Microsoft 365 leaver checks: what each option leaves behind
An administrator who wants to know what a departed user still holds already has four options from Microsoft and two free open-source ones. This page sets them next to Offboarding Evidence, read on 15 September 2026. Every statement about another product carries the number of the page it came from, and the limits of this one are stated in the same columns.
Side by side
| Option | What it checks | What it costs | What record it leaves | Where it stops for one named leaver |
|---|---|---|---|---|
| Offboarding Evidence (ITSailor, paid) | Reads Microsoft Graph for what a disabled account still holds: assigned licences, sign-in activity, delegated OAuth grants, directory roles, app role assignments, Intune devices, OneDrive presence, and inbox forwarding and redirect rules. Also reads tenant posture such as Conditional Access and SharePoint sharing. | €249 a month, or €199 a month billed annually, excluding VAT. One subscription that also covers Tenant Monitor. | An evidence pack per departure: a PDF, findings and remediation CSV files, and a PowerShell runbook that runs as a dry run by default. A closure is recorded as a bound between two daily checks, never as a time in minutes. | Revokes nothing: your own team runs the runbook. Closure is observable for four finding classes only (OAuth grants, directory roles, app role assignments, licences). A degraded later scan is reported as inconclusive, never as closed. Reads inbox rules, not forwarding set on the mailbox itself. |
| Offboarding risk scan (ITSailor, free) | The same read set, once, in one browser session. | Free. | A report and evidence pack held for ten minutes so the page can load them, then expired. | Asks for 11 read permissions and no offline_access, so it cannot scan again or observe a closure. Without MailboxSettings.Read, inbox forwarding rules appear as an evidence gap rather than a finding. |
| Manual checks: Entra admin center, Microsoft Graph, Exchange Online PowerShell | Last sign-in (signInActivity), one user's delegated grants, forwarding set on the mailbox (Get-Mailbox), and inbox rules (Get-InboxRule or the Graph messageRules call).[1, 5, 15, 4] | Already in the tenant. Reading signInActivity through Graph needs Entra ID P1 or P2, which Microsoft 365 Business Premium and E3 include.[1, 2] | None by default: whatever the administrator exports. Entra audit and sign-in logs are kept for 7 days on the free tier and 30 days on P1 or P2.[3] | Microsoft states there is no built-in report for inactive user accounts. Get-InboxRule does not run under the Global Reader role. The per-user grants call has no application permission, so it cannot run unattended.[1, 4, 5] |
| Entra ID Governance access reviews, inactive users | Recurring reviews of group, app, role or access-package membership. A reviewer approves or denies; inactivity is judged on sign-in.[6, 8] | Access reviews need Microsoft Entra ID Governance or Microsoft Entra Suite, and a review scoped to inactive users needs Entra ID Governance.[6] | Review results as a CSV download. The review history report stays downloadable for 30 days.[7] | A recurring certification over a group or an app, not a check triggered by a departure. Its recommendations treat inactive as no sign-in in the last 30 days. It does not list a leaver's OAuth grants, forwarding rules or devices.[8] |
| Microsoft 365 Lighthouse, Inactive users | Accounts across managed customer tenants inactive for over six months, with block sign-in and delete in the same view.[10] | No additional cost, for CSP partners only, indirect resellers and direct-bill partners alike. Needs GDAP or DAP per customer, at most 2,500 licensed users in the customer tenant, same geographic region.[9, 11] | The tab lists up to 500 inactive accounts per tenant. Microsoft describes no per-departure record.[10] | It serves the partner, not the customer's own administrator, and cannot manage the partner's own tenant. A leaver appears only after six months without a sign-in.[10, 11] |
| Maester | Open-source Pester tests of tenant configuration across identity, access, devices, apps and Exchange, including a test for privileged accounts left enabled when the linked primary account is disabled.[12, 13] | Free and open source, MIT licence.[12] | An HTML report, with optional email alerts.[12] | Tests whether settings are configured, not what one named leaver still holds.[13] |
| CISA ScubaGear | Compares tenant configuration with the CISA SCuBA baselines for Entra ID, Exchange Online, SharePoint, Teams, Power BI, Power Platform and the security suite.[14] | Free, released under the Creative Commons Zero licence.[14] | HTML, JSON and CSV reports.[14] | Assesses configuration against a baseline. It does not inventory a named departure's grants, licences or forwarding.[14] |
The two ITSailor rows restate what the product does in code. The permissions behind them are listed on the connector permissions page, and the price is the one the checkout charges.
What only a per-departure record answers
Microsoft's own tools answer whether a setting is right and who has not signed in for a while. The question an auditor asks after a named person leaves is narrower: what that account still held on the day it was checked, and whether it was gone by the next check. The options above either do not keep a dated record of it, keep it for a limited window, or only see the account months later. That gap, and nothing wider, is what Offboarding Evidence is for.
Where it stops is in the table in the same columns as everyone else: it changes nothing in the tenant, it can only see a closure for four kinds of finding, and it reads inbox rules rather than forwarding set on the mailbox itself.
Where the sources disagree
- Microsoft's two Lighthouse pages disagree on the relationship a partner needs. The requirements page says an indirect reseller relationship is no longer required; the FAQ still describes GDAP plus an indirect reseller relationship. This page follows the requirements page, the newer statement.[9, 11]
- Maester states its test count two ways: "360+" on its homepage, and a version 2.2.0 documentation table whose suites add up to 407. Both are quoted here because neither is wrong on its own page.[12, 13]
Sources
Every page below was read on 15 September 2026.
- [1] Microsoft Learn: manage inactive user accounts in Microsoft Entra ID
- [2] Microsoft Learn: Microsoft Entra ID Governance licensing fundamentals
- [3] Microsoft Learn: Microsoft Entra data retention
- [4] Microsoft Learn: Get-InboxRule
- [5] Microsoft Learn: list a user's oauth2PermissionGrants
- [6] Microsoft Learn: what are access reviews
- [7] Microsoft Learn: downloadable access review history
- [8] Microsoft Learn: review recommendations for access reviews
- [9] Microsoft Learn: requirements for Microsoft 365 Lighthouse
- [10] Microsoft Learn: manage inactive user accounts in Microsoft 365 Lighthouse
- [11] Microsoft Learn: Microsoft 365 Lighthouse frequently asked questions
- [12] Maester, project homepage
- [13] Maester, test documentation (version 2.2.0)
- [14] CISA ScubaGear on GitHub
- [15] Microsoft Learn: resolve inbox rule issues (the mailbox forwarding check)
Try it on your own tenant
The free scan reads the same set once, in one browser session, and leaves nothing behind after ten minutes.