Orphaned Accounts
An orphaned account is a user or system account that stays active even though it no longer has an active owner, often because the person who used it has left the organization or changed roles. Because no one is responsible for it, the account can retain access to applications and systems without anyone monitoring or managing it. These lingering accounts create security risk that a governance-focused security leader would typically flag for cleanup.
An orphaned account is a digital identity that retains access entitlements to applications, systems, or networks without a valid, active owner. This commonly occurs when a human identity persists after an employee departs or changes roles, or when a non-human identity (NHI) such as a service account, API key, or machine credential can no longer be reconciled to a responsible owner or corresponding authoritative record. In identity governance tooling, an account may be classified as orphaned when the system is unable to match it to a person or to a corresponding account in a primary source of identity, leaving the entitlement active but unattributed and typically outside normal lifecycle controls such as access reviews, deprovisioning, and recertification.
Why it matters
Orphaned accounts represent a persistent gap in an organization's attack surface because they retain valid access entitlements while sitting outside the normal controls that would otherwise govern them. When an account has no active owner, it typically falls out of scope for access reviews, recertification, and deprovisioning, which means credentials to applications, systems, or networks may remain usable long after any legitimate business need has ended. An attacker who compromises such an account often faces little resistance, since no one is monitoring its activity or expecting it to be used.
The risk is not limited to former employees. Non-human identities such as service accounts, API keys, and machine credentials can become orphaned when they can no longer be reconciled to a responsible owner or an authoritative record. These identities frequently hold standing access and may not be tied to individual logins, making their unmanaged persistence particularly difficult to detect and remediate. A governance-focused security leader would typically treat orphaned accounts as a symptom of incomplete identity lifecycle management rather than as isolated cleanup items.
A virtual or fractional CISO engagement often surfaces orphaned accounts when assessing identity governance maturity, but it is important to be precise about scope and accountability. Such a leader typically advises on policy, prioritization, and process design and may direct remediation, but hands-on discovery and deprovisioning generally depend on the client's tooling, staff, and cooperation. Accountability for acting on identified orphaned accounts usually remains with the client organization unless a contract specifies otherwise.
Who it's relevant to
Inside Orphaned Accounts
Common questions
Answers to the questions practitioners most commonly ask about Orphaned Accounts.