A B C D E F G H I J K L M N O P Q R S T U V W Z
Da Dc De Di Dl Dm Dn Do Dr Du Dy
Dec Dee Def Del Den Dep Des Det Dev

Deprovisioning

Deprovisioning is the process of removing or disabling identities, accounts, credentials, and access when they are no longer needed. It matters because old accounts and leftover permissions often become quiet but dangerous attack paths.

What is Deprovisioning?

Deprovisioning usually happens when someone leaves an organization, changes roles, a vendor engagement ends, a service account is retired, or a system is decommissioned. Good deprovisioning reduces stale access and closes unnecessary trust relationships.

What Deprovisioning Commonly Includes

Common steps include disabling accounts, revoking tokens, removing group memberships, rotating related secrets, terminating sessions, and documenting ownership changes.

Deprovisioning vs. Provisioning

Provisioning grants and sets up access. Deprovisioning removes access that should no longer exist.

Frequently Asked Questions

Why is deprovisioning important?

Because forgotten accounts and old credentials are often easier for attackers to abuse than well-managed active identities.

Does deprovisioning only apply to employees?

No. It also matters for contractors, vendors, applications, service accounts, devices, and other non-human identities.

Related Cybersecurity Terms

George Mutune

I am a cyber security professional with a passion for delivering proactive strategies for day to day operational challenges. I am excited to be working with leading cyber security teams and professionals on projects that involve machine learning & AI solutions to solve the cyberspace menace and cut through inefficiency that plague today's business environments.