Secure SaaS Offboarding: Closing Every Access Path
Disabling an employee's primary directory account is necessary, but it may not revoke every path into SaaS data. Active sessions, personal access tokens, OAuth grants, API keys, local synchronizations, shared credentials, unmanaged devices, and accounts created outside single sign-on can survive the first offboarding step.
CISA documented a state-government incident in which a threat actor used a former employee's compromised account. The broader lesson is to verify that access is gone across identity, applications, devices, integrations, and data ownership.
Build offboarding from an access graph
Join HR records, the identity provider, expense data, SaaS discovery, device management, password vaults, code repositories, cloud platforms, and application-owner records. High-risk departures need a coordinated time, while ordinary departures still require a complete and auditable workflow.
Transfer ownership of files, dashboards, automations, service accounts, domains, billing, and vendor contacts before removing the user. Otherwise security teams may preserve access simply because the business cannot identify what will break.
- Disable accounts and revoke sessions, refresh tokens, app passwords, and recovery methods.
- Remove registered devices, SSH keys, API tokens, and OAuth grants.
- Rotate shared secrets the departing user could retrieve.
- Review direct SaaS accounts that bypass corporate single sign-on.
Prove completion and watch the boundary
Record the systems checked, action timestamps, operator, exceptions, and transferred assets. Test that the old identity cannot authenticate and alert on post-departure attempts, reactivated accounts, or activity from unmanaged integrations.
Review the process after mergers, contractor changes, and new SaaS adoption. Offboarding quality declines when the application inventory is stale, so identity lifecycle and SaaS governance must improve together.
Put the lesson into practice
- Identify applications and credentials outside the central identity provider.
- Create risk-based offboarding timing with HR and system owners.
- Revoke sessions and non-password access, not only the directory account.
- Transfer data and automation ownership before deletion.
- Verify revocation and monitor attempted reuse.
Related Outfaze guidance
- Managed multi-factor authentication
- Cloud security monitoring
- Managed detection and response
- Compliance as a Service
- Data risk assessment and DSPM
