Join our Newsletter — 33% off our NHI Course
Home› FAQ› Threats, Abuse & Incident Response› What breaks when organisations leave old VPN access…
Threats, Abuse & Incident Response

What breaks when organisations leave old VPN access in place for former users?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 26, 2026 Domain: Threats, Abuse & Incident Response

Old VPN access becomes a durable entry point if it is not deprovisioned and rechecked. In a breach, attackers can use a stolen or cracked password on an inactive account to bypass initial controls, then move into critical systems. Regular access review and removal of stale access reduce that exposure and limit how far an intruder can move once inside.

Why stale VPN access matters after a user leaves

Leaving a former user’s VPN account active preserves the same remote trust path that was intended for an authorised person. That means the organisation is still accepting a password, token, or other VPN factor as proof of access long after the user relationship has ended, which turns an old account into a live access path instead of a retired one.

Operationally, the problem is not just that the account exists. It is that remote access usually lands inside a trusted network boundary, so an attacker who can authenticate through that stale path may inherit broader reach than a normal internet user would have.

How attackers turn inactive VPN accounts into a foothold

Stale VPN access becomes valuable when an old password is reused, guessed, phished, cracked, or recovered from another breach. If the VPN account was never removed, the attacker does not need to defeat the normal onboarding process, only the login check that remains in place.

Once inside, the intruder can often blend in with expected remote-user traffic, especially if the organisation has weak review of dormant accounts, limited device checks, or broad network reach after authentication. SonicWall VPN Mass Breach via Stolen Credentials is a useful example of how stolen credentials can turn remote access into a mass-compromise path.

What should change in access design and review

VPN access for former users should be treated as a lifecycle control, not a one-time provisioning step. The important question is whether offboarding, periodic recertification, and authentication review are actually tied to employment status, role changes, and access need.

Controls become materially stronger when the VPN is managed as part of a broader identity and access review process, with deprovisioning triggered by HR or contractor exit events, and with explicit attention to shared groups, backup accounts, and legacy remote-access entitlements. Where the VPN remains a high-trust entry point, the organisation should also be measuring whether network reach is broader than the user’s current job requires.

Risk and Threat Considerations

Stale VPN accounts create a durable exposure because they preserve a remote entry point that bypasses normal user lifecycle controls. If the credential is stolen or reused, the attacker may authenticate through an account that the business no longer actively watches, which makes detection and containment slower.

Failure mechanism: The organisation fails to revoke remote-access entitlements at offboarding, so an inactive account remains valid and can still satisfy VPN authentication.

Impact: A former-user account can become an initial access path for unauthorised remote entry, followed by lateral movement toward internal systems, sensitive data, or privileged services.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST Zero Trust (SP 800-207), NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST Zero Trust (SP 800-207)RA-5 — Never Trust, Always VerifyStale VPN access retains a trusted path that zero trust aims to remove.
Recommendation — Limit remote access to continuously verified, least-privilege sessions.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementFormer-user VPN risk depends on revoking or rotating still-valid authenticators.
AC-2 — Account ManagementOffboarding and recurring review are account-management controls directly implicated by stale VPN access.
Recommendation — Revoke and rotate VPN authenticators when users leave. Disable inactive remote-access accounts through timely account lifecycle controls.
CIS Controls v8CIS-5 — Account ManagementInactive VPN access is an account-management failure that CIS Controls addresses directly.
Recommendation — Automate account removal and review for all remote-access identities.
MITRE ATT&CKT1078 — Valid AccountsAttackers commonly abuse still-valid accounts to gain initial access through VPN.
Recommendation — Hunt for login activity using valid but unexpected remote-access accounts.

Practitioner Guidance

What to verify: Confirm that VPN deprovisioning is triggered by authoritative exit events, not by manual cleanup after someone notices the account later. Verify that dormant accounts are included in recurring access reviews, because stale access often survives when reviews focus only on currently active staff.

Common mistake: Treating VPN removal as an IT housekeeping task instead of an identity control. If the organisation can still authenticate a former user, the control has not been retired, only forgotten.

Practitioner takeaway: The main decision is whether remote access is tied to a current trust relationship. If it is not, the VPN becomes an attack surface that should be removed, shortened, or tightly constrained before it is reused by an intruder.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 26, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org