IT Account Management

Inactive MKUH accounts
Inactive accounts or accounts that have never logged in to a machine pose a security risk to organisations. Each one of these accounts offers a malicious actor (hacker) an opportunity to gain access to resources. When inactive accounts are not monitored, a malicious actor can compromise one and remain hidden from IT staff. Best practices and standards require that these accounts are removed or disabled within a set amount of time.
MKUH IT run weekly reports on accounts that have been inactive for 40 days* or more and blocks these accounts. If the staff member is still active in ESR, then the account is just blocked until the staff member requires access. If the staff member has left MKUH, then we would follow the Leaver process and the account would be retained for a further 90 days and then purged.
Think of it this way; imagine MKUH is a kingdom in medieval times. Each account that is given out or created is a member of our kingdom that has keys to the city. A key (or account) could topple the entire kingdom, as other kingdoms, or bandits (malicious actors) want to get into our kingdom to steal anything of value. The more keys (or accounts) we can remove from circulation, the more secure our kingdom is.
🔐🏰🔐
How do I get an account enabled?
If you have an MKUH staff member whose account has been blocked, please log the following SR asking for the account to be re-enabled : Extend / Enable Account
For Agency**, Locum or Contractors** - Please speak with HR in the first instance, who will raise the extension directly with us in IT. This way we can be sure that the worker is compliant.
Important information about leavers
➡️Leaving a substantive role, but remaining on bank : all permissions on the account will be stripped and replaced with a default setup. If bank staff start in your department, it is the managers responsibility to let IT know of the change in job role and any required permissions.
➡️Leaving Bank but remaining as a Student, or Agency, Locum or Honorary Contract: This requires an IT Access Request form to be completed, so we have a record of the new contract type. You can add any Smartcard changes required at the same time, under the additional Items section.
➡️Leaving the trust entirely : Managers must ensure that all work‑related Microsoft data (including OneDrive files, Teams content, SharePoint sites, MS Forms, Power Automate flows and Power BI reports) is transferred to a communal access area before the employee leaves.
⌛Managers automatically receive temporary access to a leaver’s OneDrive once the account is deleted. This access is provided for short‑term review and handover purposes only and should not be relied upon as the primary method of managing business data.
🚫This automatic access does not apply to Teams content, SharePoint ownership, MS Forms, Power Automate flows or Power BI reports. These must be proactively transferred before the employee leaves.
👀IT does not review, extract or retain business data on behalf of managers. Once an account has been deleted and the retention period has passed, data cannot be recovered under any circumstances.
📢To avoid disruption and data loss, staff are encouraged to share ownership of Microsoft content before leaving or taking extended absence. See Preventing Single Points of Failure: Ensuring Continuity in Your Absence.
*As of July 2022, the inactive account process was changed from 90 to 40 days, as we are at a higher risk of cyber attack.
**Agency and contractor accounts are only valid for a 90-day period from the request date. If no extend / enable request is received within a timely manner, the MS Office license will be revoked, meaning the mailbox will be deleted until such time as the person returns or the account is purged.
Related articles
Retention of NHS smartcards moving between organisations