> For the complete documentation index, see [llms.txt](https://docs.oort.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.oort.io/understanding-check-failures/oort-insights/identity-posture-management-insights/never-logged-in.md).

# Never Logged In

Detects accounts that were created but never successfully used to log in. Attackers may exploit these unused accounts to register their own MFA factors, potentially bypassing authentication controls and gaining unauthorized access.

A user will fail this check if they have not logged in 7 (configurable) days after an account was created. If needed, adjust the new account grace period in Custom Detection Settings to align with your organization's procedures.<br>

**Recommended Actions**

Trigger an access review with the user’s manager to verify that the unused account is still necessary. If not needed, suspend the account immediately. Otherwise, reset the account and direct the manager to onboard the user correctly.<br>

**Default Check Settings**

Number of days: 7

**Compatibility**

[Duo](/integrations/duo-security-integration.md)

[Google Workspace](/integrations/google-workspace-integration.md)

[Microsoft Entra ID](/integrations/azure-active-directory-integration.md)

[Okta](/integrations/okta-data-integration.md)

[Salesforce](/integrations/salesforce-integration.md)

[Snowflake](/integrations/snowflake.md)

[OpenAI](/integrations/openai.md)

<br>
