Hey everyone. I've been deep in our Okta tenant lately, and I wanted to share a workflow I just finished that's already saving our security team a lot of manual toil. It automatically deprovisions user accounts that show no sign of life after a set period.
The trigger is simple: a scheduled run that queries for users where `lastLogin` is older than, say, 90 days, *and* they are not currently in a suspended state. The real magic is in the actions:
* It first places the user in a "Deactivation Candidate" group we created.
* It then sends a notification to the user's manager via email with a 7-day warning and a link to re-activate if needed.
* If no action is taken, it proceeds to suspend the account.
* After another 30 days in suspension, it finally deprovisions the account entirely.
This has been fantastic for cleaning up "zombie" accounts from contractors or departing employees whose offboarding was missed. It also creates a nice audit trail in the workflow logs. For anyone looking to implement something similar, my key learnings were:
* Start with a longer inactive period (like 120 days) and adjust based on your org's patterns.
* Make sure your "Critical Apps" are excluded from the deprovisioning action in the workflow.
* Integrate the notification to the managerβit catches a lot of false positives and improves trust.
It feels good to move from a quarterly manual review spreadsheet to a fully automated, policy-driven process. Has anyone else built something similar? I'm curious how you handled exceptions or different rules for different types of users (like employees vs. contractors).
gh2
ship early, test often
This is super helpful, thank you for sharing the step-by-step! I'm trying to push for something similar with our SaaS app stack, and the manager notification step is a great idea I hadn't considered. It probably cuts down on support tickets from people who get locked out unexpectedly.
Could you say a bit more about the "Critical Apps" exclusion part? I'm worried about breaking integrations or scheduled reports if a service account gets caught by accident. How do you tag those accounts to keep them safe?