Report on Azure AD Stale Users

If you are utilizing external, guest, or B2B users in your Office 365 or Azure environments, you may need a way to determine which objects haven't been logged in or used in a while.  Azure AD doesn't provide an easy way to view this information (really only having the refresh tok

3.7 Star
2,165 times
Add to favorites
Office 365
E-mail Twitter Digg Facebook
  • Need help as well
    1 Posts | Last post October 25, 2019
    • I am having the same issue as Onehit42. The whole point of this script is to let you know when a guest user becomes stale by using the RefreshToken attribute. When a Guest user logs into an application whether it is Teams or the MyApps portal it is not updating that token. I have had multiple tickets open with Microsoft and they don't seem to be able to figure this out. This is a real need for enterprises to be able to manage and monitor B2B accounts. 
  • RefreshTokensValidFromDateTime not updating on login?
    2 Posts | Last post July 25, 2019
    • I had an external user with a RefreshTokensValidFromDateTime over 9 months old just login to the Teams site they're invited to this morning, and the RefreshTokensValidFromDateTime has not updated yet - over 4 hours later. Is this to be expected? Could there be another reason for the lack of update?
    • As I know a guest account only gets an access token, this does not change the RefreshTokensValidFromDateTime attribute.
      Do you see a difference between RefreshTokensValidFromDateTime and whenCreated on guest accounts ?