Skip to main content
Workflow

How to offboard shared MFA access

Step-by-step workflow to revoke shared MFA viewers and SMS recipients when employees, contractors, or MSP technicians leave—audit-friendly and fast.

Why offboarding shared MFA is different

Workforce SSO deprovisioning does not automatically remove someone from shared MFA viewer lists. A departed engineer may still see TOTP on a dashboard or receive SMS OTP until explicitly revoked—creating audit and insider-risk gaps.

Auditability expectations

Assessors ask for proof that MFA access ended with employment. Chat-based code sharing leaves weak evidence. Governed platforms provide admin actions you can reference in access reviews—pair with MFA offboarding checklist.

MSP and agency notes

Remove technicians per client context; never rely on "they lost laptop access." See MSP MFA access policy and MSP use case.

Operationalize this workflow with MultiMFA

Governed SMS and TOTP for collective logins—14-day trial.

Offboarding workflow steps

Execute on termination day—same workflow for employees, contractors, and MSP technicians.

  1. Trigger from HR/offboarding ticket

    Link MFA revocation to HRIS termination date—same day for contractors.

  2. Remove MultiMFA viewers/recipients

    Admin removes user from each enrollment; do not wait for vendor password rotation alone.

  3. Verify vendor sessions

    Invalidate active sessions where platform supports it; rotate password if policy requires.

  4. Document in access review log

    Record who revoked, when, and which shared accounts were affected.

  5. Quarterly orphan check

    Reconcile viewer lists against current roster—see shared account security checklist.

Glossary

Key terms in this guide

Operational definitions for shared MFA vocabulary—written for security and IT teams, not dictionary-only summaries.

Workflow FAQ

Does MultiMFA replace our IdP MFA?
No. MultiMFA governs second factors for shared operational logins. Workforce SSO MFA remains on your identity provider.
How fast can we revoke access?
Admins remove viewers/recipients in MultiMFA immediately—faster than resetting vendor MFA on personal phones across many apps.
Should we reset vendor MFA after offboarding?
Reset when the departing person enrolled personal MFA on a shared login. If MultiMFA held enrollment, removing viewers is usually sufficient.

More questions? Contact support or read our security overview.

Reduce operational MFA friction

Named viewers, admin revoke, and audit-friendly workflows.