Thanks malmoore.
To clarify then how this works: does the app has a list of users and looks for the existence of Windows login events for those users. If none found for a given user then they are considered an "Unused user account". Where does this list of users come from? How can I see what list of users is being used? (Professional Services set this up for us so I am missing some of the details 😞 )
Or does the app look at some attribute in AD, like lastLogon, for all users to see which users do NOT have a value in the attribute?
Thanks for helping me understand!
... View more