Directories fill with accounts that have gone quiet. A service account from a retired integration, a contractor who finished last year, an employee on extended leave. They still exist, still hold access, and have not authenticated in months. Then one morning, one of them signs in.
A dormant account reactivating is one of the highest-signal events in identity security, because the legitimate owner is not there to generate it. Yet most stacks treat the login like any other. Credentials are valid, the account is enabled, access checks pass. Nothing about the sign-in itself says the person behind it changed.
Silence, Then Sudden Activity
The signal lives in the contrast with everything before it. An identity that did nothing for six months and now enrolls a device, resets a secret, and pulls data is behaving nothing like its own history—because there was barely any history to behave like.
Baseline Includes Dormancy
PeopleBase carries each identity's full history, dormancy included. The moment a long-silent account acts, the contrast isn't between its behavior and a policy — it's between its behavior and six months of nothing. That gap is the signal.
The accounts you forgot about are the ones an attacker is counting on you to forget. Identity Threat Protection surfaces dormant and overprivileged accounts before they become the entry point.
See the latest from Abnormal's product and engineering teams.

