
9zfrk (9zfrk) asked a question.
Hi, what is the best industry practice to do with a user's account who has left the organisation. We disabled his account in AD but his account is still shown in the Okta "People" with Password status - "No Password".
Is deactivating and deleting the expired accounts is the preferred practice or just deactivating 'em is?
TIA

There's no specific answer to this question. There's best practices for data retention and preserving records, as well as for security. An assessment would need to be made for your particular environment and business needs.
However, for security purposes, I suspect at least deactivating the account would be a good idea, even without knowing all the details of your environment and objectives.