> ## Documentation Index
> Fetch the complete documentation index at: https://support.i.moneyforward.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Disabling and deleting an Entra ID

> Steps to disable and delete a user's Entra ID-linked account, and what to consider before doing so.

Sometimes you need to revoke a user's access all at once — for example, after they leave the company or change roles. In that case, disable or delete the user account linked to Microsoft Entra ID (Azure AD).

<Info>
  **Disabling** and **deleting** have different effects. Disabling temporarily suspends access; re-enabling the ID restores it. Deleting removes the Entra ID-linked account itself — it can be restored within 30 days of deletion, but not after that. Choose the option that matches your goal.
</Info>

Currently, Microsoft Entra ID (Azure AD) is the only supported identity provider. For details on scope, see [Assigning and unassigning apps for Entra ID-managed users](/en/it-management/idp-account-management/entraid-app-assignment).

<h2 id="open-action">
  Open the action screen
</h2>

You can open the disable/delete screen for an Entra ID-linked account using either of the following two methods.

a. Go to **Services** > select Microsoft Entra ID (Azure AD) > open the "Accounts" tab.\
Click the ⋮ menu next to the target account, then click **Delete**.

<img src="https://mintcdn.com/moneyforwardi/AltAQbgvkgrjVl2T/images/it-management/idp-account-management/id-lifecycle/service-open-id-action.png?fit=max&auto=format&n=AltAQbgvkgrjVl2T&q=85&s=0dd119117a4532ea890eb3ee34728437" alt="The Accounts tab on the service screen, with Delete selected from the ⋮ menu" width="1920" height="351" data-path="images/it-management/idp-account-management/id-lifecycle/service-open-id-action.png" />

b. Go to **Directory** > select the account to disable or delete > open the "Services" tab.\
In the "Actions" column for the target service, click **Delete**.

<img src="https://mintcdn.com/moneyforwardi/AltAQbgvkgrjVl2T/images/it-management/idp-account-management/id-lifecycle/directory-open-id-action.png?fit=max&auto=format&n=AltAQbgvkgrjVl2T&q=85&s=63cfc086199b123cef09d7432c4fd2cb" alt="The Services tab in Directory, with Delete selected in the Actions column" width="1920" height="150" data-path="images/it-management/idp-account-management/id-lifecycle/directory-open-id-action.png" />

The "Delete Microsoft Entra ID (Azure AD)" screen opens, where you choose either **Disable this ID** or **Delete this ID**.

<h2 id="disable-id">
  Disable an Entra ID-linked account
</h2>

This revokes access, but data in Microsoft Entra ID (Azure AD) and in the app itself is retained. Re-enabling the ID restores access. App assignments to Microsoft Entra ID (Azure AD)-managed services are kept as they are.

1. Select **Disable this ID**. To also unassign all apps at the same time, check **Also unassign all apps**.\
   This checkbox unassigns only direct assignments — group assignments and conditional access assignments are not affected.

   <img src="https://mintcdn.com/moneyforwardi/AltAQbgvkgrjVl2T/images/it-management/idp-account-management/id-lifecycle/disable-id-modal.png?fit=max&auto=format&n=AltAQbgvkgrjVl2T&q=85&s=b326e737b3c5a1fa15068fa023ba73aa" alt="The &#x22;Disable this ID&#x22; option selected, with the &#x22;Also unassign all apps&#x22; checkbox shown" width="1692" height="1034" data-path="images/it-management/idp-account-management/id-lifecycle/disable-id-modal.png" />

2. Click **Disable**. If you checked "Also unassign all apps," enter the target user's email address as a safety check. Then click **Disable**.

   <img src="https://mintcdn.com/moneyforwardi/AltAQbgvkgrjVl2T/images/it-management/idp-account-management/id-lifecycle/disable-id-confirm-input.png?fit=max&auto=format&n=AltAQbgvkgrjVl2T&q=85&s=5256be45aa4bbc26c17c46c70a368254" alt="The confirmation screen asking for the user's email address" width="1216" height="218" data-path="images/it-management/idp-account-management/id-lifecycle/disable-id-confirm-input.png" />

3. Once "Microsoft Entra ID (Azure AD) disabled" appears, the operation is complete.\
   Login to Microsoft Entra ID (Azure AD) and its apps is blocked once processing finishes, which can take a few minutes.\
   Click **Done** to close the screen.

   <img src="https://mintcdn.com/moneyforwardi/AltAQbgvkgrjVl2T/images/it-management/idp-account-management/id-lifecycle/disable-id-complete.png?fit=max&auto=format&n=AltAQbgvkgrjVl2T&q=85&s=7174f926f84a84cf5c5073b8bbb8f45f" alt="The completion screen showing &#x22;Microsoft Entra ID (Azure AD) disabled&#x22;" width="1302" height="526" data-path="images/it-management/idp-account-management/id-lifecycle/disable-id-complete.png" />

   <Info>
     A "Unassigned apps — needs review" entry is created for each app that was unassigned. For details, see [Checking assignment status and errors](/en/it-management/idp-account-management/entraid-assignment-status#unassigned-apps-need-review).
   </Info>

<h2 id="delete-id">
  Delete an Entra ID-linked account
</h2>

<Warning>
  This action revokes access and can result in data loss. Login is blocked as soon as it's applied, and the account may remain on the app side even after its assignment is unassigned.
</Warning>

Access is revoked, all app assignments are unassigned, and then Microsoft Entra ID (Azure AD) is deleted. Accounts on the SaaS side cannot be deleted directly. SCIM-supported apps are deprovisioned automatically; non-SCIM apps leave the account and need manual deletion. You can restore the ID within 30 days.

1. Select **Delete this ID**. A list of apps whose assignments will be unassigned is shown — review it.

   <img src="https://mintcdn.com/moneyforwardi/AltAQbgvkgrjVl2T/images/it-management/idp-account-management/id-lifecycle/delete-id-modal.png?fit=max&auto=format&n=AltAQbgvkgrjVl2T&q=85&s=4a50a935fca05e2a92e27c98dfc6dfb2" alt="The &#x22;Delete this ID&#x22; option selected, showing the list of apps to be unassigned and a confirmation input field" width="1292" height="1172" data-path="images/it-management/idp-account-management/id-lifecycle/delete-id-modal.png" />

2. As a safety confirmation, enter the target user's email address in the confirmation field, then click **Delete**.

3. Once "Microsoft Entra ID (Azure AD) deleted" appears, the operation is complete. Click **Done** to close the screen.\
   You can restore it within 30 days, but restoring does not re-assign apps — you'll need to provision them again.

   <img src="https://mintcdn.com/moneyforwardi/AltAQbgvkgrjVl2T/images/it-management/idp-account-management/id-lifecycle/delete-id-complete.png?fit=max&auto=format&n=AltAQbgvkgrjVl2T&q=85&s=7fe81e31f8a4f53eb2a2597828e0f884" alt="The completion screen showing &#x22;Microsoft Entra ID (Azure AD) deleted&#x22;" width="1308" height="614" data-path="images/it-management/idp-account-management/id-lifecycle/delete-id-complete.png" />

   <Info>
     A "Unassigned apps — needs review" entry is created for each app that was unassigned. For details, see [Checking assignment status and errors](/en/it-management/idp-account-management/entraid-assignment-status#unassigned-apps-need-review).
   </Info>

## Related pages

* [Assigning and unassigning apps for Entra ID-managed users](/en/it-management/idp-account-management/entraid-app-assignment)
* [Checking assignment status and errors](/en/it-management/idp-account-management/entraid-assignment-status)
