Orphaned account

An active account that is no longer tied to a current owner, such as a leaver's account left enabled or a service account whose owner has moved on; a standing credential nobody watches.

An orphaned account is an account that still works but no longer belongs to anyone current. A common cause is a leaver whose access was not fully removed: the main directory account was disabled, but an account in a separate application, a cloud service, or a system outside central management was missed. Service accounts become orphaned in a different way: the software still uses them, but the person responsible has moved on, so nobody reviews their rights or rotates their credentials.

NIST SP 800-53 Rev. 5 addresses the problem in AC-2(3), which calls for disabling accounts within a defined period when they are no longer associated with a user or individual, as well as when they have expired or been inactive. With no owner, misuse is unlikely to be noticed. Controls that find and prevent them include timely deprovisioning tied to HR events, periodic access review reconciled against a list of current staff, and a named owner for each non-human account. Just-in-time provisioning at federated applications can create them silently, because it adds accounts without removing them.

Exam relevance: a scenario is likely to describe an account found active months after its owner left. Candidates are expected to name it an orphaned account, and to point to deprovisioning and access review as the controls that failed.