To support ASD Essential Eight Maturity Level 2 compliance, privileged accounts are automatically disabled after 45 days of inactivity.

- On the first day of each month, Varonis generates an automated report and emails it to the Information Security queue. 
- The report identifies inactive privileged accounts, including both cloud administrator and Az-ADM accounts. 
- The Information Security team is pre-approved to disable any accounts identified as inactive within the report.

If access is required after an account has been disabled, the account owner must contact their internal contact or manager to request reinstatement. 
Disabled accounts will remain inactive until a legitimate business requirement has been validated and the account is re-enabled through the approved process.

From the automation, select 'View Reports'

Download the CSV and disable any accounts in AD or Entra which have not been used in 45 days.