<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Account Security on Anything About IT</title><link>https://www.verboon.info/tags/account-security/</link><description>Recent content in Account Security on Anything About IT</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 08 Jul 2025 15:34:54 +0000</lastBuildDate><atom:link href="https://www.verboon.info/tags/account-security/index.xml" rel="self" type="application/rss+xml"/><item><title>Shedding Light on Dormant Sensitive Accounts</title><link>https://www.verboon.info/2025/07/shedding-light-on-dormant-sensitive-accounts/</link><pubDate>Tue, 08 Jul 2025 15:34:54 +0000</pubDate><guid>https://www.verboon.info/2025/07/shedding-light-on-dormant-sensitive-accounts/</guid><description>&lt;p&gt;Dormant sensitive accounts are a high-risk identity exposure. In Microsoft Defender XDR, the recommendation &lt;strong&gt;Remove dormant accounts from sensitive groups&lt;/strong&gt; helps surface these accounts, including whether they are inactive, disabled, or have expired credentials.&lt;/p&gt;
&lt;p&gt;
 &lt;img src="images/shedding-light-on-dormant-sensitive-accounts-01.png" alt=""&gt;

&lt;/p&gt;
&lt;p&gt;You can export the detected entities, but the export often contains limited context. In many cases, you only get entity names or SID values, which makes remediation harder when you need ownership and organizational details.&lt;/p&gt;
&lt;p&gt;
 &lt;img src="images/shedding-light-on-dormant-sensitive-accounts-02.png" alt=""&gt;

&lt;/p&gt;
&lt;p&gt;A practical approach is to use the SID values to enrich the result set with identity attributes from &lt;code&gt;IdentityInfo&lt;/code&gt;. You can quickly build a SID variable list using KustoVars, then query Defender XDR for additional context.&lt;/p&gt;</description></item></channel></rss>