Find disabled and deleted users with lingering SharePoint permissions for cleanup.
Related topics
orphaned users
stale permissions
user cleanup
access review
security hygiene
About this tool
The Orphaned Users Report identifies disabled or deleted users who still have SharePoint permissions. These lingering access grants pose security risks and compliance issues.
Scan all SharePoint sites for permissions assigned to users who no longer exist in Azure AD or have been disabled. Generate reports with direct links to remove the orphaned permissions.
Essential for maintaining least-privilege access and cleaning up after employee departures.
Key features
Disabled user detection
Deleted user identification
Site-by-site analysis
Permission level detail
Remediation guidance
Bulk cleanup support
Compliance documentation
Scheduled scanning
Use cases
.
.
.
Graph scopes
undefined (application), undefined (application).
Tool identity
Slug: orphaned-users.
Category: audit.
Plan tier: pro.
Editions: cloud, desktop.
SKUs: security, suite.
Documented scenarios: 3.
Declared features: 8.
Graph permissions requested: 2.
Licensing & access
Requires a paid edition (security). The Suite bundle includes this tool alongside every other capability in the catalogue.
Limitations & out-of-scope
Orphaned Users Report: Detective control only: findings are reported, never auto-remediated. Severity rankings use the documented heuristic and may diverge from Microsoft Secure Score. Detection coverage stops at the Graph permission surface declared above — workloads behind tenant-licensed add-ons (Defender XDR, Purview eDiscovery Premium) require the matching license to enumerate.