Orphaned Account Checker

Cloud platform

Cloud console users, access keys and service identities; the credential report carries last used and last rotated per key. The checker reads the system column to group the accounts; the findings come from the other columns, the same way for every system.

What the export usually carries

A cloud platform credential report usually carries one line per user with console password enabled, password last used, password last changed, MFA active, and per access key: active, last rotated and last used. Keys are dated per key, not per user, so a user with two keys has two dates; password last used covers console sign-in only and says nothing about key use. Roles and workload identities often appear in a different listing with their own last used field.

What the checker most often raises here

Account types found here

The system names in your export are matched to these classes by the browser dictionary; product names are never shown on these pages. A system the dictionary does not place reads as other, and every finding still works.