๐Ÿ“‹ GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROCโ€ฆSaaS discovery for data governanceFree enriched web chat widget๐Ÿš€ Enriched remote support without your laptop

Identity & Account Management

See every user account from Active Directory, Microsoft 365, Google Workspace and local computer accounts in one list, with the risks that matter.

Where to find it
Microsoft 365 โ€บ End Users
Who can use it
Anyone who can see the page
Plan
Microsoft 365 monitoring
For
Everyone

What the page is for

Most organizations have the same person in several places: Active Directory, Microsoft 365 and Google Workspace, plus local accounts on their computers. This page merges all of those sources into one table, one row per person, so you can see each account's status, last login, password age, MFA and risk flags together.

Local Windows accounts seen by the Lavawall agent are matched to the right person where the name matches. Built-in accounts such as a local Administrator stay as a separate row for each computer, because each one is a different account.

Clickable summary cards at the top count common risks, such as admins, accounts without MFA, accounts inactive for 90 days or more, passwords that never expire, and failed logins or brute-force attempts. Click a card to filter the list. You can also add contact details and notes to a person and link them to their computers.

What you see

The Identity & Account Management page, with the summary cards, all user accounts header, filters, accounts table and edit contact numbered 1 to 5.
The Identity & Account Management page. Numbers match the list below.
  1. Summary cards: Total, Admins, Disabled, Deleted, Expired, External, Pwd Never Exp, No Pwd Req, PreAuth Off, Never Login, Locked, Inactive 90d+, No MFA, Local Accts, Failed Logins and Brute Force. Click a card to filter.
  2. All User Accounts header: the account count, Local Logins and Export.
  3. Filters: Search, Source (AD, M365, GW, Local), Lifecycle (Active, Disabled, Locked, Expired, Deleted), Properties, Inactive, Pwd Age and a reset button.
  4. Accounts table: Name, Email/UPN, Sources, Status, Status Changed, Last Login, Pwd Age, Flags and Devices.
  5. Edit Contact window: First Name, Last Name, Phone, Mobile, City and Notes.

How to find risky accounts

  1. Click a summary card, for example No MFA or Inactive 90d+. Click it again to clear.
  2. Or open Properties and tick one or more options, such as Admin, No MFA, Weak MFA, Never Logged In, Pwd Never Expires, Local Admin, Stale Local, Failed Logins or Brute Force.
  3. Use Inactive (30+d, 90+d, 365+d) and Pwd Age to find old accounts and old passwords.
  4. Click a column heading to sort, for example Last Login.

How to include disabled or deleted accounts

  1. Open Lifecycle. Only Active is ticked by default.
  2. Tick Disabled, Locked, Expired or Deleted, or click All.
  3. Status Changed shows when Lavawall first saw the account enter its current state.

How to edit a person's contact details

  1. Hover over the person's name and click the edit button.
  2. Fill in First Name, Last Name, Phone, Mobile, City and Notes.
  3. Click Save. A note icon appears beside names that have notes.
  1. In the Devices column, click the add button.
  2. In Assign Device, search for the computer and select it.
  3. Click Assign.
  4. To remove a manual assignment, click the โœ• beside the device and confirm. Automatic assignments cannot be removed.

How to export

  1. Set the filters you want.
  2. Click Export to download the list.

Tips

  • The Sources badges show where each account exists, so you can spot an account that was removed from Microsoft 365 but still exists in Active Directory.
  • Local Only accounts exist only on computers and are not in any directory. Check that they are expected.
  • Click Local Logins for event-by-event detail of local Windows logons.
  • Hover over a summary card for a description of what it counts.
  • Manually assigned devices are shown with a dashed outline.

Troubleshooting

  • An account appears twice. The sources could not be matched by name. Check the email or user name in each source.
  • Failed Logins and Brute Force show a dash. Login events are still loading or no local login data is available for this company.
  • "Cannot remove auto assignments." The device was linked automatically from its login history and can only be changed at the source.

Task guides that use this page

Still need help?

Search the support centre, or contact our support team and tell us which page you were on.

Names, companies, devices and figures in the pictures are examples. Other product and company names are trademarks of their respective owners.