SaaS Access Audits: Finding Hidden Accounts Former Employees Still Use

Getting your Trinity Audio player ready...

An employee leaves on Friday. By Monday, their email account is disabled, their laptop has been collected, and their name has been removed from the company directory. But what about the project management platform they signed up for last year? The cloud storage folder they shared with an outside contractor? The CRM account they still had from a previous role?

In many organizations, nobody checks. Months later, those accounts may still be active and accessible. This is how zombie SaaS accounts are created. Not because someone intentionally ignored security, but because modern software usage has outgrown traditional offboarding processes.

Most employee departure checklists focus on company devices and core systems while overlooking the growing number of cloud applications employees use every day. With organizations now relying on hundreds of SaaS applications, it’s easy for access to slip through the cracks.

Understanding the Risk of Zombie SaaS Accounts

A zombie account is any active user account that belongs to a former employee. The term may sound harmless, but the security implications are significant. Unlike suspicious login attempts or external attacks, zombie accounts use legitimate credentials that were originally approved by the organization. As far as the application is concerned, nothing appears unusual.

If a former employee still has access, or if their credentials become compromised after they leave, the door remains open. Research shows that nearly half of organizations have discovered former employees still accessing SaaS applications months after their departure. In many cases, the issue was uncovered accidentally rather than through a planned security review.

The Most Common Places Zombie Access Hides

File Sharing and Cloud Storage Platforms

Services such as Google Drive, Microsoft OneDrive, and Dropbox are among the most common sources of lingering access. These platforms often accumulate shared folders, guest permissions, and file links over time.

Employees may share documents with personal email accounts, collaborate with contractors, or create links that remain active long after a project ends. While the employee’s primary account may be disabled, those shared resources often remain untouched. As a result, access can continue long after someone has left the organization.

Customer Management and Productivity Applications

Applications such as Salesforce, HubSpot, Asana, Monday.com, Jira, and Notion frequently operate outside of traditional IT provisioning processes. Department managers and team leaders often create and manage user accounts directly. Because of this, IT may not know the application exists or may not have visibility into who still has access.

A former salesperson may still be able to access customer records in Salesforce, while an ex-project manager could retain access to strategic planning documents stored in Notion. Without regular reviews, these accounts can remain active for months.

Shadow IT and Unapproved SaaS Tools

The most concerning category involves applications IT never knew existed. Employees routinely sign up for software using their company email address. These tools might include AI assistants, survey platforms, design software, analytics solutions, or specialized industry applications.

Since these accounts were never formally approved, they are rarely included in offboarding procedures. When the employee leaves, the account stays active and continues to exist outside the organization’s visibility.

How to Conduct a SaaS Access Audit Successfully

Step 1: Create a Complete SaaS Inventory

Begin by identifying all SaaS applications connected to your identity platform, such as Microsoft Entra ID, Google Workspace, or Okta.

Next, compare that list against:

  • Software subscriptions
  • Expense reports
  • Browser extensions
  • Login notification emails
  • Department-managed applications

Many organizations are surprised by how many cloud applications are actually in use. Organizations that maintain visibility into SaaS applications are better positioned to manage access, reduce security risks, and support cybersecurity best practices outlined by the National Institute of Standards and Technology (NIST).

According to recent SaaS security research analyzing millions of user accounts, organizations collectively use tens of thousands of unique SaaS applications, with the vast majority operating outside direct IT management.

For smaller businesses without a centralized identity platform, reviewing active subscriptions and recent login activity can uncover many of the highest-risk applications.

Step 2: Compare SaaS Access Against Employee Departures

Review all employee departures from the past 12 months and compare those names against your SaaS inventory.

For each application, ask:

  • Does the platform provide administrative visibility?
  • Can you identify active users?
  • When was the last login recorded?
  • Does the account belong to a former employee?

Any account associated with a departed employee should be investigated immediately. Document every finding and identify accounts that require revocation.

Step 3: Remove Access and Establish Ongoing Reviews

Once zombie accounts have been identified, revoke access immediately. Document what was discovered, when it was removed, and which systems were affected.

Use those findings to strengthen your employee offboarding procedures and ensure SaaS applications are included alongside email accounts, laptops, and mobile devices.

Moving forward, require multi-factor authentication (MFA) for all active accounts and schedule quarterly SaaS access reviews. Regular reviews help transform a one-time cleanup effort into an ongoing security control.

Using a SaaS Access Audit to Strengthen Employee Offboarding

Zombie accounts cannot be eliminated if they are never reviewed. As organizations continue adopting new cloud applications, former employee access becomes increasingly difficult to track without a structured process.

A SaaS access audit provides a practical starting point for identifying hidden risks, improving visibility, and ensuring departing employees no longer have access to company data.

If you’re concerned about lingering SaaS access in your environment, now is the time to review your offboarding process and close the gaps before they become a security incident. Contact Twintel today.

Twintel Logo
+ posts

Twintel has grown into an expansive, full team of IT services professionals, acting as the outsourced IT department of non-profits, small to mid-size businesses, and enterprise-level corporations in Orange County, across California, and nationally.

Today, it’s the strength and deep expertise of the Twintel team that drives positive outcomes for clients. Each of the support staff, technicians, and engineers works diligently each day to make sure that the companies served have the seamless, secure, and stable IT environments needed to allow them to pursue their organizational objectives.

Learn more...