Most organizations believe that disabling an employee's SSO account means their access is gone. It isn't. Shadow SaaS logins, shared credentials, and vendor or partner portal accounts routinely outlive the employees who created them, invisible to the IdP, unowned, and unaudited for months after someone walks out the door. The industry treats offboarding as a checklist item. In reality, it's one of the biggest unmonitored gaps in identity security today.
In this upcoming webinar, Nick Nelli and Mohamed Mawji draw on real field findings from customer environments: proofs of concept and production deployments, where "offboarded" employees still had live, working access weeks or months after departure. This session challenges the assumption that IdP-based deprovisioning is sufficient, and shows organizations how to extend real, enforceable offboarding to every application in their stack, not just the ones behind SSO.
Key discussion points:
Why disabling an SSO account doesn't mean access actually disappears, and where it hides instead
Real findings from the field: shared accounts with no clear owner, admin rights nobody remembers granting, access tied to apps no one inventoried
The two questions every CISO should ask their team tomorrow: what stops someone from sharing a password, and how confident are you that someone who left a month ago has zero remaining access?
How to move from "we think we offboarded them" to provable, governed deprovisioning across every app—SAML, non-SAML, home-grown, and legacy
The goal: Stop treating offboarding as a one-time IdP action. Learn how to turn it into an enforceable, auditable event that actually closes access everywhere it lives, not just where it's easy to see.
Attendees are eligible to receive 1 CPE credit.