{"id":31079739,"url":"https://github.com/compcode1/remove-user-account","last_synced_at":"2026-08-16T12:31:51.242Z","repository":{"id":310855718,"uuid":"1041508201","full_name":"Compcode1/remove-user-account","owner":"Compcode1","description":"To maintain identity hygiene and enforce lifecycle governance, a user account that is no longer in use must be removed from the Microsoft Entra tenant. ","archived":false,"fork":false,"pushed_at":"2025-08-20T15:43:36.000Z","size":7,"stargazers_count":0,"open_issues_count":0,"forks_count":0,"subscribers_count":0,"default_branch":"main","last_synced_at":"2025-09-16T11:18:45.069Z","etag":null,"topics":["audit-compliance","entra-governance","identity-lifecycle","stale-accounts","user-deprovisioning"],"latest_commit_sha":null,"homepage":"","language":"Jupyter Notebook","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/Compcode1.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2025-08-20T15:32:27.000Z","updated_at":"2025-08-20T15:43:39.000Z","dependencies_parsed_at":null,"dependency_job_id":"8b8055d6-867f-4308-b54d-b03b8a6964c5","html_url":"https://github.com/Compcode1/remove-user-account","commit_stats":null,"previous_names":["compcode1/remove-user-account"],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/Compcode1/remove-user-account","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Compcode1%2Fremove-user-account","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Compcode1%2Fremove-user-account/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Compcode1%2Fremove-user-account/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Compcode1%2Fremove-user-account/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/Compcode1","download_url":"https://codeload.github.com/Compcode1/remove-user-account/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Compcode1%2Fremove-user-account/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":36714792,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-08-06T04:43:03.162Z","status":"online","status_checked_at":"2026-08-16T02:00:06.462Z","response_time":62,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["audit-compliance","entra-governance","identity-lifecycle","stale-accounts","user-deprovisioning"],"created_at":"2025-09-16T10:59:20.255Z","updated_at":"2026-08-16T12:31:51.233Z","avatar_url":"https://github.com/Compcode1.png","language":"Jupyter Notebook","funding_links":[],"categories":[],"sub_categories":[],"readme":"Remove a Stale User Account\n\nScenario\nTo maintain identity hygiene and enforce lifecycle governance, a user account that is no longer in use—jacob.choi@company.com\n—must be removed from the Microsoft Entra tenant. This process includes disabling the account, verifying no active dependencies, and then permanently deleting the user. This reflects responsible identity deprovisioning and prevents the accumulation of stale objects that could be misused.\n\nStep-by-Step Action Flow (Simulated)\n\nNavigate to Microsoft Entra Admin Center → Users\n\nLocate jacob.choi@company.com\n\nConfirm user is inactive or no longer needed\n\nClick Block sign-in → Confirm\n\nCheck group memberships and directory role assignments\n\nRemove user from any security or role-assignable groups\n\nRemove directory roles, if present\n\nClick Delete user → Confirm deletion\n\nVerify deletion by searching directory\n\nReview audit logs to confirm user removal event\n\nEntra Control Stack Mapping\nLayer 1 – Authority Definition\n\n✅ Touched\nAction requires either User Administrator or Privileged Role Administrator rights. Logs reflect execution context for accountability.\n\nLayer 2 – Scope Boundaries\n\n✅ Relevant\nWhile the user was directory-wide, cleanup actions reinforce containment and show deliberate boundary enforcement.\n\nLayer 3 – Test Identity Validation\n\n✅ Post-action validation\nConfirm no authentication attempts or group inheritance remains post-removal. Validate group and role integrity.\n\nLayer 4 – External Entry Controls\n\n❌ Not affected\nThis user is internal. No cross-tenant implications are involved.\n\nLayer 5 – Privilege Channels\n\n✅ Engaged if the user had roles\nIf jacob.choi had privileged roles, this removal closes an unnecessary privilege path.\n\nLayer 6 – Device Trust Enforcement\n\n❌ Not affected\nThis process does not involve device trust posture or compliance status.\n\nLayer 7 – Continuous Verification\n\n✅ Follow-up\nEnsure periodic identity review policies exist to flag stale accounts before long periods of dormancy. Recommend integration with access reviews or automated lifecycle policies.\n\nObservations and Follow-Up\n\nRemoval was clean, with group memberships and roles revoked prior to deletion.\n\nAudit logs confirm the action with traceable context.\n\nIdentity lifecycle policies should incorporate stale account checks to reduce manual oversight.\n\nSuggest regular review cadence for stale accounts across departments.\n\nEntra Control Stack: Micro-Project Series (Progress Tracker)\nProject\tTitle\tStatus\n1\tAdd a New Guest User\t✅ Complete\n2\tChange a Global Administrator to a Privileged Role Administrator\t✅ Complete\n3\tAssign User Administrator Role at AU Scope\t✅ Complete\n4\tRemove a Stale User Account\t✅ Complete\n5\tCreate a Group and Assign Role\t⬜ Upcoming\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fcompcode1%2Fremove-user-account","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fcompcode1%2Fremove-user-account","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fcompcode1%2Fremove-user-account/lists"}