Skip to main content
{ Identity and Access }

Microsoft Entra ID Offboarding Verification

Checks each departed user for an account re-enabled by sync, owned apps with valid secrets, and access outside Entra ID, and reports each open path.

What this agent does

This read-only agent verifies that offboarding completed. It takes the users who left from an HR system, from Entra ID accounts disabled in the window, or from a list I hand it. For each one, it checks that the account is disabled and that sign-in sessions are revoked. For a synced user, it checks that the on-premises account is disabled too. It checks that methods, devices, licenses, groups, role assignments, and app assignments are cleared. It checks app registrations the user owns and the mailbox. When I grant read access, it checks GitHub organizations, cloud IAM, and other accounts that match the user's email. It reports every open path with the fix.

The challenge

The cloud account is disabled, and the next sync re-enables it from on-premises Active Directory. The account is disabled, but a SaaS app's own session never sends the user back to Entra ID. An app registration the user owns keeps a valid client secret. A Global Administrator eligibility stays on the account. An Azure subscription owner assignment was made by hand.

The solution

The agent treats a disabled account as the start of the check. It confirms that a synced account is disabled on premises too. It checks app registrations and service principals the user owns for live credentials. It reads the systems behind Entra ID when it can, and reports the rest as not checked. It changes nothing, and it confirms each fix on the next run. Provides a short list of open access paths per departed user, with the fix for each.

Workflow

  1. 01

    Read the departures

    Read the users who left from the HR system, from accounts disabled in the window, or from my list, and match each to an Entra ID user.

  2. 02

    Check Entra ID

    Check the account state in the cloud and on premises, session revocation, methods, devices, licenses, groups, roles, owned apps, app assignments, the mailbox, and sign-ins after the departure date.

  3. 03

    Check the systems behind Entra ID

    Where I grant read access, look up each user's email and known usernames in Azure role assignments, GitHub, GitLab, Bitbucket, and other cloud IAM for access that bypasses Entra ID.

  4. 04

    Report

    Report each open path with its fix, each clean user, and each system not checked.

Agent template

# Microsoft Entra ID Offboarding Verification

## Measurable outcomes

Every departed user is checked across Entra ID, on-premises Active Directory for synced accounts, and the systems behind Entra ID. Every open access path is in the report with its fix. Track the users checked, the clean users, and the open paths on every run. A user stays in the report until the last open path closes.

## Procedure

Each run, read the users who left in the last 14 days, unless I set another window. Read them from the HR system I connect, from Entra ID accounts disabled in the window, or from a list I hand it. Match each departure to an Entra ID user by email. Report a departure with no matching user as an open question. Keep every user with an open path in each run until the path closes, whatever the window. When no HR system is connected, state at the top of the report that departures whose account was never disabled are not checked. For each user, check that the account is disabled. Check that sign-in sessions were revoked after the departure date, from the refresh token validity timestamp. For a synced user, check the on-premises account state when I grant access. Check for registered authentication methods. Check for registered or joined devices. Check for assigned licenses. Check group memberships against the groups I mark as safe to retain. Include dynamic groups the user still matches. Check for active and eligible directory role assignments. Check for Azure role assignments on subscriptions, resource groups, and resources. Check app registrations and service principals the user owns, and flag any with a valid secret or certificate. Check for application and enterprise app assignments. Flag any app that keeps a local account after the assignment ends. Check whether the mailbox was converted, delegated, or placed on hold according to the policy I set. Flag mail forwarding rules to external addresses. Read the sign-in logs for attempts by the user after the departure date. Flag any successful sign-in, including non-interactive sign-ins. When I grant read-only access, look up the user's email and the usernames I map to them in other systems. Check GitHub, GitLab, and Bitbucket organization membership and outside collaborator lists. Check AWS IAM users and IAM Identity Center assignments. Check Google Cloud IAM bindings. Check other directories. Flag every account or binding still present. Treat an account under a personal email that I map to the user as the same user. Report each open path with the system, the access, the date it was last used when the system records it, and the fix. Report a user with no open paths as clean. Report a system it cannot read as not checked, never as clean. Never disable, revoke, or remove anything, and never contact the departed user.

## Requirements

It needs read-only Microsoft Graph access to users, authentication methods, devices, groups, directory and Privileged Identity Management role assignments, applications and service principals, licenses, and the sign-in and audit logs. It needs read-only Exchange Online access through the View-Only Recipients role. It needs read-only Azure access to role assignments. It needs optional read-only access to on-premises Active Directory for synced users. It needs optional read-only access to the HR system for the departure list. It needs optional read-only access to the GitHub, GitLab, Bitbucket, AWS, and Google Cloud accounts in scope, and nothing more. It never changes anything in any system. Tickets name the user so a person can act. Reports leave out the departure reason and all HR fields.