Schools should recertify and retire accounts whenever tools are no longer used for active teaching, when a role changes, or when an application is replaced. Dormant logins are still part of the attack surface, even if staff forget they exist. Access reviews should cover these accounts as part of normal lifecycle governance, not as an exception.
When should schools recertify or retire staff access?
Schools should treat staff access as a lifecycle control, not a one-time onboarding task. Recertify or retire accounts when teaching tools are no longer active, when staff move roles, and when applications are replaced. The practical question is whether the account still reflects a current business need, because unused access remains part of the attack surface.
What makes an account due for review or removal?
The strongest trigger is a change in use, not simply a calendar date. If a platform is no longer needed for lessons, administration, or assessment, the account should be reviewed for removal or reduced scope. The same applies when a teacher becomes a coordinator, leaves a department, or no longer needs the same systems.
Schools should also recertify accounts after system changes, such as an LMS replacement, a migrated student records platform, or a new communication tool. Old access often survives because teams focus on the new system and forget the legacy one. That is where dormant accounts turn into hidden dependency risk and unnecessary privilege.
How should schools manage dormant staff accounts over time?
Recertification works best when it is tied to access governance, not emergency cleanup. A good process maintains an inventory of staff accounts, their owning department, and the business reason they exist. When that reason disappears, the account should be disabled, retired, or moved to a controlled archive state rather than left active by default.
The review should cover both directly used staff logins and any accounts that support classroom software, departmental tools, or third-party services. Schools often inherit accounts through procurement or device setup, so the account owner is not always obvious. That is why IAM and IGA Basics matter here: they frame access review as part of normal identity lifecycle governance, including joiner-mover-leaver change and entitlement cleanup.
Where schools run formal review cycles, the goal should be to confirm current need and eliminate stale access before it becomes an audit or incident problem. Access Reviews and Certification Guide is especially relevant because it emphasizes removing access, not just collecting approvals, which is the right model for staff accounts that quietly outlive their purpose.
Risk and Threat Considerations
Unused staff accounts are attractive because they often have valid credentials, familiar naming patterns, and weak monitoring. If an account is never retired, it can become a low-friction entry point for lateral movement, abuse of inherited permissions, or persistence after role change. The risk rises when passwords are reused, MFA is absent, or the account still reaches systems that matter operationally.
Failure mechanism: A dormant account retains authentication paths and access rights after the business need has ended, so compromise can occur long after the original owner stopped using it.
Impact: Attackers may gain unnoticed access to school systems, exposed data, or administrative functions, and defenders may miss the account because it no longer appears active in day-to-day operations.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Staff account retirement depends on managing credentials through their lifecycle. |
| AC-2 — Account Management | The question is about reviewing, disabling, and retiring staff accounts over time. | |
| AC-6 — Least Privilege | Recertification should trim access to the minimum needed for current staff duties. | |
| Recommendation — Rotate or retire credentials promptly when staff access is no longer needed. Review accounts regularly and disable or remove those without a current business need. Reduce entitlements to the minimum required for the staff member's current role. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Schools need a formal access-control rule for recertifying and removing stale staff access. |
| A.5.18 — Access rights | The topic directly concerns when access rights should be reviewed and withdrawn. | |
| Recommendation — Define and enforce access-control rules for review and removal of unused accounts. Review access rights routinely and withdraw rights that no longer match the role. | ||
Practitioner Guidance
What to prioritise: Start with accounts tied to high-value systems, shared classroom tools, and staff who changed roles or left a department. Those are the most likely to have stale permissions that still matter.
What to verify: Before trusting an account to remain live, verify who owns it, what system it reaches, whether it has been used recently, and whether a current teaching or operational need still exists. If you cannot answer those questions quickly, the account deserves recertification.
Decision rule: If the account no longer supports an active role, course, or application, retire it. If the account still supports a current function but the scope is too broad, reduce access rather than leaving the full entitlement in place.
Practitioner takeaway: The safest default is to treat unused staff access as expiring unless a current business owner can justify it, because stale access tends to survive longer than the process meant to govern it.
Related resources from NHI Mgmt Group
- How should teams reduce the risk of orphaned service accounts and stale tokens?
- Why do unused SaaS accounts create security risk?
- How should teams handle unused SaaS accounts without disrupting business work?
- Why does account takeover risk increase when customer accounts sit unused for long periods?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org