Orphaned Account Checker

User access review template for Excel

A user access review works per account, not per system: who owns it, when it was last used, when its credential last changed, when it was last reviewed. Download the columns as a CSV and open it in Excel, fill it in from your exports, one line per account, then paste it back and the checker reads it. The export you already pull works too: a column the checker cannot find is reported as not recorded.

Download the template CSVSee the specimen run

Columns the checker reads

header names are matched loosely
ColumnWhat goes in itNeeded
Accountthe login, user principal name, key id or client id; masked codes workrequired
Typeperson, contractor, shared login, service account, API key, OAuth client, AI agent, automation, break glass, built-in, administrator, test, device, mailboxstrongly advised
Systemdirectory, cloud platform, database, CI/CD, a SaaS application, and so onadvised
Ownerone person, by name or code, or a teamrequired
Accountable personwhen the owner is a team, the one person accountable for the accountwhen a team owns it
Enabledyes or nostrongly advised
Last useda date, "never", or a day count such as 120 daysstrongly advised
Last changedthe date the password, key or secret was last changed, or "never"strongly advised
Createda date; read when last used says neveradvised
Privilegedyes or no, or the administrative roleadvised
Interactive loginyes or no: can a person sign in to itfor service accounts
MFAyes or nofor user accounts
Stored invault, code, config file, script, a document, or unknownfor service accounts and keys
Last reviewedthe date of the last access review of this accountstrongly advised
Approvalthe ticket or request referenceadvised
Notesanything else, as a short label; never a passwordoptional

A first line for the periods

regimes: ISO/IEC 27001, SOC 2, PCI DSS | dormant after: 90 days | rotate within: 365 days | review every: 12 months | as at: 2026-09-28

The first line is optional. The ticks on the page do the same; a staff list goes in the second box, or under a line reading --- staff list --- at the end of the same paste.

The four rows in the CSV

invented
AccountTypeOwnerLast changedLast reviewed
E2001personE20012026-09-20none recorded
svc-invoice-exportservice accountE20022026-09-27vault
agent-support-draftsAI agentnone named2026-09-27vault
frontdeskshared loginFacilities team2026-09-26none recorded

Fill it in, paste it back: each line comes back with its owner and their status, the day counts, the findings and the clauses, and the review sheet export adds blank reviewer, decision, date and ticket columns for the review itself.