
By Raymond Todd Blackwood, President of QuickLaunch
Somebody walked out of a Baltimore community college for the last time, and the payroll system found out 1,526 days later. Fifty months. That detail comes from the Maryland legislative audit of Baltimore City Community College published this June, and it was not the only one. Nearly 900 former employees were not removed from payroll systems on time. Seventy-one kept getting paid after they left. And in the very same report, the auditors flagged roughly $264,000 in financial aid paid to 145 people they classified as possible ghost students. Identities that were never people at the front door. Accounts that outlived their people at the back door. One lifecycle, failing in both directions.
Baltimore was not having a uniquely bad year. Auditors in Texas spent the winter reading UT San Antonio's offboarding logs and rated what they found a high risk: former employees allowed to keep as many as sixteen Active Directory security groups, with no policy saying which ones and no record of when or why. Connecticut's state auditors dinged Central Connecticut State University for failing to immediately disable four separated staff members' access, and the university's defense was its own diagnosis: the separation dates in HR and IT did not match. Arizona's auditor general found an employee who resigned and collected a paycheck for another year and ten months. A $78,114 goodbye gift nobody approved.
The question in this week's title has a short answer, and you are owed it up front. A deprovisioning strategy is four decisions made on purpose: the trigger (access changes the moment your student information system records the status change, not when a semester calendar rolls over), the grace period (how long courtesy access runs), the afterlife (what the account becomes next, because deletion is not the only option), and the review (someone reads the leftovers every term). QuickLaunch automates the first and the last: on our platform every enrollment change becomes an automatic, governed identity action, and drops, graduations, and contract ends revoke access in seconds. The two decisions in the middle are governance, and no product can make them for you, mine included. What your campus owes a former student is a question about your institution, not your integration layer.
Last week I wrote about temporary access codes and warned that the exception list is where ghosts get born. This week is the whole nursery. Identity lifecycle management earns its keep at exactly two moments, the day someone arrives and the day someone leaves, and higher ed has spent thirty years engineering the arrival while improvising the deprovisioning.
Notice who is surfacing these findings. Not attackers. Not security researchers. State auditors, with report numbers and publication dates. Stale accounts have graduated from a security team's private worry into a documented audit finding category, and the pattern inside the reports is the one I have been naming all year. Manual. Delayed. Forgotten. Orphaned. An offboarding checklist that lives in a spreadsheet. A separation date that exists in HR but never reaches the directory. A security group nobody remembers granting. An account nobody owns, which in practice means an account an attacker can own.
The federal standards world already told us what good looks like, and told us honestly. NIST's security control for personnel termination instructs institutions to disable system access within an organization-defined time period and to revoke every authenticator and credential tied to the individual. Read that phrase again: organization-defined. The control is a printed blank. The standard hands you the pen and waits, and an unfilled blank is itself a decision, the one the auditors in Texas and Connecticut just graded.
And the plumbing is not your bottleneck. In the default hybrid setup that most Microsoft campuses run, the synchronization engine moves changes on a cycle measured in fractions of an hour. If your deprovisioning still moves in semesters, the problem is not the technology. It is that nobody on your campus has been given the pen.
Here is what the sector's actual answers look like, straight from published account expiration pages. The University of Connecticut ends a graduate's Microsoft 365 access roughly sixty days after the degree, and the data is irrecoverably deleted. Wisconsin-Madison gives nine months, with warnings starting at ninety days. Iowa gives two years of email, with a smarter pairing we will come back to. Oklahoma expires student accounts after three inactive enrollment periods, with deletion warnings at thirty, fifteen, five, and one day out, while its health campus cuts withdrawn students off immediately, no grace at all.
Sixty days. Nine months. Two years. Immediate. These are serious institutions with serious IT shops, and their answers to the same deprovisioning question differ by a factor of twelve. The spread is not evidence that somebody is wrong. It is evidence that the sector never separated the three decisions hiding inside one number. The trigger should not be controversial: it belongs on the status event, because a withdrawal processed in the SIS on Tuesday should not still hold a live login in your learning management system in November. The grace period is a legitimate policy choice, which is why reasonable campuses land anywhere from zero days to two years. And the afterlife is a relationship choice that most institutions have never consciously made at all.
Here is what we actually built for this layer. QuickLaunch treats the trigger as an event, not a schedule: deprovisioning fires the instant the SIS status changes, whether that record lives in Banner, Colleague, Jenzabar, Workday, or Anthology, and access is revoked in seconds across the directory and every connected downstream app. The afterlife is modeled in the platform too, as a tier rather than a void: alumni tier applied, access revoked, so the person keeps a designed relationship while the attack surface goes to zero orphans. The grace period sits in policy you configure, because that number belongs to your cabinet, not to us. That is event-driven identity lifecycle management doing what a platform should do: executing your decisions at machine speed and refusing to make them for you.
Now the argument against aggressive deprovisioning, because it is real and your enrollment team already knows it. The students who disappear mostly do not disappear. The National Student Clearinghouse counts 43.1 million Americans with some college and no credential, 37.6 million of them working age. Last cycle, more than one million of them re-enrolled somewhere, the highest number ever recorded. Meanwhile 14 percent of first-year students leave higher education entirely between their first fall and their first spring. The kid who vanished in October is not an ex-customer. She is, statistically, a future applicant, and with high school graduating classes past their demographic peak and shrinking for the next fifteen years, maybe your most valuable one.
Higher ed already ran the experiment on treating separated students as closed accounts. It was called transcript withholding. It stranded credits for six and a half million people, sometimes over balances under twenty-five dollars, until the Education Department stepped in and the practice collapsed under its own weight. The tax calendar teaches the same lesson every January: the 1098-T form goes out weeks after your December separations lose their logins, which is why Maryland's flagship publishes a manual identity-verification workaround just so former students can retrieve their own tax documents. Cut the cord completely and your registrar and bursar inherit the support queue.
The challenge stands, and my answer is the distinction this whole column turns on. Deprovision the access. Never deprovision the relationship. Iowa is the working model here: email ends at two years, but transcript, tax document, and billing access runs for life through a portal scoped to exactly that. Access tiers shrink. The record relationship persists. The account was never really the asset. The person was.
If you want to watch campuses make the afterlife decision badly, in public, follow the alumni email wave. Duke, Columbia, Temple, Ohio State, and Cal Poly Humboldt are all ending or restricting alumni email. Northwestern now deletes graduate Google accounts about 300 days out. Vanderbilt retired alumni Google services citing licensing changes and cybersecurity risk. And the reaction has been instructive: Harvard and Virginia Tech reversed course after alumni backlash, a University of Colorado Boulder alumnus sued for breach of contract and won a settlement and an extension, and Duke alumni stood up a grievance website to catalog the broken promise. A philanthropy scholar quoted in Inside Higher Ed's coverage warned that reneging on a lifetime promise breeds a cynicism that threatens future engagement and giving.
Here is the uncomfortable part: both sides of that fight are right. The security officer who says thousands of dormant, loosely-monitored mailboxes are attack surface is correct, and every stale-account audit finding above backs him up. The advancement officer who says yanking a promised address burns donor trust is also correct, and the settlement checks back her up. The institutions getting sued made their deprovisioning decision by budget line, decades after making a marketing promise nobody costed. That is what an undesigned afterlife looks like when it finally comes due.
So design yours, one page per population: the event that pulls the trigger, the grace that follows, the tier that remains, and the owner who reviews what is left each term. For students who graduate. For students who quietly stop registering. For the applicant who never showed. For faculty, staff, and the contractor whose badge should have died with the contract. If the blank in the federal control gets filled, the auditor finds a policy instead of a finding, the returning student finds a door instead of a wall, and the only thing that actually dies on schedule is the access. That is deprovisioning done right. Not a purge. A plan for the goodbye.
Next week this column crosses to the other side of the identity house: why we give our AI agents a worldview before we give them a login. Bring your skepticism.
Primary: Score your campus on the On-Ramp Lifecycle Audit, QuickLaunch's sixteen-question identity lifecycle assessment; its FERPA-aware lifecycle lane maps directly to the four decisions in this column. Current deprovisioning capability detail lives in the release notes and on the identity and access platform page.
Secondary: Follow the weekly column on the QuickLaunch blog.Next week: why AI agents get a worldview before they get a login.
What is account deprovisioning in higher education?
Account deprovisioning in higher education is the governed removal of a person's access when their relationship with the institution changes, such as a student graduating, withdrawing, or failing to register for the next term. Done well, deprovisioning is triggered by the status change in the student information system, revokes access across email, the learning management system (LMS), and downstream applications, applies a designed after-tier such as alumni access instead of silently deleting the account, and records every action for audit.
How quickly should a university deprovision accounts when a student withdraws or graduates?
The access trigger should fire as soon as the student information system records the status change; platforms like QuickLaunch revoke access in seconds once the SIS status changes. The courtesy grace period is a separate policy decision, and published university practices range from immediate cutoff for withdrawals (University of Oklahoma Health campus) to roughly 60 days after graduation (University of Connecticut), 9 months (UW-Madison), and 2 years (University of Iowa). The defensible pattern is an instant trigger paired with a deliberately chosen, clearly communicated grace period.
What should students keep access to after they leave a university?
Former students still need their own records: transcripts, 1098-T tax forms, financial aid documents, and billing history. The University of Iowa model gives every former student lifetime access to a scoped student portal for transcripts and tax documents even after email ends, and FERPA preserves former students' rights to their education records. Best practice is to deprovision broad access, email, LMS, and network accounts on a schedule, while maintaining a narrow, secured records tier indefinitely.
Why are stale accounts a security risk for universities?
Stale accounts are credentials that keep working after their person has left, which makes them an unwatched entry point: nobody notices failed logins, password resets, or unusual activity on an account nobody owns. Recent state audits found former university employees retaining Active Directory security groups and workstation privileges after termination, and auditors warn that delayed deprovisioning exposes institutions to inappropriate access and fraud. Because these accounts sit outside daily use, compromise can persist undetected far longer than on an active user's account.
*Raymond Todd Blackwood is the President of QuickLaunch and writes about identity, agentic AI, and the messy reality of higher-ed IT. #ItsExistential*