{"id":1131,"date":"2026-06-20T12:00:00","date_gmt":"2026-06-20T12:00:00","guid":{"rendered":"https:\/\/www.xceedit.com\/?p=1131"},"modified":"2026-05-07T13:36:46","modified_gmt":"2026-05-07T18:36:46","slug":"the-zombie-saas-audit-finding-the-3-apps-your-former-employees-still-access","status":"publish","type":"post","link":"https:\/\/www.xceedit.com\/blog\/the-zombie-saas-audit-finding-the-3-apps-your-former-employees-still-access\/","title":{"rendered":"The \u201cZombie\u201d SaaS Audit: Finding the 3 Apps Your Former Employees Still Access"},"content":{"rendered":"<p class=\"wp-block-paragraph\">Someone leaves the company on a Friday. By Monday, their email account is disabled, and their laptop is back in the pile.<\/p><p class=\"wp-block-paragraph\">What nobody checks is their login to the project management tool they signed up for in Q3, the cloud storage folder they shared with a contractor, or the CRM access they still have from two roles ago.&nbsp;<\/p><p class=\"wp-block-paragraph\">Three months later, those sessions are still active.<\/p><p class=\"wp-block-paragraph\">This is how zombie accounts form. nNot through negligence, but through an offboarding process built around corporate IT assets that no longer reflects how people actually use software.&nbsp;<\/p><p class=\"wp-block-paragraph\">The average company now runs more than 100 SaaS applications. Most offboarding checklists were written when there were three.<\/p><p class=\"wp-block-paragraph\"><\/p><h2 class=\"wp-block-heading\">What a Zombie Account Actually Is<\/h2><p class=\"wp-block-paragraph\">A zombie account is an active login that belongs to someone who no longer works for you. The name is informal. The risk is not.<\/p><p class=\"wp-block-paragraph\">What makes zombie accounts particularly dangerous is that they are valid credentials.<\/p><p class=\"wp-block-paragraph\">There is nothing to detect. The access was granted intentionally, and the system has no reason to question it. If a former employee walks back in through that door, or if their credentials are compromised after they leave, the access is there waiting.<\/p><p class=\"wp-block-paragraph\"><a href=\"https:\/\/josys.com\/article\/top-saas-cybersecurity-risks-in-2025\">Industry research finds that 50% of organizations<\/a> have discovered former employees still accessing SaaS applications months after their departure date.<\/p><p class=\"wp-block-paragraph\">For most of those organizations, the discovery was accidental rather than the result of a deliberate audit.<\/p><p class=\"wp-block-paragraph\"><\/p><h2 class=\"wp-block-heading\">The Three Apps Where Access Never Gets Removed<\/h2><p class=\"wp-block-paragraph\"><\/p><h3 class=\"wp-block-heading\">Cloud storage and collaboration tools<\/h3><p class=\"wp-block-paragraph\">Google Drive, OneDrive, and Dropbox are where zombie access causes the most immediate damage.&nbsp;<\/p><p class=\"wp-block-paragraph\">These platforms are where offboarding gets messy. Files may be shared with a departing employee\u2019s personal account. Guest permissions granted during a project may never get cleaned up. And folders set to \u201canyone with the link\u201d access may still be bookmarked.<\/p><p class=\"wp-block-paragraph\">The departure triggers a license removal in the identity provider. The shared folders, external links, and personal-account shares go untouched.<\/p><p class=\"wp-block-paragraph\"><\/p><h3 class=\"wp-block-heading\">Project management and CRM platforms<\/h3><p class=\"wp-block-paragraph\">Tools like Asana, Monday.com, Notion, Jira, HubSpot, and Salesforce are frequently provisioned by team leads rather than IT. That means the offboarding checklist has no visibility into them.&nbsp;<\/p><p class=\"wp-block-paragraph\">A former account executive\u2019s Salesforce login, or a project manager\u2019s Notion workspace with access to company strategy documents, can persist for months without anyone noticing.<\/p><p class=\"wp-block-paragraph\"><\/p><h3 class=\"wp-block-heading\">The tools IT didn\u2019t know existed<\/h3><p class=\"wp-block-paragraph\">This is the most dangerous category.&nbsp;<\/p><p class=\"wp-block-paragraph\">These are the tools employees signed up for using their work email. A survey platform. An AI writing assistant. A data visualisation tool. They were never formally provisioned, and they were never formally revoked.<\/p><p class=\"wp-block-paragraph\">When the employee leaves, the account does not get disabled. It sits there, attached to a work email address that may now redirect to an IT catch-all.<\/p><p class=\"wp-block-paragraph\"><\/p><h2 class=\"wp-block-heading\">Running the Zombie SaaS Audit<\/h2><p class=\"wp-block-paragraph\"><\/p><h3 class=\"wp-block-heading\">Step 1: Build your SaaS inventory<\/h3><p class=\"wp-block-paragraph\">Start by pulling a list of all SaaS applications connected to your identity provider: Microsoft Entra ID, Google Workspace Admin, or Okta, if you use one.&nbsp;<\/p><p class=\"wp-block-paragraph\">Cross-reference with billing records, browser extension installs, and email domains showing regular login notifications.<\/p><p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.grip.security\/saas-security-risks-report-2025\">Grip Security\u2019s 2025 SaaS Security Risks Report<\/a>, analyzing 29 million user accounts, identified 23,987 distinct SaaS applications in use across its customer base. That\u2019s far more than any IT team tracks manually.<\/p><p class=\"wp-block-paragraph\">Of those applications, 90% remained outside IT\u2019s management.&nbsp;<\/p><p class=\"wp-block-paragraph\">For smaller teams without a dedicated identity platform, a 30-minute review of active subscriptions and recent login notifications will surface most of the high-risk tools.<\/p><p class=\"wp-block-paragraph\"><\/p><h3 class=\"wp-block-heading\">Step 2: Cross-reference against your offboarding list<\/h3><p class=\"wp-block-paragraph\">Take the last 12 months of departures and check each name against the SaaS inventory.&nbsp;<\/p><p class=\"wp-block-paragraph\">For each application, ask:&nbsp;<\/p><ul class=\"wp-block-list\"><li>Does this platform have an admin console?\u00a0<\/li><li>Can you see who is still active?\u00a0<\/li><li>When did this account last log in?<\/li><\/ul><p class=\"wp-block-paragraph\">Access that is months old and belongs to someone who has left is a zombie. Flag it for immediate revocation. Document what you find.<\/p><p class=\"wp-block-paragraph\"><\/p><h3 class=\"wp-block-heading\">Step 3: Revoke, document, and set a review cadence<\/h3><p class=\"wp-block-paragraph\">Remove the access. Record what was found and when. Then use the audit as the baseline for an offboarding checklist that covers more than the corporate email and laptop.&nbsp;<\/p><p class=\"wp-block-paragraph\">Going forward, enforce multi-factor authentication on all remaining active accounts and schedule a SaaS access review every quarter.&nbsp;<\/p><p class=\"wp-block-paragraph\">That cadence turns a one-time cleanup into a repeatable control.<\/p><p class=\"wp-block-paragraph\"><\/p><h2 class=\"wp-block-heading\">Making Offboarding a Security Process<\/h2><p class=\"wp-block-paragraph\">Zombie accounts cannot be removed if no one is looking for them. The SaaS offboarding audit is the starting point.<\/p><p class=\"wp-block-paragraph\">Want to close the gaps in your SaaS offboarding process?&nbsp;<\/p><p class=\"wp-block-paragraph\">Contact us or schedule a consultation to run a zombie SaaS audit and build a repeatable process your team can follow on every exit.<\/p><p class=\"wp-block-paragraph\"><\/p><p class=\"wp-block-paragraph\"><\/p><p class=\"wp-block-paragraph\">&#8212;<\/p><p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.pexels.com\/photo\/a-gray-laptop-with-black-keys-13751210\/\" data-type=\"link\" data-id=\"https:\/\/www.pexels.com\/photo\/a-gray-laptop-with-black-keys-13751210\/\" target=\"_blank\" rel=\"noreferrer noopener\">Featured Image Credit<\/a><\/p><p>This Article has been Republished with Permission from <a rel=\"canonical\" href=\"https:\/\/thetechnologypress.com\/the-zombie-saas-audit-finding-the-3-apps-your-former-employees-still-access\/\" title=\"The \u201cZombie\u201d SaaS Audit: Finding the 3 Apps Your Former Employees Still Access\" target=\"_blank\">The Technology Press.<\/a><\/p>","protected":false},"excerpt":{"rendered":"<p>Someone leaves the company on a Friday. By Monday, their email account is disabled, and their laptop is back in the pile. What nobody checks is their\u2026<\/p>\n","protected":false},"author":1,"featured_media":1132,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[80],"tags":[],"class_list":["post-1131","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-it-management"],"_links":{"self":[{"href":"https:\/\/www.xceedit.com\/blog\/wp-json\/wp\/v2\/posts\/1131","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.xceedit.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.xceedit.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.xceedit.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.xceedit.com\/blog\/wp-json\/wp\/v2\/comments?post=1131"}],"version-history":[{"count":1,"href":"https:\/\/www.xceedit.com\/blog\/wp-json\/wp\/v2\/posts\/1131\/revisions"}],"predecessor-version":[{"id":1133,"href":"https:\/\/www.xceedit.com\/blog\/wp-json\/wp\/v2\/posts\/1131\/revisions\/1133"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.xceedit.com\/blog\/wp-json\/wp\/v2\/media\/1132"}],"wp:attachment":[{"href":"https:\/\/www.xceedit.com\/blog\/wp-json\/wp\/v2\/media?parent=1131"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.xceedit.com\/blog\/wp-json\/wp\/v2\/categories?post=1131"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.xceedit.com\/blog\/wp-json\/wp\/v2\/tags?post=1131"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}