Join our Newsletter — 33% off our NHI Course

Why do orphaned and dormant accounts create outsized risk in universities?

Orphaned and dormant accounts create risk because universities have constant churn across students, faculty, and staff, which makes manual access maintenance hard to sustain. When accounts are not promptly removed or reviewed, they can retain access without an active owner, giving attackers an unmonitored path into systems. The problem grows as roles, classes, and employment status change throughout the year.

Why orphaned and dormant accounts become outsized risk in higher education

Universities are unusually exposed because account populations change constantly, but their access paths often do not. Orphaned accounts can outlive the person who created or sponsored them, and dormant accounts can remain quietly usable long after the owner stops logging in. That combination creates hidden access that is easy to miss during routine operations.

The risk is not just the presence of old records. It is the mismatch between rapid turnover and slow review, which means access can remain active through semester breaks, staffing changes, graduations, sabbaticals, and vendor relationships. At scale, the university’s attack surface becomes larger than its apparent user list.

Universities also tend to have mixed environments, with student systems, research platforms, departmental apps, cloud services, and third-party tools all carrying different ownership and offboarding practices. A dormant account in one system may still reach another through shared credentials, forgotten integrations, or weakly enforced access boundaries.

Where the control failure usually starts

The underlying failure is lifecycle governance, not a single technical bug. Accounts are often created for a legitimate purpose, then left behind when a student leaves, a contractor finishes, a staff member changes roles, or a project ends. If no one owns periodic review, the account survives because nothing in daily operations forces its removal.

That matters because dormant access is hard to notice and easy to underestimate. A rarely used account can still authenticate, still inherit old permissions, and still provide a quiet path into email, file stores, research data, or administrative systems. In practice, the risk rises when access review depends on local memory rather than authoritative lifecycle events.

The strongest warning sign is not simply age, but authority without activity. If an account has been inactive, has unclear sponsorship, or was tied to a role that no longer exists, it should be treated as a potential control gap until someone can verify why it still exists and whether it still needs access.

Risk and Threat Considerations

Universities have a large concentration of accounts with uneven ownership, which makes orphaned and dormant access attractive to attackers looking for low-noise entry points. Once a stale account is found, it may bypass normal scrutiny because it appears legitimate, already has trust relationships, and may not trigger immediate user complaints.

Failure mechanism: Offboarding gaps, slow recertification, and weak ownership allow accounts to remain active after the original user, sponsor, or business purpose has gone away. Attackers then exploit that residual access for persistence, unauthorized data access, or lateral movement.

Impact: The result can be undetected compromise of student, research, or administrative systems, with broader exposure when the dormant account holds elevated permissions or reaches shared services. NHIMG research on non-human identity risk shows how common control gaps can become severe, including only 20% of organisations having formal processes for offboarding and revoking API keys, which is a useful signal for how easily stale access can persist when lifecycle management is weak.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST CSF 2.0 set the technical controls, while DORA, NIS2 and PCI DSS v4.0 define the regulatory obligations.

Framework Control / Reference Relevance
CIS Controls v8 6 — Access Control Management Orphaned and dormant accounts are access-control and lifecycle problems.
5 — Account Management Universities need account inventories and offboarding to remove stale access.
Recommendation — Review, revoke, and disable stale accounts on a defined schedule. Maintain authoritative account ownership and promptly remove obsolete accounts.
NIST CSF 2.0 PR.AA — Identity and Access Management Stale accounts reflect weak identity lifecycle and access governance.
DE.CM — Continuous Monitoring Dormant accounts require monitoring to detect unexpected use and exposure.
Recommendation — Enforce account lifecycle controls and periodic access review. Continuously monitor for inactive accounts that still authenticate or access data.
DORA PR.OT — Operational Resilience Testing Stale account exposure affects operational resilience and control assurance.
Recommendation — Test offboarding and access-revocation processes under realistic change scenarios.
NIS2 GOV — Cybersecurity risk-management measures Access governance and account hygiene are part of required risk management measures.
Recommendation — Implement lifecycle controls that ensure stale accounts are revoked without delay.
PCI DSS v4.0 7 — Restrict access by business need to know Dormant accounts often retain access beyond current business need.
8.6 — System and application accounts with interactive login Universities often fail where long-lived system or service accounts remain usable.
Recommendation — Remove access when the business need ends and recertify remaining access. Control and review all accounts with interactive or persistent access.

Practitioner Guidance

What to verify: Use an ownership test before trusting any long-lived account, ask who can approve its continued existence, what business function it still serves, and what event will revoke it. If that answer is vague, the account should move into a review queue rather than remaining implicitly approved.

What to prioritise: Start with accounts that combine inactivity and privilege, because those create the best attacker payoff and the worst detection gap. Dormant accounts with access to email, file sharing, directory services, research data, or finance systems deserve faster review than low-impact accounts with no meaningful reach.

What good looks like: Good practice is an inventory that ties each account to a current owner, a current purpose, and a current expiration or review trigger. Where institutions can produce that evidence quickly, dormant access is being managed as a lifecycle problem, not discovered only after an incident.

Practitioner takeaway: In universities, the real danger is not merely account age, it is unclaimed access that keeps working after the person, role, or project has changed.