Prompt
How do I handle SSO deprovisioning when an employee leaves?
Latest observation
Oct 7, 2026
OpenAI APIWeb search: off
To handle SSO deprovisioning when an employee leaves, the goal is to make sure their access is removed from all apps and systems as quickly and consistently as possible. The best approach is to combine your SSO provider’s lifecycle controls with a clear offboarding process.
Recommended approach
1) Make the identity provider the source of truth
Use your SSO/IdP (Okta, Azure AD/Entra ID, Google Workspace, Ping, etc.) as the central place to:
- disable the user account
- revoke active sessions
- remove group memberships
- trigger downstream deprovisioning via SCIM or workflows
2) Automate deprovisioning where possible
For connected SaaS apps, use:
- SCIM provisioning/deprovisioning to deactivate users automatically
- Group-based access so removing a user from a group removes app access
- Lifecycle workflows to suspend users immediately on termination
This is much safer than relying on manual removal app by app.
3) Define an offboarding process
A standard offboarding checklist should include:
- HR notifies IT/security of termination date and time
- Disable IdP account at the effective time
- Revoke active sessions and refresh tokens
- Remove MFA factors if required by policy
- Deprovision in connected apps
- Transfer ownership of shared resources
- Archive or preserve data per retention policy
- Review privileged access, shared credentials, and service accounts
4) Handle immediately vs. scheduled termination
- Voluntary departure: schedule deactivation for the last working day/time
- Involuntary termination: disable access immediately, then follow up with asset/data recovery steps
5) Don’t forget non-SSO access
Some access may not be controlled by SSO:
- local app accounts
- VPN
- cloud console admin accounts
- GitHub, AWS, GCP, Azure
- SSH keys
- API tokens
- password vault entries
- shared mailbox or group access
These need separate controls or automated cleanup.
6) Revoke credentials and tokens
When someone leaves, also rotate or revoke:
- API keys
- OAuth refresh tokens
- personal access tokens
- certificates
- device trust records
- password manager access
- recovery codes
7) Preserve evidence and data
If needed for legal/compliance reasons:
- archive mailbox and files
- export logs
- retain records according to policy
- avoid deleting data too early
A practical offboarding checklist
- Confirm termination effective time
- Disable IdP account
- Revoke sessions/tokens
- Remove from groups and privileged roles
- Trigger SCIM deprovisioning in apps
- Rotate shared credentials/secrets
- Transfer ownership of documents/repos/resources
- Recover company devices and badges
- Archive required data
- Verify access is fully removed
Good controls to put in place
- HRIS-to-IdP integration
- automated SCIM provisioning
- least privilege and role-based access
- no shared admin accounts
- quarterly access reviews
- logging and alerting on deprovision events
- break-glass accounts stored securely
If you want, I can also give you:
- a sample offboarding policy
- a step-by-step Okta/Azure AD deprovisioning workflow
- or a checklist for IT and HR.