KUID SOP 12 - Identity Termination & Deprovisioning SOP


Kean University Identity Termination & Deprovisioning Standard Operating Procedure (SOP 12)

Table of Contents

About

This Standard Operating Procedure (SOP) defines how Kean University securely terminates identities and deprovisions access. It ensures that all user accounts, credentials, and privileges are removed promptly and consistently to prevent unauthorized access after a user’s departure or role change.

This SOP supports compliance with university policies requiring immediate disablement of accounts, revocation of access rights, and removal of privileged access when eligibility ends.

Back to top

Scope

This SOP applies to all identities and access managed by Kean University, including:

  • Faculty, staff, students, vendors, and contractors
  • Service accounts and privileged accounts
  • All identity platforms (e.g., Active Directory, Entra ID, enterprise systems)

Termination triggers include:

  • Employment termination
  • Student inactivity or separation
  • Vendor contract expiration
  • Role changes requiring reduced access
  • Security incidents requiring immediate disablement

Back to top

Definitions

View Definitions
  • Deprovisioning: Removal of access, credentials, and privileges.
  • Termination Event: Authoritative trigger ending access eligibility.
  • Privileged Access: Elevated permissions requiring strict control.
  • Dormant Account: Account inactive for an extended period.

Back to top

Roles & Responsibilities

Role Responsibilities
Human Resources (HR) Provides termination notifications for employees
Registrar Identifies student status changes
Vendor Management Tracks vendor contract expirations
IAM Lead Executes account disablement and lifecycle actions
System Owners Remove application and system access
Security Operations Monitors for unauthorized access attempts
Chief Information Security Officer (CISO) Oversees privileged access removal and escalations

Back to top

Procedure Steps

Flowchart showing identity termination and deprovisioning process from trigger through closure and monitoring

1. Termination Notification & Intake
  • Receive termination events from HR, Registrar, or Vendor Management
  • Process emergency termination requests immediately
  • Validate trigger and initiate deprovisioning workflow


2. Immediate Identity Disablement
  • Disable identity in directory systems
  • Revoke active sessions and tokens
  • Disable MFA and remote access
  • Block email and SSO access
3. Privileged Access Deprovisioning
  • Remove user from administrative and privileged groups
  • Terminate privileged sessions
  • Revoke elevated tokens and system access
  • Verify removal through monitoring systems

4. Application & System Access Removal
  • Remove access to enterprise systems and applications
  • Coordinate with system owners for full access removal
  • Document completion in service management system
5. Service Account Ownership Review
  • Transfer ownership of service accounts if required
  • Rotate credentials and update records
  • Ensure no orphaned service accounts remain
6. Data Preservation
  • Preserve or transfer email and files as required
  • Ensure compliance with data retention policies
  • Remove access without impacting operations
7. Post-Termination Monitoring
  • Monitor systems for login attempts after termination
  • Investigate anomalies immediately
  • Escalate security incidents to leadership

8. Verification & Closure
  • Confirm all access and privileges are removed
  • Validate MFA and tokens are revoked
  • Document completion and close request

9. Exceptions
  • All deviations must follow formal exception management procedures
  • Risk assessment and approval are required
  • Exceptions must be time-bound and documented

Back to top

  • Identity & Authentication Policy
  • Access Control Policy
  • Account Management Policy
  • Privileged Access Management Policy
  • Password & Authentication Standard
  • Exception Management Policy
  • Policy Governance & Precedence

Back to top

Metrics & KPIs

  • Time to deprovision accounts after termination
  • Percentage of privileged access removed on time
  • Number of post-termination login attempts
  • Number of policy exceptions
  • Rate of inactive account cleanup
  • Application access removal completion rate

Back to top

Records & Storage

Record Location
Termination Notifications HRIS / Registrar / Vendor Management Systems
Disablement Logs Identity Platforms
Access Removal Records Service Management System
Privileged Access Verification Security Monitoring Systems
Monitoring Reports Security Information and Event Management (SIEM)
Closure Documentation Service Management Ticket

Back to top

Revision History

Version Date Change Author
1.0 February 13, 2026 Initial SOP IAM Lead

Back to top

Was this answer helpful? Yes No

Sorry we couldn't be helpful. Help us improve this article with your feedback.