Reference
Deleted User
All users that have been deleted from your tenant
Part of the Microsoft 365 inventory.
Scan settings
| Default scanning interval | Allowed scanning intervals | Data removal during incremental scan |
|---|---|---|
| Daily | Daily, Weekly, Bi-Weekly, Monthly, Never, Initial | Yes |
Properties
| Property | Type | Description | Automation placeholder |
|---|---|---|---|
| Account enabled | Boolean | True if the account is enabled; otherwise, false. This property is required when a user is created | {{DeletedUser.AccountEnabled}} |
| City | String | The city in which the user is located | {{DeletedUser.City}} |
| Company | String | The company name which the user is associated | {{DeletedUser.Companyname}} |
| Copilot Credits Cost | Double | Microsoft 365 Copilot credit consumption (USD) attributed to this user. | {{DeletedUser.CopilotCreditsCost}} |
| Copilot Studio Cost | Double | Copilot Studio (agent) credit consumption (USD) attributed to this user across all agents. | {{DeletedUser.CopilotStudioUserCost}} |
| Country or region | String | The country/region in which the user is located | {{DeletedUser.Country}} |
| Cowork Tasks | Double | Total Microsoft 365 Copilot Cowork tasks performed by this user. | {{DeletedUser.CoworkTaskCount}} |
| Created | DateTime | The date and time the user was created | {{DeletedUser.CreatedDateTime}} |
| Initially Scanned | DateTime | Shows when this object was initially found in a scan. | {{DeletedUser.CreatedTime}} |
| Creation Type | String | Indicates whether the user account was created as a regular school or work account (null), an external account (Invitation), a local account for an Microsoft Entra ID B2C tenant (LocalAccount) or self-service sign-up using email verification (EmailVerified). | {{DeletedUser.CreationType}} |
| Deleted Date | DateTime | The date and time the user was deleted | {{DeletedUser.DeletedDateTime}} |
| Department | String | The name for the department in which the user works | {{DeletedUser.Department}} |
| Disable Password Expiration | Boolean | If true password never expires | {{DeletedUser.DisablePasswordExpiration}} |
| Disable Strong Password | Boolean | If true it allows weaker passwords than the default policy to be specified | {{DeletedUser.DisableStrongPassword}} |
| Icon | String | Default scanning interval: Initial. | {{DeletedUser.DisplayIcon}} |
| Display Name | String | {{DeletedUser.DisplayName}} | |
| Extension Attribute 1 | String | This extension attribute is also known as Exchange custom attribute 1. For an onPremisesSyncEnabled user, the source of authority for this set of properties is the on-premises and is read-only. For a cloud-only user (where onPremisesSyncEnabled is false), these properties can be set during creation or update of a user object. For a cloud-only user previously synced from on-premises Active Directory, these properties are read-only in Microsoft Graph but can be fully managed through the Exchange Admin Center or the Exchange Online V2 module in PowerShell. Default scanning interval: Weekly. | {{DeletedUser.ExtensionAttribute1}} |
| Extension Attribute 10 | String | This extension attribute is also known as Exchange custom attribute 10. For an onPremisesSyncEnabled user, the source of authority for this set of properties is the on-premises and is read-only. For a cloud-only user (where onPremisesSyncEnabled is false), these properties can be set during creation or update of a user object. For a cloud-only user previously synced from on-premises Active Directory, these properties are read-only in Microsoft Graph but can be fully managed through the Exchange Admin Center or the Exchange Online V2 module in PowerShell. | {{DeletedUser.ExtensionAttribute10}} |
| Extension Attribute 11 | String | This extension attribute is also known as Exchange custom attribute 11. For an onPremisesSyncEnabled user, the source of authority for this set of properties is the on-premises and is read-only. For a cloud-only user (where onPremisesSyncEnabled is false), these properties can be set during creation or update of a user object. For a cloud-only user previously synced from on-premises Active Directory, these properties are read-only in Microsoft Graph but can be fully managed through the Exchange Admin Center or the Exchange Online V2 module in PowerShell. | {{DeletedUser.ExtensionAttribute11}} |
| Extension Attribute 12 | String | This extension attribute is also known as Exchange custom attribute 12. For an onPremisesSyncEnabled user, the source of authority for this set of properties is the on-premises and is read-only. For a cloud-only user (where onPremisesSyncEnabled is false), these properties can be set during creation or update of a user object. For a cloud-only user previously synced from on-premises Active Directory, these properties are read-only in Microsoft Graph but can be fully managed through the Exchange Admin Center or the Exchange Online V2 module in PowerShell. | {{DeletedUser.ExtensionAttribute12}} |
| Extension Attribute 13 | String | This extension attribute is also known as Exchange custom attribute 13. For an onPremisesSyncEnabled user, the source of authority for this set of properties is the on-premises and is read-only. For a cloud-only user (where onPremisesSyncEnabled is false), these properties can be set during creation or update of a user object. For a cloud-only user previously synced from on-premises Active Directory, these properties are read-only in Microsoft Graph but can be fully managed through the Exchange Admin Center or the Exchange Online V2 module in PowerShell. | {{DeletedUser.ExtensionAttribute13}} |
| Extension Attribute 14 | String | This extension attribute is also known as Exchange custom attribute 14. For an onPremisesSyncEnabled user, the source of authority for this set of properties is the on-premises and is read-only. For a cloud-only user (where onPremisesSyncEnabled is false), these properties can be set during creation or update of a user object. For a cloud-only user previously synced from on-premises Active Directory, these properties are read-only in Microsoft Graph but can be fully managed through the Exchange Admin Center or the Exchange Online V2 module in PowerShell. | {{DeletedUser.ExtensionAttribute14}} |
| Extension Attribute 15 | String | This extension attribute is also known as Exchange custom attribute 15. For an onPremisesSyncEnabled user, the source of authority for this set of properties is the on-premises and is read-only. For a cloud-only user (where onPremisesSyncEnabled is false), these properties can be set during creation or update of a user object. For a cloud-only user previously synced from on-premises Active Directory, these properties are read-only in Microsoft Graph but can be fully managed through the Exchange Admin Center or the Exchange Online V2 module in PowerShell. | {{DeletedUser.ExtensionAttribute15}} |
| Extension Attribute 2 | String | This extension attribute is also known as Exchange custom attribute 2. For an onPremisesSyncEnabled user, the source of authority for this set of properties is the on-premises and is read-only. For a cloud-only user (where onPremisesSyncEnabled is false), these properties can be set during creation or update of a user object. For a cloud-only user previously synced from on-premises Active Directory, these properties are read-only in Microsoft Graph but can be fully managed through the Exchange Admin Center or the Exchange Online V2 module in PowerShell. | {{DeletedUser.ExtensionAttribute2}} |
| Extension Attribute 3 | String | This extension attribute is also known as Exchange custom attribute 3. For an onPremisesSyncEnabled user, the source of authority for this set of properties is the on-premises and is read-only. For a cloud-only user (where onPremisesSyncEnabled is false), these properties can be set during creation or update of a user object. For a cloud-only user previously synced from on-premises Active Directory, these properties are read-only in Microsoft Graph but can be fully managed through the Exchange Admin Center or the Exchange Online V2 module in PowerShell. | {{DeletedUser.ExtensionAttribute3}} |
| Extension Attribute 4 | String | This extension attribute is also known as Exchange custom attribute 4. For an onPremisesSyncEnabled user, the source of authority for this set of properties is the on-premises and is read-only. For a cloud-only user (where onPremisesSyncEnabled is false), these properties can be set during creation or update of a user object. For a cloud-only user previously synced from on-premises Active Directory, these properties are read-only in Microsoft Graph but can be fully managed through the Exchange Admin Center or the Exchange Online V2 module in PowerShell. | {{DeletedUser.ExtensionAttribute4}} |
| Extension Attribute 5 | String | This extension attribute is also known as Exchange custom attribute 5. For an onPremisesSyncEnabled user, the source of authority for this set of properties is the on-premises and is read-only. For a cloud-only user (where onPremisesSyncEnabled is false), these properties can be set during creation or update of a user object. For a cloud-only user previously synced from on-premises Active Directory, these properties are read-only in Microsoft Graph but can be fully managed through the Exchange Admin Center or the Exchange Online V2 module in PowerShell. | {{DeletedUser.ExtensionAttribute5}} |
| Extension Attribute 6 | String | This extension attribute is also known as Exchange custom attribute 6. For an onPremisesSyncEnabled user, the source of authority for this set of properties is the on-premises and is read-only. For a cloud-only user (where onPremisesSyncEnabled is false), these properties can be set during creation or update of a user object. For a cloud-only user previously synced from on-premises Active Directory, these properties are read-only in Microsoft Graph but can be fully managed through the Exchange Admin Center or the Exchange Online V2 module in PowerShell. | {{DeletedUser.ExtensionAttribute6}} |
| Extension Attribute 7 | String | This extension attribute is also known as Exchange custom attribute 7. For an onPremisesSyncEnabled user, the source of authority for this set of properties is the on-premises and is read-only. For a cloud-only user (where onPremisesSyncEnabled is false), these properties can be set during creation or update of a user object. For a cloud-only user previously synced from on-premises Active Directory, these properties are read-only in Microsoft Graph but can be fully managed through the Exchange Admin Center or the Exchange Online V2 module in PowerShell. | {{DeletedUser.ExtensionAttribute7}} |
| Extension Attribute 8 | String | This extension attribute is also known as Exchange custom attribute 8. For an onPremisesSyncEnabled user, the source of authority for this set of properties is the on-premises and is read-only. For a cloud-only user (where onPremisesSyncEnabled is false), these properties can be set during creation or update of a user object. For a cloud-only user previously synced from on-premises Active Directory, these properties are read-only in Microsoft Graph but can be fully managed through the Exchange Admin Center or the Exchange Online V2 module in PowerShell. | {{DeletedUser.ExtensionAttribute8}} |
| Extension Attribute 9 | String | This extension attribute is also known as Exchange custom attribute 9. For an onPremisesSyncEnabled user, the source of authority for this set of properties is the on-premises and is read-only. For a cloud-only user (where onPremisesSyncEnabled is false), these properties can be set during creation or update of a user object. For a cloud-only user previously synced from on-premises Active Directory, these properties are read-only in Microsoft Graph but can be fully managed through the Exchange Admin Center or the Exchange Online V2 module in PowerShell. | {{DeletedUser.ExtensionAttribute9}} |
| External User State | String | For invited users, the state can be PendingAcceptance or Accepted, or null for all other users. | {{DeletedUser.ExternalUserState}} |
| First Name | String | The given name (first name) of the user | {{DeletedUser.FirstName}} |
| onPremises Sync Enabled | Boolean | true if this user object is currently being synced from an on-premises Active Directory (AD); otherwise the user isn't being synced and can be managed in Microsoft Entra ID. | {{DeletedUser.InCloud}} |
| Is External | Boolean | Is user sign-in as guest | {{DeletedUser.IsExternal}} |
| Title | String | The user's job title | {{DeletedUser.JobTitle}} |
| Last scan update | DateTime | Shows when this object was last updated in a scan. If an object is found during a scan but no property has been changed this date will not change. | {{DeletedUser.LastModifiedTime}} |
| Last Name | String | The user's surname | {{DeletedUser.LastName}} |
| Last password change date | DateTime | The time when this Entra ID user last changed their password or when their password was created, whichever date the latest action was performed | {{DeletedUser.LastPasswordChangeDateTime}} |
| Last Sign-In | DateTime | The last date a user has signed in to M365. This date can either be the last date a user actively signed in to M365 or when he last had a so called non-interactive sign-in (depending on what is more recent). Interactive sign-in happens by opening the browser and opening the url of an M365 resource (e.g. SharePoint Online). Non-interactive sign-in will happen when users use clients (e.g. Outlook Client) to access tenant resources rather than signing into your tenant directly. The timestamp represents date and time information using ISO 8601 format and is always in UTC time. Default scanning interval: Weekly. | {{DeletedUser.LastSignIn}} |
| Last Sign-In (Interactive) | DateTime | The last date a user has signed in to M365 interactively. Interactive sign-in happens by opening the browser and opening the url of an M365 resource (e.g. SharePoint Online). The timestamp represents date and time information using ISO 8601 format and is always in UTC time. Default scanning interval: Weekly. | {{DeletedUser.LastSignInInteractive}} |
| Last Sign-In (non-interactive) | DateTime | The last date a user has signed in to M365 non-interactively. Non-interactive sign-in will happen when users use clients (e.g. Outlook Client) to access tenant resources rather than signing into your tenant directly. The timestamp represents date and time information using ISO 8601 format and is always in UTC time. Default scanning interval: Weekly. | {{DeletedUser.LastSignInNonInteractive}} |
| Last Successful Sign-In | DateTime | The date and time of the users most recent successful sign-in activity. The timestamp type represents date and time information using ISO 8601 format and is always in UTC. Default scanning interval: Weekly. | {{DeletedUser.LastSuccessfulSignIn}} |
| Member Type | String | A String value that can be used to classify user membership types in your directory Allowed values: External Guest, External Member, Internal Guest, Internal Member. | {{DeletedUser.MemberType}} |
| Office | String | The office location in the user's place of business | {{DeletedUser.OfficeLocation}} |
| On-premises Distinguished Name | String | Contains the on-premises Active Directory distinguished name or DN. The property is only populated for customers who are synchronizing their on-premises directory to Microsoft Entra ID via Entra ID Connect. | {{DeletedUser.OnPremisesDistinguishedName}} |
| On-premises sAMAccountName | String | Contains the on-premises sAMAccountName synchronized from the on-premises directory. The property is only populated for customers who are synchronizing their on-premises directory to Microsoft Entra ID via Entra ID Connect | {{DeletedUser.OnPremisesSamAccountName}} |
| Preferred data location | String | The preferred data location for the user | {{DeletedUser.PreferredDataLocation}} |
| Risk Score | Int32 | Stores risk score | {{DeletedUser.RiskScore}} |
| Risk Score Update | DateTime | Stores risk score update | {{DeletedUser.RiskScoreLastUpdate}} |
| Risk Score Value | String | Stores risk score value like Low_Low | {{DeletedUser.RiskScoreValue}} |
| State or province | String | The state or province in the user's address | {{DeletedUser.StateOrProvince}} |
| Type | String | A custom security attribute that is assigned to a directory object | {{DeletedUser.Type}} |
| Usage location | String | A two letter country code (ISO standard 3166) | {{DeletedUser.UsageLocation}} |
| User Email | String | The SMTP address for the user | {{DeletedUser.UserEmail}} |
| User Email Domain | String | Email domain of the user. This will only be set if User Email is not empty. | {{DeletedUser.UserEmailDomain}} |
| User Id | String | The unique identifier for the user | {{DeletedUser.UserId}} |
| User Principal Name | String | The user principal name (UPN) of the user. The UPN is an Internet-style login name for the user based on the Internet standard RFC 822 | {{DeletedUser.UserPrincipalName}} |
| User Type | String | A String value that can be used to classify user types in your directory | {{DeletedUser.UserType}} |
Relations
| Relation | Service | Description |
|---|---|---|
| Mailbox | Exchange | All Exchange mailboxes of your users, rooms & equipment |
| User Activity | Teams | Details about the activity of the user in Teams |
| Device Usage | Teams | Details which devices the user uses to access Teams |
Segments
This object does currently not have any segments.
Actions
- Restore User Account