Collaboration and mail
Mailboxes, room accounts and chat integrations. The checker reads the system column to group the accounts; the findings come from the other columns, the same way for every system.
What the export usually carries
A mail and collaboration export usually carries mailboxes, shared mailboxes, room and equipment accounts, and last activity. Shared and resource mailboxes often have sign-in blocked by design, so read their enabled column with that in mind; the delegate or manager field is where an owner is usually recorded.
What the checker most often raises here
- 3. No owner named, or a team named with no accountable person: The account is not a personal account and its owner cell is blank, "unknown", "TBC" or similar, or names a team, a department or a mailbox with no accountable person named beside it. When an accountable, approver or owner of record column names a person for the team, this finding does not fire; with a staff list, that person is checked like any owner (left is finding 2, not in the list is a question).
- 4. Dormant for more than the threshold: The account is enabled or its status is not recorded, it is not a break-glass account, and its last used date is more than the threshold you set (default 90 days) before the as-at date. With CIS Controls ticked, more than 45 days (CIS 5.3) also fires; with PCI DSS ticked, more than 90 days (8.2.6) fires on user accounts. An account never used fires when its created date is older than the same periods. Exactly the period never fires.
- 2. Owner has left, or owner not recognised: The account is not a personal account, its owner names a person, and the staff list is pasted: when the list says that person has left it is a gap; when the owner is not in the list at all it is a question ("owner not recognised, confirm"). Without a staff list this finding never fires.
- 9. Shared or generic login used by people: The account type is a shared or generic login, from the type column or assumed from the name.
Account types found here
- Built-in or vendor default accounta system account
- Break-glass or emergency accounta user account
- AI agent credentiala system account
- Automation or bot (scheduled jobs, RPA)a system account
- Service accounta system account
- API key or access keya system account
- OAuth client or app registrationa system account
- Device or workload identitya system account
- Mailbox or resource accounta user account
- Test accounta user account
- Shared or generic logina user account
- Administrator or privileged person accounta user account
- Contractor or guesta user account
- Person (employee)a user account
The system names in your export are matched to these classes by the browser dictionary; product names are never shown on these pages. A system the dictionary does not place reads as other, and every finding still works.