TJ Hoag

The Real Cost of Stale Accounts

TJ
Timothy J. Hoag
IAM & IT Operations Specialist

The account was still active six months after the person left.

This is not an unusual finding. In organizations without automated offboarding tied directly to HR systems, deprovisioning depends on a chain of human actions: someone recognizes that the person has left, someone submits a ticket, someone else actions the ticket, and all of this happens before the access becomes a liability.

That chain breaks more often than most organizations want to acknowledge.

Why Do Stale Accounts Accumulate?

Stale accounts (active credentials belonging to users who no longer have a legitimate reason to hold them) are one of the most consistent findings in any access governance review. They exist in organizations of every size, across every industry.

The root cause is almost never the IAM platform. Both Okta and Entra ID support automated deprovisioning when configured correctly. Active Directory has had account expiration features for decades. The tools exist.

The gap is in the process that should trigger the tool.

HR offboarding does not notify IT. In organizations where HR and IT operate independently, a departure can be processed in the HR system without any automated signal reaching the identity management layer. IT finds out when a manager mentions it, or when the account is flagged in an audit, or not at all.

Manual checklists get skipped under pressure. Offboarding checklists that depend on a departing employee's manager to submit a ticket assume the manager will remember to do so and will have time to do so in the middle of a transition. When things are busy, the checklist waits.

Role changes look like departures but get categorized differently. When an employee moves to a different department or location, their access from the previous role may not be reviewed. They accumulate permissions from multiple roles over time. When they eventually leave, the full scope of their access is not obvious to whoever actions the offboarding ticket.

Access governance is only as strong as the offboarding process feeding it. A tool that can deprovision automatically cannot act if it never receives the signal that someone left.

What Does a Stale Account Actually Cost?

In a low-risk environment with limited data sensitivity, a stale account is primarily a compliance and hygiene problem. It inflates your user count, clutters directory queries, and represents a potential attack surface if the credentials are ever compromised.

In regulated industries, the cost is higher.

In healthcare, an active account belonging to a former employee is a HIPAA exposure. If that account has access to systems containing protected health information (and in most healthcare organizations, even basic clinical staff accounts have some level of access to clinical systems), the account represents an unauthorized access path. If that path is used, or if it cannot be confirmed that it was not used, the organization may face breach notification obligations under the HIPAA Breach Notification Rule.

In higher education, active accounts for former employees who had access to student information systems represent potential FERPA violations if the access is used or cannot be confirmed as unused. The institution has an obligation to ensure that access to student records is controlled and limited to authorized individuals.

In both cases, the stale account is not just a policy violation. It is a potential regulatory event.

What Automated Offboarding Looks Like

Organizations that handle this well have built a direct integration between their HR system and their identity management layer. When a termination is processed in the HR system, it triggers an automated workflow in the IAM platform:

  1. The account is disabled within a defined window (often same-day or next-business-day)
  2. Active sessions are terminated
  3. Application access tokens are revoked
  4. A deprovisioning ticket is generated and assigned to an owner for confirmation
  5. The account is flagged for deletion after a defined retention period

The integration does not require expensive custom development in most modern environments. Both Workday and ServiceNow have native integrations with Okta and Entra ID. The technical capability is available. The gap is usually in the organizational decision to prioritize building and maintaining the integration.

What Front-Line IT Support Can Do

Front-line IT support agents are not typically responsible for offboarding workflows, but they are often the first to encounter a stale account in a ticket context: a former employee's account that is still active, a shared account being used with credentials that belong to someone who has left, or an account flagged by a security tool that appears to belong to a user who should not have access.

When a stale account appears in a ticket:

  • Document the finding clearly: account owner, last known role, apparent date of departure if known
  • Do not take independent action on the account without authorization: disabling or deleting an account without proper authorization creates its own audit and recovery risks
  • Escalate to the account owner, the IAM team, or the security team depending on the organization's defined process
  • Note whether the account has access to regulated data, as this affects the urgency and documentation requirements of the escalation

The visibility that front-line agents have into stale accounts is often the earliest warning that offboarding processes are not working. Escalating clearly and documenting thoroughly is the contribution the support tier can make to a problem that is ultimately a process problem.


This post addresses general access governance principles. It is not legal advice. Organizations with specific HIPAA or FERPA compliance questions should consult qualified legal counsel.

Opportunities
Open to Remote Roles

IAM Analyst, Junior Systems Administrator, or IT Operations Analyst - ideally in healthcare or higher education. Direct hire, W-2.

Discuss opportunities