Kean University Identity Termination & Deprovisioning Standard Operating Procedure (SOP 12)
Table of Contents
- About
- Scope
- Definitions
- Roles & Responsibilities
- Procedure Steps
- Related Policies & Standards
- Metrics & KPIs
- Records & Storage
- Revision History
About
This Standard Operating Procedure (SOP) defines how Kean University securely terminates identities and deprovisions access. It ensures that all user accounts, credentials, and privileges are removed promptly and consistently to prevent unauthorized access after a user’s departure or role change.
This SOP supports compliance with university policies requiring immediate disablement of accounts, revocation of access rights, and removal of privileged access when eligibility ends.
Scope
This SOP applies to all identities and access managed by Kean University, including:
- Faculty, staff, students, vendors, and contractors
- Service accounts and privileged accounts
- All identity platforms (e.g., Active Directory, Entra ID, enterprise systems)
Termination triggers include:
- Employment termination
- Student inactivity or separation
- Vendor contract expiration
- Role changes requiring reduced access
- Security incidents requiring immediate disablement
Definitions
View Definitions
- Deprovisioning: Removal of access, credentials, and privileges.
- Termination Event: Authoritative trigger ending access eligibility.
- Privileged Access: Elevated permissions requiring strict control.
- Dormant Account: Account inactive for an extended period.
Roles & Responsibilities
| Role | Responsibilities |
|---|---|
| Human Resources (HR) | Provides termination notifications for employees |
| Registrar | Identifies student status changes |
| Vendor Management | Tracks vendor contract expirations |
| IAM Lead | Executes account disablement and lifecycle actions |
| System Owners | Remove application and system access |
| Security Operations | Monitors for unauthorized access attempts |
| Chief Information Security Officer (CISO) | Oversees privileged access removal and escalations |
Procedure Steps
1. Termination Notification & Intake
- Receive termination events from HR, Registrar, or Vendor Management
- Process emergency termination requests immediately
- Validate trigger and initiate deprovisioning workflow
2. Immediate Identity Disablement
- Disable identity in directory systems
- Revoke active sessions and tokens
- Disable MFA and remote access
- Block email and SSO access
3. Privileged Access Deprovisioning
- Remove user from administrative and privileged groups
- Terminate privileged sessions
- Revoke elevated tokens and system access
- Verify removal through monitoring systems
4. Application & System Access Removal
- Remove access to enterprise systems and applications
- Coordinate with system owners for full access removal
- Document completion in service management system
5. Service Account Ownership Review
- Transfer ownership of service accounts if required
- Rotate credentials and update records
- Ensure no orphaned service accounts remain
6. Data Preservation
- Preserve or transfer email and files as required
- Ensure compliance with data retention policies
- Remove access without impacting operations
7. Post-Termination Monitoring
- Monitor systems for login attempts after termination
- Investigate anomalies immediately
- Escalate security incidents to leadership
8. Verification & Closure
- Confirm all access and privileges are removed
- Validate MFA and tokens are revoked
- Document completion and close request
9. Exceptions
- All deviations must follow formal exception management procedures
- Risk assessment and approval are required
- Exceptions must be time-bound and documented
Related Policies & Standards
- Identity & Authentication Policy
- Access Control Policy
- Account Management Policy
- Privileged Access Management Policy
- Password & Authentication Standard
- Exception Management Policy
- Policy Governance & Precedence
Metrics & KPIs
- Time to deprovision accounts after termination
- Percentage of privileged access removed on time
- Number of post-termination login attempts
- Number of policy exceptions
- Rate of inactive account cleanup
- Application access removal completion rate
Records & Storage
| Record | Location |
|---|---|
| Termination Notifications | HRIS / Registrar / Vendor Management Systems |
| Disablement Logs | Identity Platforms |
| Access Removal Records | Service Management System |
| Privileged Access Verification | Security Monitoring Systems |
| Monitoring Reports | Security Information and Event Management (SIEM) |
| Closure Documentation | Service Management Ticket |
Revision History
| Version | Date | Change | Author |
|---|---|---|---|
| 1.0 | February 13, 2026 | Initial SOP | IAM Lead |