Orphaned Account Checker

Orphaned accounts, and why auditors ask

An orphaned account is an account whose owner has left or was never named: a service account set up by someone who moved on, an API key nobody remembers asking for, a leaver's login still enabled, a shared login owned by "the team". It still works, and nobody is asked about it at the access review.

Why auditors ask about them first

An orphaned account is access with nobody to answer for it. The auditor samples leavers against enabled accounts, asks who owns each service account and API key, and asks for the last review of each. SOC 2 CC6.2 expects credentials removed once access is no longer authorised; ISO/IEC 27001 A.5.16 expects identities managed through their whole life cycle; PCI DSS 8.2.5 expects a terminated user's access revoked immediately; CIS Controls 5.1 and 5.5 expect an inventory of accounts and service accounts with an owner. A US issuer's external auditor also samples leavers, shared logins and privileged accounts in the financial systems when testing IT general controls under Sarbanes-Oxley section 404 (named, not quoted), a broad obligation rather than a rule for each account.

The four ways an account becomes orphaned

The clauses behind them

SOC 2 CC6.2Registering and authorising users before issuing credentials

Before system credentials are issued and access is granted, internal and external users whose access the organisation administers are registered and authorised; their credentials are removed once their access is no longer authorised. Points of focus: credentials to protected assets are created only on authorisation from the asset owner or an authorised custodian; access is removed when a person no longer needs it; and credentials are reviewed periodically for people who should not hold them.

What an auditor asks to see: Access request tickets with owner approval for a sample of new users; Termination records reconciled to account disablement dates; Periodic user access review sign-offs with remediation of findings
Where account lists usually fall short: Accounts created without a recorded approval; Leavers retaining active accounts days or weeks after departure; Access reviews performed but inappropriate access not removed
Source: SOC 2 (Trust Services Criteria, common criteria)
ISO/IEC 27001 A.5.16Identity management

Identities are to be managed throughout their whole life cycle. Purpose (stated in ISO/IEC 27002:2022): enables unique identification of people and systems accessing organizational assets and appropriate assignment of access rights. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 5.16.

What an auditor asks to see: Statement of Applicability entry for control A.5.16, showing inclusion or justified exclusion, implementation status and the risks it treats; Identity management procedure covering creation, verification, activation, change, disablement and removal; Evidence that identities are verified against trusted documents before issue; A register of shared identities with the business justification and approval for each; A register of non-human identities (service accounts, machine identities) with segregated approval and an independent oversight record
Where account lists usually fall short: Generic shared accounts exist without documented justification or approval; Service accounts have no owner and no periodic oversight; Identities of leavers remain enabled for weeks because HR notifications are not integrated; The same person holds several identities in one directory, undermining accountability
Source: ISO/IEC 27001:2022 Annex A
PCI DSS 8.2.5Terminated users' access revoked immediately

Access for users who have been terminated must be revoked immediately. The testing procedures check both local and remote access lists for terminated IDs and confirm that any physical authentication factor, for example a token or smart card, has been deactivated or handed back. The guidance explains that a former employee or third party who keeps a working account, or an attacker who takes over an abandoned one, could reach cardholder data. Objective under the customized approach: accounts belonging to terminated users cannot be used.

What an auditor asks to see: HR termination list for the period reconciled against active account lists; Deprovisioning tickets with timestamps relative to termination dates; Remote access (VPN, SaaS, cloud) account listings checked for leavers; Token or smart card return and deactivation log
Where account lists usually fall short: Leavers disabled in the directory but still active in SaaS or VPN systems; Days elapse between termination and account revocation due to manual handoffs; Hardware tokens of departed staff never recovered or deactivated
Source: PCI DSS v4.0
CIS Controls 5.5Establish and Maintain an Inventory of Service Accounts

Keep a register of service accounts that records, at a minimum, the owning department, the date of review and the purpose. Review service accounts on a regular cycle of at least once a quarter to confirm that every active one is authorised.

What an auditor asks to see: Service account inventory with owning department, review date and purpose; Quarterly service account review records; Account management standard naming who owns each service account and requiring quarterly authorisation review; Directory export of accounts flagged as service accounts, reconciled against the inventory with unmatched entries listed; Last four quarterly review sign-offs with disabled or re-justified service accounts recorded per entry
Where account lists usually fall short: Service accounts created by application teams or vendors never entered in the inventory; Owning department still lists a team that was disbanded or a person who left; Quarterly review skipped or rubber-stamped with no account disabled in a year
Source: CIS Controls v8

See the specimen: 40 accounts, 11 nobody ownsThe review template