@Gargron

Maybe keep the timestamp of the last login and if more than (e.g.) two months send a warning email the next time someone logs in?

Or suspend the account and require the user click a link on an email to reactivate.