An access exception is a starting point

Access reviews · published 2 October 2026 · updated 3 October 2026

An enabled account after someone has left is worth investigating. I would start by checking that the two records describe the same person and the same point in time.

It is tempting to look at a directory status and jump straight to a finding. I’d want a few ordinary questions answered first. Which identifier did the reconciliation use? When were the extracts taken? What does the departure date mean in the source system?

If the extracts don’t line up, the comparison may be raising a data-quality question rather than a confirmed control failure. That still needs attention, but it needs the right explanation.

Make the match traceable

I’d check how an HR record becomes a directory-account match. A display name alone would make me cautious, particularly where names repeat or a person has more than one account.

I’d want duplicate identifiers, missing values and unresolved matches to stay visible. Removing them from the output makes the table tidier, but leaves the reviewer with a less complete view of the population.

The workpaper should preserve the source and the matching basis. Someone else ought to be able to follow the comparison without relying on the script author’s memory.

A deadline gives the dates meaning

The requirement matters just as much as the export. I’d establish the removal deadline, the effective departure date and the basis for any approved extension before testing timeliness.

For a simple fictional example, suppose the policy requires removal by the end of the departure date. A person leaves on the 20th and the account is disabled on the 28th. The current status is disabled; the eight-day gap still needs an explanation.

I’d check the actual removal event and the departure notification before concluding where the delay arose. An approval or an explanation may change the assessment, but it needs evidence of its own.

Keep the scope in view

An account belonging to a current employee is outside a leaver review. That person might still belong in a periodic review of role appropriateness, but the test would have a different purpose.

There is a second boundary: a disabled directory account tells us about that account. The review may also need to cover separate application or privileged accounts. I would agree that scope and request the evidence for the access routes it includes.

Activity deserves context

An activity date after departure would increase my interest in a record, particularly if it has elevated permissions. It would also give me another evidence request.

I’d want to understand the event, the account context and its timestamp. A date in an export does not tell me enough to write that a former employee misused access. The appropriate urgency and escalation depend on the confirmed facts.

What I would report

Once the investigation supports a finding, I would explain the requirement, confirmed condition and evidence. I would make the population and period clear, describe the risk and distinguish what has already been addressed from what still needs action.

I would also keep an unresolved cause visible. Closing the current account and fixing the process that caused a delay can require different actions. The owner, due date and closure evidence should make that difference understandable.

The five-record walkthrough uses these questions in a small exercise. It includes both candidate exceptions and records I would leave outside the finding.

Try the access walkthrough

Reference

Microsoft: Disable-ADAccount documents the directory-account action. The broader scope of a review needs to be established separately.