Home / Companies / SSOJet / Blog / Post Details
Content Deep Dive

The Offboarding Gap: Deactivated in the IdP, Still Logged Into Your App

Blog post from SSOJet

Post Details
Company
Date Published
Author
Goverdhan Sisodia
Word Count
3,251
Company Posts That Month
23
Language
English
Hacker News Points
-
Post removed?
No
Summary

SCIM deactivation through `active: false` does not automatically end existing sessions or revoke tokens, creating a potentially significant exposure window between an HR termination event, the IdP sync, and the expiry or explicit revocation of credentials. RFC 7643 leaves the meaning of deactivation to service providers, while RFC 7009 recommends minimizing revocation propagation delays and cascading refresh-token revocation to related access tokens; NIST also cautions that valid tokens do not prove a user is still present or authorized. Effective offboarding therefore requires blocking new logins and deliberately invalidating server sessions, refresh and opaque access tokens, API keys, and active streams, while treating stateless JWTs through short lifetimes or request-time denylist checks. Organizations should report deprovisioning speed as both IdP detection latency and their own revocation latency, document their behavior for disables and deletes, reconcile IdP user scope to catch omission-based deprovisioning or failed syncs, and monitor for successful requests by inactive users.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Platform Engineering 9 358 65 25 -70%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.