ISSUE 18 · 6 MIN READ ·

The leaver who can still log in

Offboarding took back the laptop but never disabled the login, so a former colleague's account is still live. How to find dormant accounts in ten minutes.

Someone left the company a few months ago. It was amicable, the handover went fine, and on their last day you collected the laptop, thanked them, and wished them well. As far as everyone is concerned, they’re gone.

Their account isn’t. The email login still works. The single sign-on that reaches your shared drive, your finance tool, your customer records — still works. Taking back the hardware felt like the end of the story, but the laptop was never where the access lived; the access lives in the account, and nobody disabled the account. It sits there, enabled, with a password the former colleague still knows and may well reuse elsewhere.

This is the quiet failure at its purest: a door that should have been locked on someone’s last day, still standing open weeks or months later, with no one watching it.

Why it stays invisible

A dormant account makes no noise. It isn’t sending email, isn’t logging in, isn’t showing up in anyone’s day. Nothing on your side flashes to say “this person left but their login didn’t.” The absence of activity looks exactly like safety, when in fact it’s the opposite — an unused, unwatched account is the ideal thing for an attacker to quietly borrow, because no real user is around to notice odd behaviour on it.

It stays invisible because offboarding is usually a physical ritual — collect the laptop, the pass, the phone — and the digital half is easy to assume someone else handled. IT thinks the manager disabled the login; the manager thinks IT did; the account belongs to neither of them now, so nobody owns closing it. And the credentials don’t expire on their own. A password a leaver set two years ago keeps working until someone deliberately turns the account off, and if that person also reused the password on a site that later gets breached, an attacker can walk in through a login you forgot you’d left live.

Find it yourself

You can compare who can log in against who actually works here in about ten minutes. Start with your main identity provider — the account that most other tools sign in through.

Google Workspace (admin):

  1. Admin console → DirectoryUsers.
  2. Click the Last sign in column heading to sort by it. Accounts that haven’t signed in for months are your first suspects.
  3. Cross-check the list against your current staff list. Anyone here who no longer works for you is the failure.

Microsoft 365 / Entra ID (admin):

  1. Entra admin centreUsers.
  2. Select Manage view → Edit columns and add the Last interactive sign-in time column, then sort or filter by it for the stalest accounts. One caveat: this column needs a paid Entra ID P1 licence (included in Microsoft 365 Business Premium, but not the cheaper plans) — on the free tier it stays blank, though you can still open each account and read its recent sign-in log.
  3. Compare against your staff list.

No admin access, or a smaller setup? Do it by hand: take your list of every tool the team uses — email, accounting, the CRM, the design tools — and for each one, open its user or members page and read down the names. You’re looking for three things: people who’ve left, shared logins nobody can put a face to, and accounts you simply don’t recognise. Most organisations find at least one leaver still listed on the first pass.

The fix

The fix is to make “disable the login” a definite step owned by a definite person, not an assumption.

Close the accounts you found. For each former colleague, suspend or disable the account rather than deleting it outright at first — suspending cuts off access immediately while preserving their mail and files in case you need to retrieve or reassign anything. Once you’re sure nothing’s needed, you can delete or archive it properly.

Make offboarding include the login. Add a single explicit line to your leaver checklist: disable the account in the identity provider on the last day, named as one person’s job. Because most tools sign in through that one account, disabling it there quietly closes the majority of the doors at once — but check any tool that keeps its own separate login too.

Reset, don’t just rely on the old password. For any account you can’t disable immediately, change the password so the leaver’s known one stops working straight away.

Look again on a schedule. People leave in ones and twos all year, and checklists slip. A quarterly five-minute pass down the user list — comparing logins against the people who actually work here — catches anything that fell through, and keeps the list honest.

None of this is hard. It’s the deciding, once, that switching off the login is part of someone leaving — and then checking now and then that it actually happened.


Diffing your active accounts against who still works here is exactly the review that slips in a busy quarter. AuthScope watches your identity provider and flags dormant and orphaned accounts continuously, so a leaver’s login doesn’t sit open unnoticed. But the manual check above costs nothing but ten minutes — so do that first, today, whether or not you ever automate it.

Check your inbox — confirm and you're in. Latest issue: The Remote Desktop you opened "just for now" is still open.

One real, fixable exposure every week. Free.