
OktaW.51968 (Customer) asked a question.
How does ISPM determine an account is "orphaned" in Entra/AAD? The only link to documentation I can find is this, and it doesn't go into any detail re: the requirements for an orphan.
https://help.okta.com/ispm/en-us/content/topics/ispm/home.htm?cshid=csh-ispm-home

Hello @OktaW.51968 (Customer) Thank you for posting on our Community page!
I have done some reaserch on this matter and unfortunately was unable to find more details on this issue. I would recommend to open a case with Support they'll be able to access additional tools and resources to help you get to the bottom of it.
Thank you for reaching out to our Community and have a great day!
--
Help others in the community by liking or hitting Select as Best if this response helped you.
Collect them all. Learn a new skill and earn a new Okta Learning badge.
Below is the response from support. My hope is that it will help others.
An orphaned account is defined as an account that the system was unable to match to a person or a corresponding account in your primary Identity Provider (typically Okta). ISPM employs several linking algorithms to identify accounts, and if a match cannot be established, the account may be flagged as orphaned.
As this is determined by AI, it might not always be completely accurate. Based on our experience, the system may identify "leftover" accounts.
Please provide the account details so we can investigate the reason. However, as previously mentioned, please be aware that since this determination is AI-based, the exact cause isn't always identifiable.
This will be a low-priority case and may take some time to resolve. Alternatively, you can dismiss and mark this as a false-positive FP in the console.