPN accounts across 16 environments in October 2025.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Dormant identities create lifecycle debt, not just directory clutter. The problem is not that the account exists, but that its permissions, tokens and memberships continue to act as though the user still has a business purpose. In IAM terms, the organisation has let identity state drift away from operational reality, and that is what attackers exploit.
Closed-loop deprovisioning is the control boundary that matters. Periodic review models assume a dormant account will still be visible, reachable and easy to remove when the audit cycle arrives. In practice, stale identities can sit in a tenant for months, long enough to accumulate reach across mail, files and groups. Practitioners should treat offboarding completeness as the real measure of control maturity.
Hidden access paths are a governance failure across human and machine-adjacent identity estates. Even when the subject is a human user, the mechanics are similar to NHI sprawl: an identity remains enabled after its business role has ended, and access outlives accountability. That makes lifecycle ownership, not just authentication policy, the decisive control surface for modern identity programmes.
Continuous discovery is the named concept this article makes unavoidable. Identity programmes need a mechanism that finds stale access as a live condition, not as a quarterly reporting problem. The practical conclusion is that discovery, validation and revocation must be linked, or dormant users will continue to masquerade as low-risk inventory.
Legacy protocol tolerance is an overlooked access-lifecycle blind spot. Dormant Office 365 users often survive because older authentication paths remain enabled even after modern controls are added elsewhere. That creates an access path that looks obsolete but is still perfectly usable, so teams need to treat protocol retirement as part of identity cleanup rather than a separate infrastructure task.
From our research library:
- Only 5.7% of organisations have full visibility into their service accounts, according to the Ultimate Guide to NHIs.
- Across one million observed logins, 1 in 4 were password-based rather than SSO, 2 in 5 were not protected by MFA and 1 in 5 used a weak, breached or reused password.
- Read next: NHI Lifecycle Management Guide
What this signals
Dormant account cleanup is increasingly an identity lifecycle problem rather than a simple hygiene task. When users leave behind active tokens, memberships or legacy protocol access, the tenant keeps producing hidden entry points until discovery and revocation are tied together.
Continuous discovery: the useful control is not periodic reporting but live detection of identities that have outlived their purpose. That shift matters because an inactive Office 365 user can still be reachable long after the business thinks the account is dead.
For practitioners
- Implement continuous dormant-account discovery Track internal users with no interactive sign-in or token activity for your chosen threshold, then review them continuously instead of waiting for quarterly audits.
- Revoke access in one offboarding workflow When an account is confirmed stale, disable it, revoke refresh tokens, remove licences and strip group memberships in the same workflow so residual access does not linger.
- Validate dormant accounts before removal Cross-check stale identities against HR, managers, legal hold requirements and break-glass ownership before deprovisioning anything that might still be needed.
- Retire legacy authentication paths Identify dormant accounts that can still use legacy protocols and phase out those protocols so stale identities cannot bypass modern access controls.
- Record evidence for identity cleanup Log every disablement, token revocation and membership change so auditors can see that identity lifecycle control was executed, not just planned.
Key takeaways
- Dormant Office 365 accounts remain dangerous because inactivity does not automatically remove tokens, group memberships or legacy access paths.
- The evidence in the article points to a large stale-account problem, including 34% inactive internal accounts in one assessment and 88% of companies still admitting to stale accounts in 2025.
- The practical answer is continuous discovery paired with closed-loop remediation so disablement, token revocation and entitlement removal happen together.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | Dormant users persist because offboarding never fully removed access and tokens. |
| NHI-07 — Long-Lived Secrets | Dormant accounts often survive on old authentication paths and residual credentials. | |
| NHI-05 — Overprivileged NHI | The article highlights privilege drift in identities that remain enabled too long. | |
| Recommendation — Map stale-user cleanup to NHI-01 and remove access, tokens and memberships together. Review dormant identities for long-lived credentials and retire any access path that remains valid. Recertify inherited permissions on dormant identities and strip any rights no longer needed. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | Dormant account cleanup depends on governing who still has entitlements and why. |
| Recommendation — Apply PR.AA-05 to remove stale entitlements and enforce current authorisation state. | ||
| CIS Controls v8 | CIS-5 — Account Management | Account management controls directly address stale, unused identities left enabled. |
| Recommendation — Use CIS-5 to inventory inactive accounts and disable those no longer required. | ||
| MITRE ATT&CK | TA0006;TA0008 — Credential Access; Lateral Movement | The article describes attackers using dormant identities as a beachhead for movement. |
| Recommendation — Map dormant-account abuse to TA0006 and TA0008 to prioritise detection on trusted identities. | ||
Key terms
- Dormant account: A dormant account is an identity that has not been used within a defined period but still retains active access. The risk is not only wasted licensing. Dormant access often becomes stale standing privilege, which makes offboarding, certification, and incident response harder to execute cleanly.
- Privilege Drift: Privilege drift is the gradual gap between the permissions an identity was meant to have and the permissions it actually retains. In AI agent environments, drift grows quickly because roles are reused, tasks change, and lifecycle reviews often lag behind deployment velocity.
- Closed-Loop Remediation: A governance process that does not stop at finding risk. It removes or reduces access, confirms the change in the source systems, and keeps evidence that the risky condition stayed fixed. For NHIs, this is the difference between inventory and actual risk reduction.
- Alternate Authentication Path: An alternate authentication path is any credential or trust relationship that can be used after the primary token is removed. Security teams miss these paths when they treat revocation as the end of the incident instead of checking for newly planted keys, app grants, or delegated sessions.
What's in the full article
Unosecur's full blog covers the operational detail this post intentionally leaves for the source:
- A practical cleanup workflow for dormant Office 365 users, including validation steps before disablement
- How to revoke refresh tokens, licences and group memberships without leaving residual access behind
- The connector workflow the vendor describes for automating account closure at tenant scale
- Examples of the audit evidence teams need when deprovisioning stale identities
Deepen your knowledge
NHI governance, identity lifecycle management, and secrets management are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 23, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org