IT Glossary
An orphaned account is an active account with no owner. Learn why orphaned accounts are a security risk and how clean deprovisioning eliminates them.
July 3, 2026
An orphaned account is an active user account that no longer has a legitimate owner, typically left behind when an employee leaves or changes roles and deprovisioning is incomplete. Orphaned accounts are a major security risk and a frequent audit failure, because they provide unmonitored access that attackers and former insiders can exploit.
Orphaned accounts are dangerous for three reasons. They provide unmonitored access that no one owns or watches. They enlarge the attack surface as a live entry point with valid credentials. And they cause audit failures, because active accounts without owners fail reviews.
Months after an engineer leaves, their admin account in a small analytics tool is still active, never deprovisioned because that app was outside SSO. It is an orphaned account: a real breach risk and a guaranteed audit finding. Eliminating orphaned accounts requires complete, automated deprovisioning across every app, including the long tail that manual offboarding forgets, plus regular access reviews to catch any that slip through.
An active account with no legitimate owner, usually left behind after incomplete deprovisioning when someone leaves or changes roles.
Because they provide valid, unmonitored access that attackers or former insiders can use, and no one is responsible for watching them.
With complete, automated deprovisioning across every app (including non-SSO and long-tail tools) backed by regular access reviews.