Web_Logo
Remote Support
Google Workspace: Faster Deprovisioning Cuts Account Risk
Home » Google Workspace Updates  »  Google Workspace: Faster Deprovisioning Cuts Account Risk

Google Workspace: Faster Deprovisioning Cuts Account Risk

Google has rolled out a new security feature for Workspace that automatically removes departing staff from cloud services the moment their access changes, closing a common gap that attackers rely on.

  • What it is: Inbound SCIM (System for Cross-domain Identity Management) now pushes account updates to Google Workspace in real time when an employee leaves or changes roles, rather than waiting for a manual update.
  • Who is affected: Any Google Workspace admin using an identity provider connected via SCIM for employee provisioning.
  • The risk being addressed: Orphaned accounts, logins left active after someone leaves the business, are a common way attackers and former employees retain unauthorised access.
  • What to do: No action is required to receive the update, but it is a good prompt to review your offboarding process and confirm accounts are actually being deactivated when staff leave.

We recommend using this as an opportunity to check that your current offboarding checklist covers every system a departing employee has access to, not just Google Workspace.

Source: Google Workspace Updates blog