Orphaned Account
An active account with no valid owner, typically left behind after someone leaves or changes roles. A common audit finding and a soft target for attackers.
Orphaned accounts are dangerous precisely because they are boring: no owner means no one notices the login, no password change, and no MFA enrollment. They cluster in the systems outside SSO, in local admin accounts on appliances, and in service accounts created for a project that ended. Reconciling every account against an authoritative owner is the only reliable way to find them.
See also: deprovisioning, what is IGA, joiner-mover-leaver, access certification
Related on Start with Identity
- GlossaryProvisioning
Creating user accounts and entitlements in target systems. Modern provisioning is automated via SCIM or vendor APIs, triggered by HR system events. Manual provi
- GlossaryCIEM
Cloud Infrastructure Entitlement Management. Tools that discover and right-size identities and permissions across AWS, Azure, and GCP, reducing excessive and un
- GlossaryEntitlement
A specific permission or right an identity holds over a resource. Governance and CIEM exist to keep entitlements understood, justified, and minimal. Entitlement
- BlogServiceNow closes its Veza acquisition at about 1.2 billion dollars
Announced in December 2025 and closed on 2 March 2026, substantially in cash. Veza, valued at 808 million dollars in its Series D, now supplies the permission g
- TechniqueOrphaned account abuse
An account left active after its owner departed or its purpose ended draws no attention from anyone, because no one owns it, no one expects a login from it, and
- BlogAbbott investigates two incidents, one starting with a vished Entra account
Abbott confirmed unauthorized access to legacy Exact Sciences systems after a mid-June vishing attack compromised a Microsoft Entra single sign-on account. Shin