The Ticket Is Closed. Is the Work Done?

About This Post

By Greg Margolin · September 4, 2026

An employee leaves on Friday. HR records the departure, IT disables the main company account, and the offboarding ticket is closed. Everyone moves on.

But the vendor portal has its own login. The engineering tool keeps local accounts. A shared reporting workspace still lists the departed employee as its owner. None of that was touched, because none of it hangs off the main account.

A quick word on terms. Your identity provider (IdP), such as Microsoft Entra ID or Okta, is the central system people sign in through. Single sign-on (SSO) lets them use that one sign-in for many applications. Deprovisioning means removing an account and its access. An orphaned account is one that no longer belongs to an active person. The whole process of setting people up, changing their access and removing it is often called joiner–mover–leaver (JML).

Why Disabling One Account Isn't the Whole Job

Sessions outlive the switch. Microsoft's own guidance notes that disabling an Entra ID account doesn't instantly end every session. Access tokens are valid for an hour by default, and applications that issue their own session cookies manage those sessions themselves. Microsoft's recommended steps include revoking sessions and having a manual process for applications that aren't automatically deprovisioned.

Automatic deprovisioning only reaches what's connected. Most identity providers use a standard called SCIM (System for Cross-domain Identity Management) to create and remove accounts in other applications. It works well, but only for applications that support it and have been set up for it. Even then, a departed user is often marked inactive in the target application rather than deleted.

Some access was never tied to a person's sign-in at all. Local administrator accounts, shared credentials, API tokens and vendor portals with separate passwords sit outside the identity provider entirely.

What Good Looks Like

The security frameworks agree on the basics. NIST SP 800-53, the U.S. government's catalog of security controls, calls for disabling access and revoking credentials within a defined time when someone leaves. The CIS Controls (from the Center for Internet Security) call for revoking access immediately on termination, disabling dormant accounts after 45 days, and validating the list of accounts at least quarterly.

In practice, that means:

  • An inventory of where access lives, including applications that don't use single sign-on.
  • A checklist per application, with a named owner and a defined removal step.
  • Confirmation, not just requests. Each removal is verified, and failures stay open until they are resolved.
  • Regular access reviews that catch whatever slipped through.

How GQP Helps

Our Fractional Agentic AI Team builds and runs access lifecycle workflows across your systems. When someone joins, moves or leaves, the workflow works through every application in scope, carries out the steps it is authorized to perform, routes the rest to the right owner, and confirms each one. Uncertain matches and exceptions go to your people. The result is a short completion report: what is done, what is waiting, and who needs to act.

How You'd Know It's Working

  • Every departure has a completion record, not just a closed ticket.
  • Access reviews find fewer accounts nobody can explain.
  • Application owners get clear, specific requests instead of chasing emails.
  • Auditors get evidence without a special project.

Ready to Talk?

Start with a 15-minute conversation. We'll ask how offboarding runs today and where access tends to linger, then tell you honestly whether AI would help.

Prefer the phone? Call us at 888-477-5580, or 888-GQP-5580. Alternatively, complete our Contact Us form here.

Sources: Microsoft Learn, “Revoke user access in an emergency in Microsoft Entra ID” and “How application provisioning works in Microsoft Entra ID.” Okta Help Center, “Deactivate a user account.” IETF RFC 7643 and RFC 7644 (SCIM 2.0), September 2015. NIST SP 800-53 Rev. 5, controls AC-2 (Account Management) and PS-4 (Personnel Termination). CIS Critical Security Controls v8.1, Controls 5 and 6.