Provisioning

Orphan Account

An Orphan Account is an account that exists in a target system but is no longer properly linked to an active, governed identity.

Definition

An Orphan Account is a user or service account that remains present in a target system without a valid, current association to a known and governed identity in the IAM platform. Orphan accounts often arise from failed deprovisioning, legacy migrations, manual account creation, correlation errors, acquisitions, or weak joiner-mover-leaver controls. Because they frequently escape standard governance processes, orphan accounts represent a significant security and audit concern. Identifying and remediating them typically requires reconciliation, ownership investigation, and policy-driven cleanup decisions.

Why it matters

Orphan Accounts are a classic source of residual access risk because they often remain active outside normal governance visibility.

The Ariovis perspective

Ariovis promotes automation that remains explainable and recoverable: explicit rules, approvals where needed, logs, error handling and recovery mechanisms.

Related services

Common pitfalls

  • A common mistake is detecting orphan accounts but postponing remediation indefinitely because ownership and business impact are unclear.

These concepts matter most inside a real project.

The first conversation helps establish your context, the systems involved and the next useful decision.