Getting this under control requires consistency. A few things that move the needle:
Audit disabled and privileged accounts on a routine basis
If an account has been inactive for 30, 60, or 90 days, flag it. For an MSP managing multiple clients, that means building account review into your quarterly check-ins.
Tie every account to a current owner and a current purpose
If you can't answer "Who owns this?" or "Why does it still exist?" then you've got risk, pal. A simple spreadsheet mapping every privileged account to a name and a business reason is a better starting point than most organizations have.
Watch out for abnormal authentication activity associated with dormant accounts
If an account that's been dark for six months tries to authenticate at 2 am, that's a red flag. Investigate it.
Harden account settings as part of your overall posture management
Privilege management is an ongoing discipline that should be built into how you manage identity security across the board.
It's also a compliance issue. Regulations like HIPAA, GDPR, and SOX mandate strict access controls, and over-permissioned accounts are a fast path to an audit finding or a fine.