How would you fully offboard a user, including their integrations?
Suggested answer
I treat it as three layers, because stopping at the first one is the mistake I see most often.
1. Directory: disable the account at the identity provider. This stops new interactive single sign-on logins.
2. Salesforce user: freeze and then deactivate the user. Freezing is the immediate action — it takes effect instantly and does not require the licence to be freed — while deactivation may need record ownership to be reassigned first.
3. Tokens and app access: revoke the user's OAuth tokens. A refresh token issued to a mobile app or a desktop tool is a standalone credential that the identity provider never sees; it keeps working until it is revoked, the user is deactivated, or the connected app's refresh token policy expires it.
Alongside that I check anything that was configured to run as that person — scheduled jobs, integration connections, named credentials, connected app run-as users — because deactivating a user who is silently the identity of an integration turns an offboarding into an outage. Designing integrations to run as dedicated integration users rather than named individuals is what prevents that in the first place.
Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.
Community comments (0)
No comments yet.
Sign in or create a free account to add a comment. Comments are moderated before they appear.