Guide | July 2026
Why This Matters
Security Risk: Stale computer objects are exploitable attack vectors. Unused identities with valid credentials can be leveraged by attackers to move laterally inside the network.
Operational Noise: Inactive objects clutter AD, making it harder to accurately audit systems, enforce policies, and maintain a reliable inventory of active endpoints.
Compliance Gap: Security frameworks (CIS, NIST) and internal audit standards require organizations to continuously monitor and remove unused identities.
Defining a Stale Computer Object
A computer object is considered stale if it has not authenticated to the domain for a defined period of time.
Inactivity Thresholds:
- 30-60 Days: Potentially Inactive
- >90 Days: Stale
- >1 Year: Deletion
Key Attributes: lastLogonTimestamp, pwdLastSet, lastLogonDate.
Linux objects validated with Asset Panda and VM Center.
Apple objects validated with JAMF.
Computer Object Lifecycle
1. Detect – Monthly query and reporting.
2a. Disable – No login/password change in 90+ days.
2b. Isolate – Move to Quarantine OU.
3. Delete from Quarantine – No activity or recovery request in 1 year.
Automation & Reporting
Process performed using PowerShell, Task Scheduler, CSV Reports, SIEM/Splunk integration, and AD Recycle Bin.
Safeguards: Protecting Against False Positives
Exclusions: Domain Controllers, Disaster Recovery computers, Laboratory computers.
OU-based exclusions and quarterly reviews.
Identification methods include naming conventions, ManagedBy/Description flags, and MECM/Intune status.
Guide Summary
90 days without password change -> Disable account.
Disabled account -> Move to Quarantine OU.
1 year no activity -> Delete account.
All actions reported to DSP and Splunk.