Why: The practice's account-inventory reconciliation is the routine that keeps identifier management honest — surfacing dormant identifiers, unowned service accounts, and departures that slipped past process, which is the population every lifecycle decision in this requirement acts on.
What this does not claim: Surfacing identifiers is not authorizing, assigning, or quarantining them: the requirement's authorization step, reuse-prevention period, and individual-status characteristic are procedure and directory work the inventory does not perform. Provides the checkable population and operating evidence rather than implementing the requirement.
- Reconcile directory identifiers against personnel and asset lists on a cadence
- Include last-sign-in and ownership columns so dormant and orphaned identifiers surface
- Reconciliation reports with dormant-identifier findings
- Records of lifecycle actions taken on those findings
Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06