When configuring Compliance Policies in ProvisionPoint, Rules are created and added to ruleset groups to define what checks will be run.
This article will explain what Inactive Guests are and the rules that are available to check for them.
Additional licensing is required to use this rule in your tenant: The sign in activity is not available unless your tenant is using a premium Entra license (P1/P2).
If you have Group Operations enabled for Service account in the Admin > Settings > App Settings tab, the Service Account will be used to pull the data for this request.
A role will be required for the service account user in Entra Identity. Please add the Report Reader role to this account.
What are Inactive Guests?
An Inactive Guest is a guest account user that has not signed in to your tenant for a specific number of days, or who has never signed in at all.
Expand to learn more
When a Guest is invited they must sign in to activate their account. If this is not completed they will be flagged as inactive.
Inviting Guests in ProvisionPoint
Guests can be invited into the tenant and added to Group connected workspaces. Use the ProvisionPoint Action or your existing invite Guest method.
What does the Inactive Guest rule achieve?
The Inactive Guest rule identifies any guest users that have not signed in to your tenant within a specified number of days.
The rules can be customised to
- set the duration of inactivity.
- The rule looks at the last signed in date (UTC) of the user.
- If the user has never signed in then it will go on the created date (date the user was first sent an invitation to your tenant).
- If any Guest users are inactive for more than the specified amount of days, the workspace will be flagged as non-compliant

Please be aware that there is a Microsoft delay with pulling through the last sign in date of Guest users of up to 24 hours.
When configuring the rule, we recommend adding an additional day to the duration to cover this
For example, if you want to look for Guests who have been inactive for 7 days or more, set the duration to 8.
Available Rules
|
Rule Name
|
Description
|
|
Inactive Guests - Report
|
Report and display any inactive guests and store the results in the policy queue, these can be accessed via the API
|
|
Inactive Guests - Notify
|
Send an email to configured people about the non-compliance, this email will include content defined in the rule. Additional configuration will be needed. Read the Configure Notifications for Notify Rules article for more information
|
|
Inactive Guests - Remove
|
Will remove any inactive guests found from the workspace. If the Guest user has never logged in, the rule will base it on the user's created date instead
|
We always recommend starting with a Report rule to ensure the policy brings back the results you expect before applying other rules
Check the Result
Once a compliant policy is run, you can check the result in the 'Policy' queue and Timeline to see if it is non-compliant.
Read articles in the Job Queue section.