Orphaned Account
An orphaned account is a user or machine account that stays active in a system even though no valid owner or business reason for it remains, often because the person left the organization or changed roles. Because no one is clearly responsible for it, such an account tends to be overlooked during reviews. This makes it a lingering security risk that can be misused without anyone noticing.
An orphaned account is a provisioned identity, human or non-human, such as a service account, API key, or machine credential, that retains access to applications or systems without an active, accountable owner or valid business purpose, typically resulting from incomplete deprovisioning after a leaver or role change. As an identity governance concern, orphaned accounts are primarily addressed through joiner-mover-leaver lifecycle management, access reviews, and access certification, since they frequently escape periodic review precisely because no owner is mapped to them. Their significance is that retained entitlements represent standing access that can be exploited; remediation depends on deployment-specific reconciliation between authoritative identity sources and target-system account inventories. Note that the term is used differently in unrelated consumer contexts and this definition covers only its enterprise IAM meaning.
Why it matters
Orphaned accounts represent standing access that no accountable owner is watching, which makes them a durable weakness in an organization's access posture. Because no valid owner or business purpose is mapped to the account, it tends to escape the periodic access reviews and certifications that would normally flag excessive or unnecessary entitlements. The result is that entitlements persist long after the underlying business justification has disappeared, for example, after an employee leaves or moves to a different role, and those retained entitlements can be exploited without anyone noticing.
The risk is amplified for non-human identities such as service accounts, API keys, and machine credentials, which frequently have no obvious human owner to begin with and are easy to overlook during governance activities. These credentials often hold broad or long-lived access, so an orphaned service account can quietly become a high-value target. Because remediation depends on reconciling authoritative identity sources against the actual account inventories in target systems, gaps in that reconciliation directly translate into orphaned accounts that linger undetected.
Addressing orphaned accounts is therefore a core identity governance concern rather than a runtime enforcement problem: the issue is not whether an access request is correctly authorized in the moment, but whether the account should exist and retain entitlements at all. Left unremediated, these accounts accumulate over time and expand the attack surface, which is why they are a recurring focus of joiner-mover-leaver lifecycle management and access certification programs.
Who it's relevant to
Inside Orphaned Account
Common questions
Answers to the questions practitioners most commonly ask about Orphaned Account.
