IT & Cyber Audit
Dormant User Account Cleanup
Identification of inactive, terminated-staff and stale user accounts that should be disabled or removed.
Why dormant accounts are an exploitable backdoor
Inactive, stale and terminated-staff accounts that remain enabled are a standing security exposure and a recurring AGSA IT control finding, because they can be hijacked with no legitimate user to notice. Prompt disabling of accounts on termination is a basic but frequently failed control. AuditPro Core identifies dormant and orphaned accounts so they can be disabled before they are abused.
The Numbers
AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.
Active accounts
9,640
Dormant 90+ days
418
4.3% of accounts
Terminated, still active
73
deprovision now
Disabled this cycle
256
▲ 61 vs prior
Account status breakdown
Accounts flagged for action
| Account | Type | Last login | Action |
|---|---|---|---|
| m.dlamini | Terminated staff | 210 days ago | Disable |
| svc-backup | Service account | Never | Verify owner |
| t.botha | Dormant | 134 days ago | Confirm |
| contractor07 | Expired contract | 98 days ago | Remove |
Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.
Termination and de-provisioning must be linked
An account should be disabled the moment employment ends, which requires HR termination to trigger IT de-provisioning. A gap between the two leaves live credentials for departed staff.
Dormancy is a measurable threshold
Accounts unused beyond a defined period should be flagged and reviewed. Setting and enforcing an inactivity threshold turns a vague risk into an actionable list.
Orphaned accounts have no owner
Accounts with no matching active employee, often shared or service accounts, are the hardest to govern. Reconciling accounts to the HR establishment exposes them.
How AuditPro Core Bridges the Gap
- Inactivity detection: AuditPro Core flags accounts dormant beyond the defined threshold for review and disabling.
- HR reconciliation: accounts are matched to active employees so terminated-staff and orphaned accounts surface.
- Remediation workflow: flagged accounts are routed for disabling with confirmation tracked to closure.
- Audit-ready evidence: the cleanup record demonstrates timely de-provisioning to the AGSA.
Key Takeaways
- Termination should automatically trigger account de-provisioning.
- Define and enforce an inactivity threshold for dormancy.
- Reconcile accounts to the HR establishment to find orphans.
- Documented cleanup answers a common IT control finding.
See This on Your Own Data
AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.
