Faculty/Staff Account Termination Policy
Tags: Faculty, Staff, Accounts, Account Deletion, Account Termination, Identity Management
Department: Information Technology Services
Submitted: July 6, 2025
Next Scheduled Review: July 6, 2027
Policy Statement
University information resources, including domain accounts, Microsoft 365 services, and email, are strategic assets and must be managed as valuable state resources. Proper account lifecycle management ensures the confidentiality, integrity, and availability of university systems while protecting institutional data and maintaining compliance with applicable security standards.
Reason for Policy
The purpose of this policy is to establish a consistent and secure process for the termination, disabling, and deletion of faculty and staff accounts after employment ends. Standardizing the account lifecycle reduces security risk, protects university information resources, and ensures system access is only available to authorized personnel.
Policy
Account Termination
The faculty and staff account termination process is initiated when an individual is no longer identified as an active employee in the daily Workday employee feed received by Information Technology Services.
The Workday provisioning file is processed each morning beginning at approximately 5:00 AM. If an employee's University Identification Number (UIN) is no longer present in the file, the account is automatically processed for termination.
Account disablement occurs during the scheduled automation process beginning at approximately 7:00 AM.
Account Disable
When an account is terminated, the following actions occur:
- The NTNET (Active Directory) account is disabled.
- Sign-in access to Microsoft Entra ID (Azure AD) is blocked.
- Access to Microsoft 365 services, including Outlook, Teams, OneDrive, SharePoint, and other cloud resources, is removed.
- Authentication to university-managed systems using the terminated account is prevented.
Dormant Accounts
Accounts that become dormant due to inactivity may also be disabled through established account lifecycle processes.
A dormant account is one that has not authenticated to either Active Directory or Microsoft 365 within the established inactivity period.
Account Deletion
Disabled faculty and staff accounts remain in a disabled state for 180 days.
After the 180-day retention period expires, the account is automatically removed from the university identity management systems. Once deleted, recovery may not be possible, and a new account would be required should the individual return to employment.
Employees are responsible for ensuring any personal or departmental data required for business continuity is transferred to the appropriate department prior to separation from the university.
Additional Information
- Account termination is fully automated based on employment status received from Workday.
- Departmental supervisors are responsible for ensuring institutional data ownership is transferred before an employee's separation date.
- Shared mailboxes, shared drives, and other departmental resources are not deleted as part of the employee account termination process.
- Information Technology Services may delay account deletion when required for legal hold, audit, litigation, or other approved business purposes.
Definitions
Domain Account (NTNET):
An Active Directory account used to authenticate to university-owned computers, on-premises applications, network resources, and file shares.
Microsoft 365 Account:
A Microsoft Entra ID identity that provides access to Microsoft 365 services, including Outlook, Teams, SharePoint, OneDrive, and other cloud-based applications.
Microsoft Entra ID:
Microsoft's cloud-based identity and access management platform used for authentication and authorization to Microsoft cloud services.
MS365:
Microsoft 365 Enterprise, including Office applications, Exchange Online, Teams, SharePoint, OneDrive, and Enterprise Mobility and Security services.
Dormant Account:
An account that has not authenticated to either Active Directory or Microsoft 365 within the established inactivity period and is subject to disablement.
Disabled Account:
An account that has had all authentication privileges removed but remains within the directory for the retention period.
Account Deletion:
The permanent removal of an account from university identity systems following the 180-day retention period.
Workday Feed:
The authoritative daily employee data file received from Workday that is used to automate account provisioning and deprovisioning processes.
UIN (University Identification Number):
The unique identifier assigned by the university to faculty, staff, students, and affiliates for identity management purposes.