Skip to main content
Sometimes you need to revoke a user’s access all at once — for example, after they leave the company or change roles. In that case, disable or delete the user account linked to Microsoft Entra ID (Azure AD).
Disabling and deleting have different effects. Disabling temporarily suspends access; re-enabling the ID restores it. Deleting removes the Entra ID-linked account itself — it can be restored within 30 days of deletion, but not after that. Choose the option that matches your goal.
Currently, Microsoft Entra ID (Azure AD) is the only supported identity provider. For details on scope, see Assigning and unassigning apps for Entra ID-managed users.

Open the action screen

You can open the disable/delete screen for an Entra ID-linked account using either of the following two methods. a. Go to Services > select Microsoft Entra ID (Azure AD) > open the “Accounts” tab.
Click the ⋮ menu next to the target account, then click Delete.
The Accounts tab on the service screen, with Delete selected from the ⋮ menu b. Go to Directory > select the account to disable or delete > open the “Services” tab.
In the “Actions” column for the target service, click Delete.
The Services tab in Directory, with Delete selected in the Actions column The “Delete Microsoft Entra ID (Azure AD)” screen opens, where you choose either Disable this ID or Delete this ID.

Disable an Entra ID-linked account

This revokes access, but data in Microsoft Entra ID (Azure AD) and in the app itself is retained. Re-enabling the ID restores access. App assignments to Microsoft Entra ID (Azure AD)-managed services are kept as they are.
  1. Select Disable this ID. To also unassign all apps at the same time, check Also unassign all apps.
    This checkbox unassigns only direct assignments — group assignments and conditional access assignments are not affected.
    The "Disable this ID" option selected, with the "Also unassign all apps" checkbox shown
  2. Click Disable. If you checked “Also unassign all apps,” enter the target user’s email address as a safety check. Then click Disable. The confirmation screen asking for the user's email address
  3. Once “Microsoft Entra ID (Azure AD) disabled” appears, the operation is complete.
    Login to Microsoft Entra ID (Azure AD) and its apps is blocked once processing finishes, which can take a few minutes.
    Click Done to close the screen.
    The completion screen showing "Microsoft Entra ID (Azure AD) disabled"
    A “Unassigned apps — needs review” entry is created for each app that was unassigned. For details, see Checking assignment status and errors.

Delete an Entra ID-linked account

This action revokes access and can result in data loss. Login is blocked as soon as it’s applied, and the account may remain on the app side even after its assignment is unassigned.
Access is revoked, all app assignments are unassigned, and then Microsoft Entra ID (Azure AD) is deleted. Accounts on the SaaS side cannot be deleted directly. SCIM-supported apps are deprovisioned automatically; non-SCIM apps leave the account and need manual deletion. You can restore the ID within 30 days.
  1. Select Delete this ID. A list of apps whose assignments will be unassigned is shown — review it. The "Delete this ID" option selected, showing the list of apps to be unassigned and a confirmation input field
  2. As a safety confirmation, enter the target user’s email address in the confirmation field, then click Delete.
  3. Once “Microsoft Entra ID (Azure AD) deleted” appears, the operation is complete. Click Done to close the screen.
    You can restore it within 30 days, but restoring does not re-assign apps — you’ll need to provision them again.
    The completion screen showing "Microsoft Entra ID (Azure AD) deleted"
    A “Unassigned apps — needs review” entry is created for each app that was unassigned. For details, see Checking assignment status and errors.
最終更新日 2026年8月26日