Offboarding Under Control: How to Prevent Orphaned Accounts

19. 8. 2026

Offboarding Under Control: How to Prevent Orphaned Accounts

19. 8. 2026

The laptop has been returned, the access card has been blocked, and the employment relationship has ended. Yet the former employee may still have active accounts in applications, active sessions, VPN access, or user tokens.

Offboarding therefore does not end with disabling an account in the central directory. It ends only when the organization can demonstrate that all user access has been revoked.

How Orphaned Accounts Occur

A single person typically uses accounts across several different systems. In addition to an account in a directory service, they may have access to enterprise applications, cloud services, customer portals, or legacy systems. In some cases, they may also use a separate privileged identity.

The risk arises when an organization does not have control over the entire lifecycle of these accounts and access rights. Some applications may use a central directory service or SSO, but blocking the central identity alone does not necessarily mean that the account in the target application is actually deactivated. Inadequate deprovisioning may leave the account active or leave tokens or permissions associated with it. This creates an orphaned account – an account without a valid or identifiable owner. Such an account poses a security risk because it may still allow unauthorized access to systems or data.

During onboarding, missing access becomes apparent immediately: the new user cannot work and starts addressing the issue. With offboarding, the situation is the opposite. If an account remains active, there may be no visible impact on day-to-day operations. The organization may not discover the problem until an audit, a license review, or a security incident.

What Offboarding Needs to Ensure

A reliable process is built on several clear principles.

A clear trigger
An HR system or another authoritative system must determine when an employment or contractual relationship ends and when access should be blocked.

Full account visibility
Every account must be assigned to a specific identity or accountable owner. If a system cannot be managed automatically, a traceable task must be created with a deadline and a designated owner.

Removal of all forms of access
Disabling the primary account is not enough. Depending on the environment, sessions may need to be terminated, tokens invalidated, VPN access revoked, and privileged permissions removed.

Verification of the outcome
The process does not end when a request is sent. It ends when it has been verified that the target system actually carried out the change. At the same time, a centralized record should be created automatically for each step, showing what was removed and when.

Access and Identity Do Not Always End at the Same Time

Offboarding rules may specify that access is terminated immediately while the identity and related data remain retained for a limited period. A grace period provides time for data handover, completion of ongoing processes, or preservation of necessary relationships.

Once this period ends, the identity may be deleted or pseudonymized. During pseudonymization, direct identifiers such as a name, personal email address, or username are replaced with a technical identifier. The technical identity and necessary relationships remain preserved. This allows the organization to reduce the amount of personal data retained for inactive identities while maintaining continuity.

If the person later returns to the organization, their current information can be linked to the original identity and existing records instead of creating a duplicate identity. This approach is used, for example, at universities, where it helps preserve continuity when a student continues into another program or when a faculty member returns after a period away.

External Users Require Special Attention

External identities, including accounts belonging to consultants, vendors, or guests, are often not recorded in the HR system in the same way as employee identities and frequently do not have a clearly defined end date. Every external identity should therefore have an internal owner, a documented purpose, and an expiration date.

Any extension should be subject to recertification – in other words, a new confirmation that the access is still needed. Access must not remain active simply because no one reported that the project had ended.

Offboarding Must Be Verifiable

A well-designed IAM process separates three points in time:

  1. termination of access rights;
  2. temporary retention of the identity and necessary data;
  3. deletion or pseudonymization of the identity.

This means the organization does not have to choose between two extremes: deleting everything immediately or leaving the account active. Access can be terminated right away, while the identity itself can continue to be managed according to operational, audit, and legal requirements.

At Orchitech, we help connect these steps into a single automated and verifiable process – including checks that confirm the changes were actually carried out in the target systems.

The first step can be simple: choose an employee, student, or external user who recently left. Can you demonstrate that all of their access was revoked on time?