Inactive - but disabled user accounts?
Hello all-
My brain just spun-locked on this one. We are auditing a group that has over 9,000 accounts, but over 6,000 of those accounts are labeled "inactive" and are disabled - no login/shell access. Now going over our User Account Policies and Standards we find that this is a still no-no - as avenues - such as Social Engineering can be deployed to activate those accounts again, among other avenues of attack; however IT is battling back with some of the following reasons:
1. Project data needs to be kept under project IDs per project retention requirements
2. Expired user is still an active employee and have not indicated that they want account removed
3. Samba accounts are locked upon setup
4. Default System accounts are required but can be locked
I can see their logic for some of the above - but 6,000+ plus accounts - more than double that of their active accounts? Before I go off and club them with the policies and standards, yet again, I wanted to get some opinions from the ever-wise group me'ah. Thoughts please.
Thank you!