The Staff Member Left. Their SaaS Access Didn’t.
Someone finishes up on a Friday. By Monday, their M365 account is disabled and their laptop is back in the storeroom. Tick, tick — offboarding complete.
Except nobody checked the project management tool they signed up for in Q3. Or the cloud storage folder they shared with a contractor. Or the CRM login they’ve carried over from two roles ago.
Three months later, those sessions are still active. This is how zombie accounts form — not through negligence, but through an offboarding process built around corporate IT assets that no longer reflects how people actually work.
The average organisation now runs more than 100 SaaS applications. Most offboarding checklists were written when there were three.
What a Zombie Account Actually Is
A zombie account is an active login belonging to someone who no longer works for you. The risk is very real.
What makes these accounts particularly dangerous is that they’re valid credentials. There’s nothing to detect — the access was granted intentionally, and the system has no reason to question it. If a former employee walks back in through that door, or their credentials are compromised after they leave, that access is sitting there waiting.
Industry research suggests around half of organisations have discovered former employees still accessing SaaS applications months after their departure. For most, the discovery was accidental — not the result of a deliberate audit.
From an Essential Eight perspective, this is a Restrict Administrative Privileges and application control problem. The ACSC is clear: access should be revoked promptly when no longer required.
The Three Places Access Never Gets Removed
Cloud Storage and Collaboration Tools
OneDrive and SharePoint (via M365) are where zombie access causes the most immediate damage. A departing employee’s licence gets removed from Entra ID, but shared folders, external sharing links, and personal-account shares often go untouched. Microsoft Purview can help surface overshared content — but only if someone is looking.
Project Management and CRM Platforms
Tools provisioned by team leads rather than IT — think project trackers, CRMs, and collaboration boards — rarely appear on any offboarding checklist. A former account executive’s CRM login, or a project manager’s workspace containing company strategy documents, can persist for months without anyone noticing.
The Tools IT Didn’t Know Existed
This is the most dangerous category. These are tools employees signed up for using their work email — a survey platform, an AI writing assistant, a data visualisation tool. Never formally provisioned, never formally revoked. When the employee leaves, the account sits there, attached to a work email address that may now redirect to an IT catch-all.
Running the Zombie SaaS Audit
Step 1: Build Your SaaS Inventory
Start by pulling a list of all SaaS applications connected to Microsoft Entra ID. Cross-reference with billing records, browser extension installs, and email domains showing regular login notifications. For smaller teams without a dedicated identity platform, a 30-minute review of active subscriptions and recent login notifications will surface most high-risk tools.
Step 2: Cross-Reference Against Your Offboarding List
Take the last 12 months of departures and check each name against your SaaS inventory. For each application, ask: does this platform have an admin console? Can you see who is still active? When did this account last log in? Access that is months old and belongs to someone who has left is a zombie — flag it for immediate revocation and document what you find.
Step 3: Revoke, Document, and Set a Review Cadence
Remove the access. Record what was found and when. Then use the audit as the baseline for an offboarding checklist that covers more than the corporate email and laptop. Enforce multi-factor authentication on all remaining active accounts via Entra ID, and schedule a SaaS access review every quarter. That cadence turns a one-time cleanup into a repeatable control — and brings you closer to Essential Eight compliance.
Make Offboarding a Security Process
Zombie accounts cannot be removed if no one is looking for them. Under the Privacy Act and Notifiable Data Breaches scheme, your organisation bears responsibility for data accessed through credentials you failed to revoke.
The SaaS offboarding audit is the starting point. If you’d like help running one and building a repeatable process your team can follow on every exit, get in touch with us or check out our Safe to Scale programme.