Active Directory & Entra ID Account Cleanup Checklist Template
Directories only ever grow. Contractors from a finished project, laptops rebuilt under new names, groups made for a migration that ended years ago: each one still exists, and each account is a sign-in nobody is watching.
This free Active Directory cleanup checklist gives system administrators, identity teams and MSPs a quarterly routine for removing stale objects from on-premises Active Directory and Microsoft Entra ID. It covers inactive users and computers, accounts left disabled for years, empty and ownerless groups, service accounts, privileged group membership, guests, stale Entra devices and app registrations with old secrets. It explains which timestamp to trust for each object, and it never deletes in one step: candidates are disabled, held for a grace period, approved by a named person and only then removed. Cloud-only tenants skip the on-premises tasks automatically, and every run ends with a removal log.
Stale Object Cleanup vs Access Review: Two Different Questions
A cleanup asks whether an object should still exist. An access review asks whether a person should keep a particular permission. Both matter, but they need different people. Cleanup is evidence-led: the directory’s own timestamps show which accounts, computers, guests and devices have gone quiet, and IT can act on most of them without a meeting. An access review needs managers and application owners to confirm each entitlement, which is slower and belongs in its own process.
Running both at once usually means neither gets finished. Clear out the dead objects first and the access review has fewer rows to argue about.
Stale object cleanup
Does this object still need to exist?
Evidence: last sign-in, logon timestamp, device activity and a named owner.
Decided by: IT, with a named approver before anything is deleted.
Output: objects disabled, then deleted, and a removal log.
Access review
Should this person keep this access?
Evidence: role, team and the manager’s knowledge of the job.
Decided by: managers and application owners.
Output: each entitlement confirmed or removed.
The staged approach is the same in both directories: find, disable, wait, approve, delete. Deletion is the only step that can go badly wrong, so it comes last, after a grace period and a sign-off. For people leaving the organisation, the right moment to act is the leaving date itself, through the Employee Offboarding Checklist. This checklist catches whatever offboarding missed.
What the Active Directory Cleanup Checklist Covers
Seven phases run every quarter. For cloud-only tenants, Phase 2 and the other on-premises tasks stay hidden.
Phase 1
Phase 1: Scope, Baseline & Safeguards
The first answer decides whether the on-premises tasks appear. The deletion approver is named here too.
Record the directory setup and the scope of this run — hybrid with on-premises AD synced to Entra ID, or cloud-only; domains, OUs and tenants included
Confirm the AD Recycle Bin is enabled before anything is deleted — it needs the Windows Server 2008 R2 forest functional level, and enabling it cannot be undone
Agree the inactivity threshold and the exclusion list — Microsoft suggests 90 to 180 days suits many organisations; exclude emergency access accounts and people on long leave
Export a baseline of users, computers, groups, guests and devices — the before-picture for the report and for any restore
Tell the service desk when the cleanup runs — so an “account disabled” call is recognised and routed straight away
Phase 2
Phase 2: On-Premises Users & Computers
Appears only when there is an on-premises Active Directory.
Find enabled users whose lastLogonTimestamp is older than the threshold — the value runs 9 to 14 days behind by design, so short thresholds give false positives
Find computer accounts inactive beyond the threshold — check them against the asset register first; a laptop in a drawer is still an asset
List accounts already disabled and the date each was disabled — accounts left disabled for years still carry their group memberships
Review accounts whose passwords never expire — each needs a named owner and a reason, or it joins the disable list
Check the default Users and Computers containers and empty OUs — the containers cannot take their own group policy, so objects there miss OU-level settings
Phase 3
Phase 3: Entra ID Users, Guests & Devices
Task 2 appears only for hybrid directories.
Export signInActivity for every user — lastSuccessfulSignInDateTime needs Entra ID P1 or P2; a blank means no sign-in on record
Handle synced accounts in AD, not in Entra ID — delete a synced user only in the cloud and the next sync can bring it back
Review guests by last sign-in and sponsor — ask the inviting team whether each is still needed
Find stale devices by their activity timestamp — it updates only about every 14 days, so Microsoft advises against treating anything under 21 days as stale
Back up BitLocker recovery keys and retire devices in Intune or your MDM first — deleting the Entra device deletes its keys with it
Keep Autopilot and other system-managed devices off the deletion list — once deleted, they cannot be reprovisioned
Phase 4
Phase 4: Groups, Service Accounts & Apps
Task 3 appears only when there is an on-premises Active Directory.
List empty groups and groups with no owner — ask the team named in the description, then assign an owner or delete
Check every service account has an owner, a purpose and a review date — CIS Controls v8.1 Safeguard 5.5 asks for this review at least quarterly
Move suitable services to group Managed Service Accounts — Windows then manages the password, so nobody rotates it by hand
Review app registrations for expired and long-lived client secrets — Microsoft caps secrets at 24 months, recommends under 12, and prefers certificates in production
Remove app registrations with no owner and no recent sign-ins — confirm with the business first; a yearly job can look idle for months
Phase 5
Phase 5: Privileged Access
Task 1 appears only when there is an on-premises Active Directory.
List members of Domain Admins, Enterprise Admins and Administrators — Microsoft’s guidance is that membership is needed only for build and disaster recovery work
Count Global Administrator assignments — Microsoft recommends fewer than five, plus two cloud-only emergency access accounts
Check privileged Entra roles are held by cloud-only accounts — Microsoft advises against using synced on-premises accounts for them
Confirm every admin account belongs to a current, named person — shared admin logins and leavers’ admin accounts go first
Test that the emergency access accounts still sign in — and that every past use of them was recorded
Phase 6
Phase 6: Disable, Wait, Approve & Delete
Task 4 is an approval. The named approver signs off the deletion list, and nothing is deleted until they do.
Disable the agreed candidates and record the date and reason — stamp the description so anyone who finds the account knows why
Remove licences from disabled accounts — a disabled account can still hold a paid licence
Hold for the grace period and deal with anyone who objects — 30 days is a common default; re-enable with a ticket and add to the exclusions
Approve the deletion list — the named approver checks it against the grace-period log and records the decision
Delete the approved objects — AD can restore them for the deleted object lifetime, usually 180 days; Entra keeps deleted users for 30
Phase 7
Phase 7: Record & Report
Complete the removal log — object, type, last activity, disabled date, deleted date and approver
Compare object counts with the baseline — users, computers, groups, guests and devices, run on run
Send each pattern back to the process that caused it — leavers found here mean offboarding missed a step
Set the date of the next run — CIS Controls v8.1 Safeguard 5.1 asks for accounts to be validated at least quarterly
lastSignInDateTime includes failed attempts; the successful sign-in date needs Entra ID P1 or P2
Entra ID guests
Last sign-in, or the creation date if they never signed in
As for users
New guests look inactive until they first sign in
Entra ID devices
approximateLastSignInDateTime (the activity timestamp)
Replaced only when the stored value is more than 14 days old, give or take 5
Some active devices have a blank timestamp; BitLocker keys live on the device object
Service accounts and app registrations
Owner and purpose, not activity
Not applicable
A quarterly or yearly job looks idle most of the time
Know how long each mistake stays reversible before you delete anything. With the AD Recycle Bin enabled, a deleted object keeps its attributes and group memberships for the deleted object lifetime, which follows the tombstone lifetime of 180 days in any forest created with Windows Server 2003 SP1 or later. Microsoft Entra ID keeps a deleted user restorable for 30 days, after which permanent deletion starts and cannot be stopped. A deleted Entra device cannot be restored at all, and its BitLocker recovery keys go with it.
Why Run Directory Cleanup in CheckFlow?
1
One template for hybrid and cloud-only
One dropdown on the first task drives conditional logic that hides every on-premises task for cloud-only tenants. A quarterly recurring schedule starts each run and assigns it to the directory owner, with due dates that leave room for the grace period.
2
Nothing is deleted without a name against it
The deletion approver is picked in a members field at the start, and the approval task holds the checklist until they decide. The activity trail records who disabled each batch, who approved the list and who deleted it, and when.
3
A removal log built as you go
Candidates, disables and deletions go into tables inside their tasks, and exports attach as files. Tags separate domains or client tenants, and webhooks or the REST API can pass the finished log to your ticketing system.
Most stale user accounts are leavers the exit process missed. CheckFlow’s IT offboarding checklist software covers the day someone leaves, and the IT offboarding security guide lists the accounts, tokens and keys that most often survive a departure. Every leaver this cleanup finds is a reason to tighten that process.
How do you find inactive users in Active Directory?
+
Filter enabled users on lastLogonTimestamp, which replicates to every domain controller. In PowerShell, Search-ADAccount with the AccountInactive switch does this, as does Get-ADUser with the LastLogonDate property, which is a readable conversion of the same value. In a hybrid setup, check Entra ID sign-in activity as well: someone who works only in cloud apps may rarely authenticate against a domain controller, depending on how sign-in is configured.
What is the difference between lastLogon and lastLogonTimestamp?
+
lastLogon is updated only on the domain controller that handled the logon and is never replicated, so finding the true latest value means asking every domain controller. lastLogonTimestamp is replicated, but to limit replication traffic it is only rewritten when the stored value is older than the ms-DS-Logon-Time-Sync-Interval, 14 days by default, minus a random 0 to 5 days. It was designed for finding stale accounts, not for tracking logons in real time.
What inactivity threshold should you use?
+
There is no single right number. CIS Controls v8.1 Safeguard 5.3 asks for dormant accounts to be disabled or deleted after 45 days of inactivity where supported, while Microsoft suggests 90 to 180 days is a reasonable window for many organisations using Entra ID. Pick a threshold, write it into the checklist with its exclusions, and apply it the same way every quarter. Stay well above the 14-day timestamp delay either way.
How do you find stale devices in Microsoft Entra ID?
+
Use the activity timestamp, shown in the Activity column of the devices list and as ApproximateLastSignInDateTime in Microsoft Graph PowerShell. Microsoft’s guidance is to disable stale devices for a grace period before deleting them, to retire managed devices in Intune or your MDM first, to back up BitLocker keys, and to leave Autopilot devices alone. Hybrid-joined devices are disabled or deleted in on-premises AD and synchronised up.
Can you recover a deleted Active Directory account?
+
Yes, if the AD Recycle Bin was enabled before the deletion and the deleted object lifetime has not passed. The object comes back with its attributes and group memberships, from Active Directory Administrative Center or with Restore-ADObject. Without the Recycle Bin you are left with an authoritative restore from backup. A deleted Entra ID user can be restored for 30 days.
Is CheckFlow free for this template?
+
14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.
Close the Accounts Nobody Is Watching
Free trial — no credit card required.
Do you like cookies? 🍪 We use cookies to ensure you get the best experience on our website. Learn more