
Admin-LizG.50391 (Customer) asked a question.
Hello,
I am relatively new to Okta and have an emergency offboarding situation today. A Super Admin who authorized multiple critical Okta Workflow connections is leaving the company. We do not have time to set up a Service Account today.
I need to completely block this user from logging into our Okta Org immediately, and I cannot risk breaking the live production workflows. Since I don't have custom "Deny Access" groups set up yet, I am planning to manually change their password (and keep the new password to myself) and click "Clear Sessions" on their profile so they are locked out of the UI.
My questions for the community:
1. Will manually changing their password and clearing their browser sessions keep the background Okta Workflow OAuth tokens alive? How long will they be kept alive for?
2. What is the absolute safest way for an Okta beginner to build a dedicated Service Account for Workflows?
Appreciate any urgent guidance!

Hi @Admin-LizG.50391 (Customer) , Thank you for reaching out to the Okta Community!
I would strongly recommend opening a ticket to work with our Okta Support Colleagues on this to ensure a smooth transition.
That being said, to give you some general guidance.
1. To lock the user out today without risking your production environment, follow these steps:
Once the immediate offboarding emergency is handled, you can safely proceed with the dedicated Service Account migration steps below.
2. Safest Way to Build a Workflows Service Account:
Once the emergency has passed, follow these steps to securely migrate the connections:
If my answer helped, remember to mark it as best to increase its visibility for other members of the Okta Community who might have the same questions as you.
Hope my answer helps!
--
Help others in the community by liking or hitting Select as Best if this response helped you.
Collect them all. Learn a new skill and earn a new Okta Learning badge.
Just released: More Okta Community badges just added