← Blue Lantern Security

Monitor Identity: Daily MFA Coverage and Dormant-Account Checks

Blue Lantern Security's identity posture scan runs once a day against your Google Workspace or Microsoft 365 directory and answers two questions that insurers, auditors, and attackers all care about: which users have no multi-factor authentication method registered, and which enabled accounts nobody has signed into for months. Admin accounts are held to a stricter bar, and the results feed your attestation report.

Enable identity monitoring

Access: included with the Gmail or Microsoft 365 organization integration on a Seat License at $15 per monitored user per month. Enable it with a checkbox in the integration's settings; it runs once daily. On Microsoft 365, the dormancy check also requires an Entra ID P1 or P2 license on the tenant. See current pricing.

Most account takeovers start with a password and end at the MFA prompt, if there is one. A directory usually has a few accounts that never registered a second factor, and a few more that belong to people who left. Both are easy to miss and easy to fix once you can see them.

What does the identity scan check?

Check What it looks for Severity
MFA registration Every directory user is checked for a registered MFA method (2-Step Verification in Google Workspace; a registered authentication method in Microsoft Entra) Users without MFA are findings; admins without MFA are critical
Dormant accounts Enabled accounts with no sign-in for 90 days, or 30 days for admins Dormant accounts are findings; dormant admins are critical

The scan reads the whole directory, including users whose mailboxes are not monitored, so coverage numbers reflect the entire organization. Each run reports a coverage percentage and an exportable roster of users and results for audits.

How do I enable it?

  1. Connect the organization integration for Google Workspace or Microsoft 365 if you have not already.
  2. Grant the permission if needed. On Google Workspace, no new scopes are required; the directory scope in your existing domain-wide delegation grant covers both checks. On Microsoft 365, the scan needs the AuditLog.Read.All application permission with admin consent. If it was not granted at connect time, grant it in Entra ID and re-run the connect flow. Until it verifies, the scan shows "needs permission" and mail monitoring continues unaffected.
  3. Turn on the daily identity posture scan in the integration's settings and save.
  4. Review results in the Monitoring Hub under the Identity type. Filter to failed checks, MFA findings, dormancy findings, or admins.

What should I do with the findings?

Finding Practical next step
Admin without MFA Register a method today. Admin accounts are the highest-value target in the directory
User without MFA Enroll the user, then enforce MFA at the platform level so new accounts cannot skip it
Dormant admin Disable the account, or downgrade it if the person still needs ordinary access
Dormant user Confirm the person has left or the account is unused, then disable it

Findings clear on the next daily run once the fix is in place. Because the scan is daily, a change made today shows up tomorrow.

Registration is not the same as enforcement. The scan confirms that a method exists for each user; it does not observe whether every sign-in was actually challenged. Pair it with an enforcement policy in Google Workspace or Microsoft Entra so registration is required rather than encouraged.

What data does the scan read?

  • Google Workspace: the user directory and 2-Step Verification status, using the existing admin.directory.user.readonly delegation scope.
  • Microsoft 365: the user directory, registered authentication methods, and sign-in activity, using the User.Read.All and AuditLog.Read.All application permissions.

The scan reads account attributes, not mail or files. See the Privacy Policy for retention terms.

Common questions

Does this enforce MFA?

No. It verifies who has a method registered and reports who does not. Enforcement is a policy you set in Google Workspace or Microsoft Entra. Together they give you both the rule and the proof it is working.

Why are admins treated differently?

An admin account can reset other users' passwords, change mail routing, and grant application access. An admin without MFA, or a dormant admin account still enabled, is an attacker's best target, so those findings are critical and the dormancy threshold is 30 days instead of 90.

What counts as dormant?

An enabled account with no recorded sign-in for 90 days (30 for admins). Service accounts and shared mailboxes that legitimately never sign in will show up; review them and disable the ones that do not need interactive access.

Does this cover AWS or Azure roles?

No. This scan covers directory users in Google Workspace and Microsoft Entra ID: MFA registration and sign-in activity. It does not audit AWS IAM policies or Azure role assignments.

What about third-party and AI apps with access to my directory?

That is a separate daily scan. Monitor AI exposure inventories the OAuth apps your users have granted access to mail, files, and calendars.

Enable identity monitoring

Related guides

Sources and further reading