Orphaned Account Checker

Cloud identity provider

The cloud directory most sign-ins pass through; its export carries last sign-in, MFA and guest accounts. The checker reads the system column to group the accounts; the findings come from the other columns, the same way for every system.

What the export usually carries

A cloud identity provider export usually carries the user, user type (member or guest), enabled, last sign-in, created and, in a separate report, MFA registration. Last sign-in commonly records interactive sign-ins by people; sign-ins by applications, service principals and managed identities are often logged separately and may not appear in that field, so an application reading as never signed in is a question, not a gap.

What the checker most often raises here

Account types found here

The system names in your export are matched to these classes by the browser dictionary; product names are never shown on these pages. A system the dictionary does not place reads as other, and every finding still works.