How to Set a Microsoft Entra ID Account Expiration Date
Question details
The user needs to configure an expiration date for user accounts in Microsoft Entra ID to ensure automated access revocation.

- Product
- Microsoft Entra ID (formerly Azure Active Directory)
- Device & OS
- not provided
- Scenario
- Managing account lifecycle and access control for guest and regular users.
- Observed behavior
- Microsoft Entra ID lacks a built-in GUI feature to set a specific date for regular user account expiration, requiring alternative methods like PowerShell or guest policies.
Ensure you have the necessary administrative privileges, such as Global Administrator or User Administrator roles in Microsoft Entra ID, and access to an Azure environment for PowerShell scripting if required.
Configure Guest User Expiration Policies
Use this method for managing external guest users by setting expiration based on membership duration or inactivity.
Microsoft Entra ID provides built-in lifecycle management features for guest accounts. Instead of a hard-coded date, you can rely on inactivity periods or a set membership duration to automatically clean up obsolete external users.
Sign in to the Microsoft Entra admin center and navigate to 'Identity Governance'.
Select 'Access reviews' or 'Lifecycle workflows' depending on your specific licensing and configuration.
Create a new policy targeting guest users and define the maximum allowed inactivity duration or membership time limit before the account expires and access is revoked.
Use PowerShell and Azure Automation for Regular Users
Since Entra ID lacks a specific date setting for regular users, use PowerShell scripts triggered by Azure Automation to disable accounts on a scheduled date.
Set Expiration for Synchronized Users via On-Premises AD
If your environment uses hybrid synchronization, configure the account expiration date directly in your on-premises Active Directory.
Streamline Your Business Administration with WPS Office
While you manage your organization's Microsoft Entra ID environment, you can cut software costs by equipping your workforce with WPS Office. It provides a lightweight, highly compatible, and free alternative to Microsoft Office for all your document needs.
- 1. Download the Installer: Visit the official WPS Office website and download the free installer for your operating system.
- 2. Install WPS Office: Run the setup file and follow the quick on-screen instructions to deploy the suite on your machine.
- 3. Open Your Documents: Launch WPS Office to instantly open and edit your existing Microsoft Office files without formatting loss.

Frequently Asked Questions
Can I set an exact expiration date for regular Microsoft Entra ID users in the admin center?
No, Microsoft Entra ID does not currently offer a built-in graphical interface setting to expire regular cloud-only user accounts on a specific date. You must rely on PowerShell automation or Identity Governance policies.
Will disabling a synchronized account in on-premises AD immediately disable it in Entra ID?
Not instantly. The account will be disabled in Microsoft Entra ID only after the next synchronization cycle completes (usually every 30 minutes), unless you force a manual sync via PowerShell.
How do guest user expirations differ from regular user expirations?
Guest user expirations can be natively managed through Microsoft Entra Identity Governance and Access Reviews based on inactivity periods or set membership durations, whereas regular accounts lack these specific date-based lifecycle features out-of-the-box.
How can I request this expiration feature from Microsoft?
Since this is a widely requested management capability, you can submit or upvote a feature request regarding regular user expiration dates in the official Microsoft Feedback Portal.




