Detect-Not-Active-AD-User-Accounts
Description
// Detect Active Directory service accounts that are not active because their last logon was more than 14 days ago // Replace XXX on line 4 with the naming convention start of your Active Directory service accounts
Query · kql
IdentityLogonEvents | project Timestamp, AccountName, DeviceName, LogonType | where AccountName startswith "XXX" | summarize LastLogon = max(Timestamp) by AccountName, LogonType, DeviceName | where LastLogon < ago(14d)