---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Playbook for Attempted Access to Deactivated Accounts

# Playbook for Attempted Access to Deactivated Accounts {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

This playbook triggers when an employee whose account is terminated, disabled, or separated attempts to log in with their credentials. User's identity state in Sail point generally gets updated to disabled on their termination
date.

30 days is the ideal time from the termination date for it to get updated to a separated state. You can use business logic in Sail point to delete the RSA accounts and remove the Active Directory (AD) group memberships after 30
days.
* **[Set up the Attempted Access Deactivated Account playbook](https://servicenow-prod.fluidtopics.net/KobrxY5lqoKeLXFay3lG4w)**   
  Use the following steps to set up the Attempted Access Deactivated Account playbook.
* **[Use the Attempted Access to Deactivated Accounts playbook](https://servicenow-prod.fluidtopics.net/z82wGXPIJFQTX65~FQS1zw)**   
  Use this playbook when an employee whose account is terminated, inactive, or separated attempts to log in with their credentials. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the Attempted Access to Deactivated Accounts playbook.

