Disable Inactive User
Route discovered inactive user accounts through an approval gate and disable them across connected identity systems, capturing full evidence for each account.
Requires a Nuxari account. Installs as Draft — no changes until you enable it.
Back to templatesWhat this template does
This remediation workflow accepts inactive-account findings and routes each through a required approval gate before any account is touched. Once an approver confirms, the account is disabled across every connected identity system where it exists. The workflow validates that the disable succeeded and captures a closing evidence record linking the original finding to the action taken.
When to use it
Use this template when you have identified dormant or inactive accounts — through the Dormant Account Review or another scan — and need a safe, approval-gated way to disable them at scale. It is especially valuable for reducing the standing attack surface from accounts that should no longer be active.
How it works
Finding intake
Inactive-account findings from a scan or review are queued into the remediation workflow with their last-activity evidence attached.
Approval routing
Each account is routed to the configured approver, who reviews the inactivity evidence and confirms or excludes the account from remediation.
Disable execution
Approved accounts are disabled across every connected identity system where they appear. Each system action is attempted and logged independently.
Validation and closure
Nuxari verifies the account is disabled in each system and generates a closing evidence record linking the finding, approval, and outcome.
What gets created in your tenant
Inactive User Disable Workflow
An approval-gated workflow that disables confirmed inactive accounts across connected identity systems.
Account Disable Approval
A per-account approval gate ensuring no account is disabled without a recorded decision.
Account Disable Evidence
Structured evidence records linking each finding, approval decision, and disable action.
What evidence it produces
- Inactive account finding record
- Approval decision with approver identity and timestamp
- Account disable confirmation per system
- Post-remediation account state snapshot
- Closure record linking finding to action
Safety and approval model
Templates install as Draft / Disabled by default. No actions run until you explicitly enable the template after reviewing the configuration.
This template requires an approval decision before enabling. No execution occurs without a recorded approver sign-off.
This template performs potentially destructive actions. Review configuration carefully before enabling.
This template installs in Draft state and is destructive — it disables user accounts. No account is touched until you connect the required connectors, review the configuration, and explicitly enable the workflow. Every disable action is approval-gated and cannot execute without a recorded approver decision. Disable is reversible (accounts are disabled, not deleted), and each action is fully logged.
Customization options
- Approval chain (single approver, sequential, any-of)
- Connector scope (which identity systems to disable in)
- Disable vs. block sign-in mode where supported
- Optional notification to the account owner or manager
- Grace period between approval and execution
- Exclusion list for protected or service accounts
Related templates
Dormant Account Review
Identify accounts with no sign-in or activity in a configurable window, generate a dormancy report, and route owner review tasks — without modifying any accounts automatically.
View templateResidual Access Sweep
Scan all connected systems for access belonging to offboarded users, generate findings for residual access, and create remediation tasks for each system with remaining access.
View templateRevoke Excessive Group Membership
Route excessive group membership findings through an approval gate, remove group assignments for confirmed cases, validate removal, and capture a per-removal evidence record.
View templateUse this template
Install in your Nuxari tenant and run the full approval and evidence workflow from day one.
Build the operating layer
for governance work.
See how Nuxari Ops reduces manual IT work, eliminates access drift, and generates audit evidence automatically, across your entire enterprise.