A leaver's account is still being used

Either the former employee still has a way in, or somebody else has found an account nobody is watching. The two look identical in the first hour, and they lead to very different conversations, so the first job is telling them apart.

Trigger. Sign-ins, mailbox activity or VPN sessions on the account of somebody who has left, or of a contractor whose engagement has ended.

The first 90 minutes2 of 5 expire
045 min90
  1. 01

    Disable the account and revoke what it holds

    by 10 minexpires

    Disable rather than delete, so the audit history and the mailbox survive. Revoke refresh tokens, VPN certificates, app passwords and any API keys the account owns.

  2. 02

    Export everything the account did after the leaving date

    by 25 minexpires

    Sign-ins with addresses, devices and user agents, mailbox and file access, and VPN sessions. Compare the addresses and devices with the ones the person used while employed: a match points one way, a hosting provider or a new country points the other.

  3. 03

    Find out how it could still sign in

    by 45 min

    A missed step in the leaver process, a shared mailbox with its own password, an app password or a legacy protocol that skipped MFA, or a personal device that was never unenrolled. The answer is also the fix for everyone else.

  4. 04

    Establish what was taken or changed

    by 75 min

    Downloads, forwarding rules, sharing links created, and anything sent from the mailbox. If data went to a personal address or a competitor, this has become the insider data removal case, and that playbook takes over.

  5. 05

    Check every other leaver from the past year

    by 90 min

    Compare HR's leaver list with enabled accounts in every identity store, including the ones HR has never heard of: SaaS tools with their own logins, cloud consoles and VPN appliances. One live leaver account usually means there are more.