## TL;DR
Remove the user from the VPN authorization groups, kill active VPN sessions on the gateway, and revoke any client certificates. Then verify by checking the gateway logs for the user. Do this as part of the offboarding runbook, not as an afterthought.

## The error
```text
(Urgent offboarding step; no error.)
```

## Steps
1. Remove the user from all VPN authorization groups in AD/Entra. Expected: group membership gone. This stops new connections at next auth.
2. Kill active sessions: on the gateway admin console, find the user's session and terminate it. Expected: session gone. Group removal alone does not drop an established tunnel.
3. If the VPN uses certificates, revoke the user's client certificate at the CA and publish the CRL. Expected: revoked. A valid cert can re-auth depending on gateway config.
4. Disable or delete the VPN client profile on the user's device if you have MDM control. Expected: profile removed. This is hygiene; steps 1-3 are the enforcement.
5. Verify: check gateway logs for any connection attempts by the user after revocation. Expected: none, or rejected attempts. Rejected attempts confirm the revocation is working.

## When to use
- Employee termination (voluntary or involuntary)
- Contractor end date reached

## When not to use
- Temporary VPN suspension (use session kill only)
- Changing VPN groups for an active employee

## Compatibility
- Any VPN with group-based authorization; gateway session management

## Variants
### Involuntary termination
Do steps 1-3 before notifying the employee, coordinated with HR and security.
### Shared VPN credentials (bad practice)
If the org used shared credentials, rotate them immediately; revoking one user does nothing.

## Why it happens
VPN is remote network access, the highest-risk access to leave lingering. Sessions persist past group removal and certs persist past account disable, so all three must be handled.

## Edge cases
- Always-on VPN clients retry aggressively; watch the logs for retry storms and confirm they are rejected.
- Document the revocation time for compliance.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_iRig8cH2BtPONf23Gcql_A
