Orphaned Account Checker

Directory service

The on-premises directory: people, service accounts and built-in accounts side by side, with last logon and password last set. The checker reads the system column to group the accounts; the findings come from the other columns, the same way for every system.

What the export usually carries

A directory export usually carries the account name, enabled or disabled, a last logon value, password last set, when created, member of and a description. The last logon value most exports carry is replicated between servers on a schedule and can lag the real last logon by up to about two weeks, so a date near the threshold is a question; a service account that authenticates through the directory updates it, a key or certificate used elsewhere does not.

What the checker most often raises here

Account types found here

The system names in your export are matched to these classes by the browser dictionary; product names are never shown on these pages. A system the dictionary does not place reads as other, and every finding still works.