# Close technician offboarding across PSA, RMM, vaults, partner portals, and customer access

> Disabling one directory account does not end an MSP technician’s access. Close sessions, groups, RMM and PSA accounts, vault permissions, customer-local identities, API tokens, recovery paths, and shared knowledge.

- Canonical URL: https://update.dsesecurity.com/updates/close-technician-offboarding-across-msp-access/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: Gavin Stewart
- Published: 2026-08-17T13:23:00+00:00
- Modified: 2026-08-17T19:22:09+00:00
- Last reviewed by DSE: 2026-08-17
- Resource type: Checklist
- DSE priority: Important
- Topics: Cybersecurity, IT, Microsoft 365 & Identity
- Reading time: 3 minutes

## What you need to know

Disabling one directory account does not end an MSP technician’s access. Close sessions, groups, RMM and PSA accounts, vault permissions, customer-local identities, API tokens, recovery paths, and shared knowledge.

## Potentially affected

Technician identities; Microsoft Entra and local directories; PSA and RMM platforms; vaults; backup consoles; partner portals; customer-local accounts; API tokens; remote access; documentation; and recovery mechanisms.

## DSE recommendation

Build a role-based access register, trigger offboarding from an authoritative event, disable and revoke sessions immediately, remove delegated and customer-local access, rotate exposed shared secrets, verify closure, and retain evidence.

## Article

## Source facts: account termination must follow the real access graph

[NIST SP 800-53 Rev. 5 Update 1](https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final) includes controls for managing accounts and for terminating access when employment ends. Its account-management guidance addresses creating, enabling, modifying, disabling, and removing accounts; aligning access with authorized users and roles; monitoring account use; and reviewing accounts. Personnel-termination controls include disabling system access, revoking credentials, retrieving property, and notifying responsible roles.

Microsoft’s Cloud Solution Provider guidance likewise emphasizes removing users who no longer require access, reviewing administrative relationships and privileged roles, protecting credentials, and monitoring partner activity. CISA’s MSP advisory recommends restricting privileged access, tracking provider accounts, logging actions, and coordinating responsibilities between providers and customers.

Those outcomes cannot be achieved by assuming the primary identity provider is the only control point. MSP access can persist through active browser sessions, local customer accounts, RMM agents, vault exports, API keys, application consents, emergency credentials, shared device codes, documentation copies, SSH keys, vendor portals, and customer-controlled identities. Some paths may not support centralized revocation, and an operator may possess knowledge of a shared credential even after the account that revealed it is disabled.

## DSE recommendation: make offboarding an evidence-backed runbook

Build the runbook from the access paths used in daily service delivery. Assign an accountable coordinator, strict target times by risk, and a second person who confirms completion.

- Define the trigger. Use an authoritative HR or leadership event with effective time, employment status, role change, legal constraints, equipment location, manager, and offboarding risk level. Restrict advance notice when required, but pre-stage the checklist and owners.

- Contain identity first. Disable privileged and standard accounts at the effective time, revoke active sessions and refresh tokens, remove authentication methods, block remote access, and remove the person from privileged groups, approval workflows, on-call systems, and password-recovery roles.

- Close the MSP stack. Disable or delete named accounts in PSA, RMM, vault, documentation, backup, security, monitoring, registrar, cloud, telephony, source-control, and vendor systems. Reassign tickets, alerts, automation ownership, secrets, scheduled tasks, and customer communications before removing dependencies.

- Close customer paths. Query the access register for GDAP groups, customer-local accounts, VPN profiles, firewall accounts, remote-support tools, certificates, SSH keys, API tokens, and customer-managed identities. Coordinate removals with customers where the provider lacks authority and document pending items.

- Rotate exposed shared material. Change passwords, recovery codes, shared keys, and secrets the technician could retrieve or memorize. Prioritize domain administration, network equipment, backup, hypervisor, vault recovery, and emergency access. Validate dependent services after rotation.

- Recover assets and data. Collect managed devices, badges, tokens, removable media, paper records, and licensed hardware. Remotely isolate or wipe devices only under approved policy. Preserve required business records and prevent uncontrolled copies of customer data.

- Verify independently. A second operator should search for the person’s name, addresses, object IDs, device certificates, tokens, group membership, recent sessions, and customer accounts. Test that old access fails, review post-termination alerts, record exceptions, and obtain owner signoff.

Factual boundary: NIST controls describe security outcomes, not product-specific deletion commands or legal procedures. Disabling an identity does not retract information already viewed or copied. Labor, privacy, evidence-preservation, and customer-notification requirements must be determined with the appropriate business and legal owners.

Track time from effective termination to session revocation, unresolved customer paths, shared-secret rotations, returned assets, orphaned automations, failed verification tests, and post-departure access attempts. A mature process can answer not just when the employee account was disabled, but when every material customer-access path was closed and who verified it.

## Official references

- NIST, [Security and Privacy Controls for Information Systems and Organizations](https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final), SP 800-53 Rev. 5 Update 1.

- Microsoft Learn, [Security best practices for Cloud Solution Provider partners](https://learn.microsoft.com/en-us/partner-center/security/csp-security-best-practices).

- CISA, [Protecting Against Cyber Threats to Managed Service Providers and their Customers](https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-131a).

## Primary reference

- Name: CISA: Protecting Against Cyber Threats to Managed Service Providers and their Customers
- Authority: Cybersecurity and Infrastructure Security Agency
- URL: https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-131a
- Source publication date: 2022-05-11

## Citation and use

Preferred citation: “Close technician offboarding across PSA, RMM, vaults, partner portals, and customer access,” DSE Security, https://update.dsesecurity.com/updates/close-technician-offboarding-across-msp-access/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
