Why offboarding shared MFA is different
Workforce SSO deprovisioning does not automatically remove someone from shared MFA viewer lists. A departed engineer may still see TOTP on a dashboard or receive SMS OTP until explicitly revoked—creating audit and insider-risk gaps.
Auditability expectations
Assessors ask for proof that MFA access ended with employment. Chat-based code sharing leaves weak evidence. Governed platforms provide admin actions you can reference in access reviews—pair with MFA offboarding checklist.
MSP and agency notes
Remove technicians per client context; never rely on "they lost laptop access." See MSP MFA access policy and MSP use case.
