A zombie account is a dormant or orphaned user account that remains active in systems after the user has left the organization or no longer requires access.
A zombie account is a user account that remains active and accessible in systems after the associated user has departed the organization, changed roles, or no longer requires the access. These orphaned accounts retain their original permissions and often go unmonitored, creating exploitable entry points for attackers. Zombie accounts are common in organizations lacking automated deprovisioning processes and regular access reviews across their identity infrastructure.
Zombie accounts are security risks because they provide authentication-ready entry points with established permissions that attackers can exploit without triggering new-account alerts. Former employees may retain access to sensitive systems. Attackers who discover zombie accounts through credential databases or brute force gain legitimate-appearing access that evades behavior-based anomaly detection. The accounts lack active users to notice suspicious activity on their profiles.
Zombie accounts form through incomplete employee offboarding processes that deactivate primary accounts but miss application-specific credentials, service accounts created for projects that conclude without cleanup, shared accounts where individual users depart but the account persists, vendor and contractor accounts remaining after engagement completion, and accounts in systems not integrated with centralized identity management or automated lifecycle processes.
Identify zombie accounts by correlating HR termination records with active directory and application account inventories, analyzing last-login timestamps to find accounts with extended inactivity periods, reviewing accounts belonging to users with no current role assignments, auditing service accounts against active project and application inventories, and implementing automated detection tools that flag accounts exceeding inactivity thresholds for review and potential deactivation.
Zombie account compromise enables attackers to access systems with legitimate credentials, bypass multi-factor authentication if not enforced on dormant accounts, move laterally using the account's existing network trust relationships, access sensitive data based on original role permissions that were never revoked, maintain persistent access that is difficult to attribute to an active threat, and evade detection systems expecting the account owner to notice anomalies.
Prevent zombie accounts through automated identity lifecycle management integrating HR systems with identity providers, mandatory offboarding checklists covering all application access, automated account disabling triggered by HR termination events, regular access certification campaigns requiring managers to validate active accounts, time-limited account provisioning with automatic expiration, and continuous monitoring for accounts with extended inactivity periods triggering review workflows.
Access reviews systematically evaluate all active accounts to verify continued business justification, identifying zombie accounts that should be deactivated. Quarterly or semi-annual certification campaigns require managers and application owners to confirm each account is still needed. Automated access review platforms flag accounts associated with terminated employees, extended inactivity, or missing organizational assignments for expedited review and remediation action.
Identity governance and administration (IGA) platforms address zombie accounts through automated lifecycle management linking account status to HR employment records, role-based provisioning that automatically adjusts access when roles change, automated deprovisioning workflows triggered by termination events, continuous access certification with attestation workflows, orphan account detection engines, and policy enforcement ensuring accounts without valid business justification are automatically disabled.