how to revoke oauth app grants for a terminated user
Revokes OAuth app grants for a terminated user in Okta, Entra ID, and Google Workspace so third-party apps cannot keep accessing company data after offboarding. Covers the admin console paths and how to confirm the grants are gone. Use during terminations or when a compromised account needs containment. Not for disabling the user account itself.
TL;DR
Disabling the account is not enough: OAuth refresh tokens live on independently of the user account, so connected third-party apps keep their access until the grants are revoked. Walk each identity provider, revoke the user's app grants and sessions, then re-check after 24 hours because some apps re-grant on scheduled sync.
Steps
- Okta Admin: Directory > People > the user > Applications, and revoke each granted app. Expected: the user's app list is empty afterward.
- Entra ID: open the user's page > Applications, then use Revoke sessions to invalidate refresh tokens. Expected: confirmation that sessions were revoked; tokens die within minutes.
- Google Admin: Security > API controls > Manage third-party access, select the user, and remove each grant. Expected: the grant list shows nothing for the user.
- Check apps where the user was the OAuth owner or installer (dashboards, integrations, data tools). Expected: ownership transferred to an active employee or the app documented as retired; otherwise the app breaks silently later.
- Re-verify 24 hours later by listing the grants again in each console. Expected: still empty. Anything that reappeared is re-granting on a schedule and needs its admin consent removed, not just the user grant.
Use this when
- An employee is terminated
- A contractor engagement ends
- A compromised account needs containment
- An audit asks which third-party apps a user authorized
Not for this skill when
- The user stays employed (use a least-privilege review instead)
- Revoking a tenant-wide admin-consented app (that is an app-level decision, not a per-user cleanup)
Compatibility
- Okta, Entra ID, Google Workspace
- Applies to OAuth grants and SAML app assignments alike
Variants
User signed into everything with Google
Revoking the Google grants kills those sessions too, which is usually what you want at termination. Warn the manager first if the user is only suspended.
The same app keeps reappearing
An admin-consented app re-grants on sync. Remove the admin consent for the app, not just the user's grant.
Why it happens
Offboarding disables the account, but the OAuth grant is a separate contract between the app and the identity provider. The app keeps refreshing its own tokens until someone revokes the grant.
Edge cases
- Service principals owned by the user: transfer ownership or they die with the account.
- Mobile app tokens on personal devices: revoking the grant kills them, but verify on the next login report.
- Shared team apps connected under one user's grant: coordinate before revoking so the team does not lose access.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_FmZcx7pdPLAwTbORbF8GUQ
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.