Orphaned Accounts

Orphaned Accounts are user or technical accounts that no longer have a responsible owner assigned but remain active and permit access. They typically arise after departures, role changes, reorganizations or migrations, and with technical accounts that were created without a documented responsibility.

Closely related are dormant accounts, which have not been used for a defined period but have remained active. With a dormant account, the owner is usually still known; with an orphaned account, any assignment is missing. Both account types are attractive to attackers because abusive logins are less likely to be noticed there. They are particularly critical when administrative or privileged rights exist, and with technical accounts whose credentials have often never been changed.

Countermeasures start at several points: automated workflows in Identity Lifecycle Management prevent accounts from persisting after a departure, a regular Access Review uncovers remaining accounts, and inactivity rules deactivate unused access after defined periods. Separate thresholds usually apply to technical accounts. Cleaning up orphaned and dormant accounts is a fundamental component of Identity Security.