## TL;DR
Disabling the account is not enough: OAuth refresh tokens live on independently of the user account, so connected third-party apps keep their access until the grants are revoked. Walk each identity provider, revoke the user's app grants and sessions, then re-check after 24 hours because some apps re-grant on scheduled sync.

## Steps
1. Okta Admin: Directory > People > the user > Applications, and revoke each granted app. Expected: the user's app list is empty afterward.
2. Entra ID: open the user's page > Applications, then use Revoke sessions to invalidate refresh tokens. Expected: confirmation that sessions were revoked; tokens die within minutes.
3. Google Admin: Security > API controls > Manage third-party access, select the user, and remove each grant. Expected: the grant list shows nothing for the user.
4. Check apps where the user was the OAuth owner or installer (dashboards, integrations, data tools). Expected: ownership transferred to an active employee or the app documented as retired; otherwise the app breaks silently later.
5. Re-verify 24 hours later by listing the grants again in each console. Expected: still empty. Anything that reappeared is re-granting on a schedule and needs its admin consent removed, not just the user grant.

## Use this when
- An employee is terminated
- A contractor engagement ends
- A compromised account needs containment
- An audit asks which third-party apps a user authorized

## Not for this skill when
- The user stays employed (use a least-privilege review instead)
- Revoking a tenant-wide admin-consented app (that is an app-level decision, not a per-user cleanup)

## Compatibility
- Okta, Entra ID, Google Workspace
- Applies to OAuth grants and SAML app assignments alike

## Variants
### User signed into everything with Google
Revoking the Google grants kills those sessions too, which is usually what you want at termination. Warn the manager first if the user is only suspended.
### The same app keeps reappearing
An admin-consented app re-grants on sync. Remove the admin consent for the app, not just the user's grant.

## Why it happens
Offboarding disables the account, but the OAuth grant is a separate contract between the app and the identity provider. The app keeps refreshing its own tokens until someone revokes the grant.

## Edge cases
- Service principals owned by the user: transfer ownership or they die with the account.
- Mobile app tokens on personal devices: revoking the grant kills them, but verify on the next login report.
- Shared team apps connected under one user's grant: coordinate before revoking so the team does not lose access.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_FmZcx7pdPLAwTbORbF8GUQ
