Said It Here

Tracking down unmanaged SaaS accounts when an employee leaves

Central SSO cuts off many access points, but employees often leave behind a messy tail of separate credentials, service portals, API tokens, and rogue accounts created without lifecycle integration. This leaves sysadmins hunting down unmanaged services by hand instead of fully securing offboarding in one place.

What people tried

Every workaround mentioned in the threads below. We haven’t tested any of them — and nobody here is claiming they worked.

  1. 1
    Conducting manual account audits
  2. 2
    Notifying individual service owners to confirm closures
  3. 3
    Chasing down non-SSO apps and separate credentials manually
  4. 4
    Block user creation of shared booking pages
  5. 5
    Restrict creation privileges using an Exchange policy and require support tickets
  6. 6
    Perform periodic quarterly audits to identify and delete orphaned accounts

In their words

Unedited, grouped by where they were said, most upvoted first within each place, each linked to the thread it came from.

r/sysadmin4 people · September 2026

“SSO cuts off a lot, but the messy tail is usually SaaS accounts with separate credentials, service/vendor portals, API tokens, and accounts without proper lifecycle integration.”source ↗

Gorka-Grenier · r/sysadmin · 1 upvotes

“I had companies tieing VPN to SSO, I had some which did not.”source ↗

T_Thriller_T · r/sysadmin · 1 upvotes

“And when you get an alert that a new user account named “Test test” or “For Sarah” you can look here first instead of freaking out like I did.”source ↗

sparkyflashy · r/sysadmin · 1 upvotes

“Same. A salesperson, not having any idea what they're doing, and ended up creating three new booking pages.”source ↗

ADynes · r/sysadmin · 1 upvotes

Where this came up

People with this problem also raised