Tracking down unmanaged SaaS accounts when an employee leaves
Central SSO cuts off many access points, but employees often leave behind a messy tail of separate credentials, service portals, API tokens, and rogue accounts created without lifecycle integration. This leaves sysadmins hunting down unmanaged services by hand instead of fully securing offboarding in one place.
What people tried
Every workaround mentioned in the threads below. We haven’t tested any of them — and nobody here is claiming they worked.
- 1Conducting manual account audits
- 2Notifying individual service owners to confirm closures
- 3Chasing down non-SSO apps and separate credentials manually
- 4Block user creation of shared booking pages
- 5Restrict creation privileges using an Exchange policy and require support tickets
- 6Perform periodic quarterly audits to identify and delete orphaned accounts
In their words
Unedited, grouped by where they were said, most upvoted first within each place, each linked to the thread it came from.
“SSO cuts off a lot, but the messy tail is usually SaaS accounts with separate credentials, service/vendor portals, API tokens, and accounts without proper lifecycle integration.”source ↗
“I had companies tieing VPN to SSO, I had some which did not.”source ↗
“And when you get an alert that a new user account named “Test test” or “For Sarah” you can look here first instead of freaking out like I did.”source ↗
“Same. A salesperson, not having any idea what they're doing, and ended up creating three new booking pages.”source ↗
Where this came up
People with this problem also raised
- 3How to catch all account dependencies during user offboarding
- 4How to track service retirements across multiple client tenants
- 2Automated notification emails only show IDs instead of client names
- 3Client tries to reverse cancellation during offboarding
- 2Are there travel accountant jobs like travel nursing?
- 3How to find a lost financial account with no paperwork