The employee left in March. Their Microsoft 365 account is still active. With the same permissions as before.
And this isn't the exception. It's the rule.
The problem isn't a lack of effort; it's a lack of process. Offboarding has no clear owner, IT finds out about departures by chance, and the daily grind means account deactivation takes a backseat to current tickets. The result: lingering accounts, accumulating permissions, and an attack surface that grows in silence.

An active account belonging to a former employee is a valid authentication for your tools. Microsoft 365, SharePoint, VPN, CRM: if the account isn't deactivated, everything remains accessible.
The access audits we conduct for our clients regularly reveal that 20% to 40% of accounts are orphaned or inactive, even in well-maintained environments.
An orphan account can be exploited directly by the former owner or compromised by a third party without anyone noticing, precisely because no one is monitoring it.
Orphan accounts are visible. There is another, harder to detect: the active account whose permissions no longer match the user's role.
An employee changes roles. They are given access to the tools for their new scope. The old access rights are rarely removed. After two or three role changes, they have access to HR data, contracts, and financial information that have nothing to do with their current responsibilities. This is what we call privilege creep.
In the event of a contentious departure, a data breach, or an audit, this situation becomes as much a legal problem as a technical one.
Formalize IT offboarding with a shared HR/IT checklist: account deactivation on the departure date, revocation of active sessions, email mailbox transfer, license release, and termination of third-party access.
Explicitly revoke sessions. In Microsoft 365, deactivating an account does not terminate already open sessions: you must revoke authentication tokens separately.
Audit inactive accounts twice a year. M365 reports allow you to identify accounts with no logins for the past 60 days in just a few minutes.
Manage permissions by role groups, not account by account. When someone changes roles, you update their group, and their access updates automatically, in both directions.
Include contractors. Accounts created for temporary projects are the most easily forgotten: set an expiration date or review them at every renewal.
Access management goes unnoticed until it becomes a problem. Then, a contentious departure, an audit, or an incident occurs, and the true state of your environment is revealed.
An orphaned account is a forgotten door left wide open. Accumulated permissions are a key that opens too many rooms. The real question is: do you know which ones?