A leaver's account is still being used
Either the former employee still has a way in, or somebody else has found an account nobody is watching. The two look identical in the first hour, and they lead to very different conversations, so the first job is telling them apart.
- 01
Disable the account and revoke what it holds
by 10 minexpiresDisable rather than delete, so the audit history and the mailbox survive. Revoke refresh tokens, VPN certificates, app passwords and any API keys the account owns.
- 02
Export everything the account did after the leaving date
by 25 minexpiresSign-ins with addresses, devices and user agents, mailbox and file access, and VPN sessions. Compare the addresses and devices with the ones the person used while employed: a match points one way, a hosting provider or a new country points the other.
- 03
Find out how it could still sign in
by 45 minA missed step in the leaver process, a shared mailbox with its own password, an app password or a legacy protocol that skipped MFA, or a personal device that was never unenrolled. The answer is also the fix for everyone else.
- 04
Establish what was taken or changed
by 75 minDownloads, forwarding rules, sharing links created, and anything sent from the mailbox. If data went to a personal address or a competitor, this has become the insider data removal case, and that playbook takes over.
- 05
Check every other leaver from the past year
by 90 minCompare HR's leaver list with enabled accounts in every identity store, including the ones HR has never heard of: SaaS tools with their own logins, cloud consoles and VPN appliances. One live leaver account usually means there are more.