Join our Newsletter — 33% off our NHI Course
Home› FAQ› NHI Lifecycle Management› What happens when an employee leaves but shadow…
NHI Lifecycle Management

What happens when an employee leaves but shadow IT accounts are not discovered?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 26, 2026 Domain: NHI Lifecycle Management

The organisation can lose control over accounts that remain active after departure. Those credentials may stay usable, be shared with others, or expose company data if the service is breached. In the worst case, information can be taken to a competitor. Even when nothing is stolen, the account remains an unmanaged security liability.

Why undiscovered shadow IT accounts are a departure risk

When an employee leaves, the real problem is not only the official accounts that HR and IT remember to disable. Any shadow it account that was created outside normal provisioning can remain active, still authenticated, and still able to reach company data or connected services. That leaves a gap between personnel offboarding and access removal.

What unmanaged shadow accounts can still do after departure

An undiscovered account can be reused by the former employee, handed to someone else, or left open for anyone who knows the password or token. If the service stores company data, the organisation may also lose visibility into where that data resides, whether it is being synced elsewhere, and whether the account has inherited permissions that were never reviewed.

Because shadow IT often sits outside standard inventory and review processes, the organisation may also miss whether the account is tied to a personal email, a shared mailbox, a contractor-created workspace, or a third-party app connected through SSO. Those hidden connections make the account harder to revoke cleanly and easier to overlook during incident response.

Why the business impact grows after separation

The impact is usually bigger than a single forgotten login. Unmanaged accounts can become long-lived access paths into files, SaaS tools, messaging histories, code repositories, or customer records. If the former employee moves to a competitor, the risk shifts from accidental exposure to potential information leakage, misuse of shared credentials, or continued access through forgotten integrations.

In practice, the account also creates a governance problem: if nobody owns it, nobody can attest to its purpose, prove least privilege, or confirm that it should still exist. That makes the account both an exposure and an audit blind spot, especially when the service is outside central IT control.

Risk and Threat Considerations

Shadow IT accounts are attractive because they bypass normal joiner-mover-leaver controls. Once the employee departs, any surviving credential, session, API token, or linked app can preserve access beyond the organisation’s intended offboarding window, creating a persistence path and a data exposure path at the same time.

Failure mechanism: The account is never discovered, never revoked, or is revoked only in the primary system while the shadow service, linked token, or shared secret remains usable. A shared password, stale OAuth grant, or unattended mailbox can keep access alive even after formal employment ends.

Impact: The organisation can lose control of data, auditing, and accountability, and in a worst case the former employee or another user can continue to access, copy, or exfiltrate information without immediate detection.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementCovers lifecycle control of credentials and tokens that may survive offboarding.
AC-2 — Account ManagementDirectly applies to discovering, disabling, and reviewing accounts after employment ends.
AU-6 — Audit Review, Analysis, and ReportingSupports detecting lingering access or suspicious use of forgotten accounts.
Recommendation — Rotate and revoke surviving authenticators as part of every departure workflow. Inventory, disable, and recertify all accounts tied to departing users. Review logs for post-departure activity and investigate unexpected account use.
ISO/IEC 27001:2022A.5.18 — Access rightsRequires timely removal and review of access rights when roles change or end.
Recommendation — Remove access rights promptly when an employee leaves and verify completion.
CIS Controls v8CIS-5 — Account ManagementAddresses unmanaged accounts and the need to track, disable, and review them.
Recommendation — Maintain an account inventory and disable accounts that no longer have a business owner.

Practitioner Guidance

What to prioritise: Treat shadow IT discovery as part of offboarding, not as a separate cleanup exercise. The highest-risk cases are services with file storage, messaging, code, finance, or customer data, because those accounts can retain both access and content after departure.

What to verify: Offboarding should confirm more than directory deprovisioning. Verify which external SaaS tools, browser-based services, and shared workspaces were used, then check whether credentials, API tokens, delegated access, or sharing links still exist for those services.

Decision rule: If an account cannot be tied to a current business owner and a legitimate operational need, treat it as an unmanaged access path and remove or isolate it before assuming the employee has been fully deprovisioned.

Practitioner takeaway: The control objective is not just “disable the employee,” it is “eliminate every surviving path that still lets the former employee, or anyone else, act through their shadow accounts.”

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 26, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org