Join our Newsletter — 33% off our NHI Course
Home Glossary Governance, Ownership & Risk Suspended User
Governance, Ownership & Risk

Suspended User

← Back to Glossary
By NHI Mgmt Group Updated September 9, 2026 Domain: Governance, Ownership & Risk

A suspended user is an account that remains part of the organisation but is temporarily barred from platform access. In this state, the user cannot authenticate, recover the account, or receive notifications. The account record is preserved so access can be restored later without rebuilding identity relationships or shared permissions.

Expanded Definition

A suspended user is a deliberately disabled account that remains in the directory or application but cannot sign in, reset its own credentials, or act on notifications. The key boundary is that suspension preserves identity state while removing active access, so it differs from deletion, lockout after failed attempts, and role removal. Those states may all reduce access, but they do not mean the same operational thing.

In practice, suspension is used when an organisation needs a reversible control for a person whose access must stop immediately but whose record, approvals, audit history, or entitlement relationships should remain intact. That makes the term especially common in HR-driven offboarding, policy enforcement, and temporary administrative holds. Definitions vary across vendors about whether a suspended user can still receive email, retain group membership, or trigger downstream workflows, so teams should treat the status as platform-specific rather than universal.

For readers working in identity governance, the main boundary to watch is that suspended does not always mean fully inert. A suspended account may still exist in connected systems, which matters when integrated applications cache sessions, tokens, or delegated access paths.

Examples and Use Cases

Suspension shows up wherever access must be paused quickly without destroying the account record. It is usually a control state, not a security conclusion, and its effect depends on how each platform handles sessions, tokens, and downstream integrations.

  • An HR case triggers a temporary suspension while an employee separation is reviewed, preserving the directory record for later reinstatement.
  • A contractor finishes a project early, and the account is suspended rather than deleted so historical approvals and entitlement links remain auditable.
  • A help desk suspends a compromised user account after suspected misuse, then coordinates token revocation and recovery through identity operations.
  • A regulated environment suspends a user during an investigation to prevent authentication while keeping evidence and account lineage intact.

The tradeoff is speed versus completeness. Suspension is fast and reversible, but it only works as intended when surrounding systems honour the disabled state and do not continue to trust stale sessions or cached authorisation.

Security Implications

Suspension is security-relevant because it can look like an access revocation while leaving practical exposure behind. If the account is still trusted by connected apps, active sessions, refresh tokens, delegated grants, or external integrations may continue to function for some period after suspension.

Failure mechanism: the directory status changes, but downstream systems do not consistently re-check account state or invalidate issued credentials. That creates a gap between administrative intent and actual access removal, especially where single sign-on, API tokens, or session persistence are involved.

Impact: a supposedly suspended user may still reach data, trigger workflows, or retain privilege in linked systems. At scale, that weakens incident containment, delays offboarding, and obscures whether access was truly removed or only masked in the primary directory.

NHIMG’s Ultimate Guide to NHIs notes that only 20% of organisations have formal processes for offboarding and revoking API keys, which is a useful reminder that status changes alone rarely finish the job.

Domain and Governance Relevance

Suspended user status matters in identity governance because it separates administrative control from identity preservation. The record must often remain for audit, legal hold, HR workflow, or reinstatement, but the organisation still has to prove that active access, recoverability, and notification paths were actually removed.

For NHI governance, the concept is instructive even when the subject is human. It highlights a broader machine-identity lesson: disabling the primary account object is not enough unless related credentials, sessions, and delegated access are also handled. That is why suspension often sits alongside offboarding, revocation, and privilege review in mature access programs.

Where access is tied to business process rather than just authentication, suspended status becomes an operational control point. It signals who owns the account, who may restore it, and what evidence is needed before reactivation. In that sense, suspension is not only a user lifecycle label, but also a governance decision about reversibility, continuity, and control integrity.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v85.3 — Disable Dormant AccountsSuspended users are a disabled account state that must block interactive access.
6.3 — Data RecoverySuspension often preserves records for later restoration and audit.
6.8 — Audit Log ManagementSuspension decisions should remain traceable for investigation and governance.
Recommendation — Disable suspended accounts promptly and verify downstream systems stop trusting them. Retain account evidence needed for restoration without leaving access paths active. Log suspension actions and confirm who approved or restored the account.
NIST CSF 2.0PR.AC — Access ControlSuspension is an access-state decision that should immediately remove use of the account.
DE.CM — Continuous MonitoringSuspended status needs monitoring to catch residual use in connected systems.
Recommendation — Enforce account-disable rules so suspended users cannot authenticate or reuse sessions. Monitor for post-suspension activity and investigate any continuing account use.
MITRE ATT&CKT1098 — Account ManipulationAttackers abuse account state changes to preserve or regain access.
T1078 — Valid AccountsA suspended account is still a valid identity object that may be abused if trust lingers.
Recommendation — Detect suspicious account-status changes and treat unexpected suspension or reactivation as potential abuse. Hunt for reuse of suspended identities in sessions, tokens, and linked services.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 9, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org