PasswordSafe and Terminated Employees
A few times I’m asked about what to do about employees who have left the organization and their accounts that are in PasswordSafe. The following are some suggestions on next steps, and components to watch out for when cleaning up the environment.
Step 1: Audit Current Access in PasswordSafe
I would recommend running this before deprovisioning a user so you have a record of their configurations to make clean-up activities a bit easier. Unless the user is an Admin - skip to step 2.
Step 2: Remove Access to PasswordSafe
🚩 Note: if you have let go an Administrator, validate PasswordSafe immediately, regardless if automation is configured, to ensure there are no potential paths into the vault by removing access to PasswordSafe.
While this may be the most obvious, there may be a few components worth noting. Occasionally this may be set up with a SCIM, or integrated into an automation for user lifecycle management. The short version is to ensure the users aren’t provisioned to a group that provides access, or quarantined to ensure no access.
Is the user a local user or a domain user?
-
If a local user, you can deprovision the user from an User Groups that provide access, and delete if they have never used PasswordSafe. Otherwise, marking inactive will ensure they can’t log in.
-
If the user is a domain user, you may need to mark the user quarantined until the user has been de-provisioned from a domain group that is being synced.
✅ Tip: You can’t delete a user who has audit history in PasswordSafe. You can, however, always quarantine them, or mark inactive. For more details, please see: https://beyondtrustcorp.service-now.com/csm?id=csm_kb_article&sysparm_article=KB0016988
Does the user have a dedicated account?
-
If so, ensure the dedicated account is also de-provisioned from PasswordSafe.
Step 3: Check for dedicated accounts
If the user has dedicated managed accounts, these accounts will need to be removed from password-safe check-ins. If you are using Attributes, you may desire to have an attribute tag of “Deprovisioned” and then collecting those as a smart group.
If the account is still live on the target systems, it may be beneficial to maintain the auto-rotation of credentials on until the account is removed. These accounts may show up in the failed password checks or rotations, so the attribute to know that these have been deprovisioned likely means that the accounts have been removed from the target system, and are safe to start removing from PasswordSafe.
Once the accounts are no longer active, you can choose to maintain the managed account in PasswordSafe for any log retention requirements before finally removing them from PasswordSafe.
Overall decommissioning guide is best written up in the knowledge base article https://beyondtrustcorp.service-now.com/csm?id=csm_kb_article&sysparm_article=KB0020560.





