Skip to content
LOG-097 Logs, Records & Provider Evidence

What is an account-disable event?

An account-disable event records that an account was placed into a state where it could no longer be used normally.

The action may be performed by an administrator, automated policy, security system or identity-management process.

Avoid the dangerous assumption

The dangerous assumption is that an account-disable event proves misconduct by the account holder or confirms that the account was compromised.

It proves neither by itself.

Accounts may be disabled because someone left an organisation, a licence expired, a security incident was suspected, a policy was triggered or an administrator made an error.

The event may include the target account, actor, reason, method, source address, result and timestamp. This can help establish when the status changed and which technical identity initiated the change.

But disabling an account may not terminate every existing session or token. Some applications may continue operating until cached access expires or the session is explicitly revoked.

Investigators should identify who or what initiated the disable action and whether it was manual or automated. Ask what policy or reason code applied and what effect the action had across connected services.

Preserve administrator audit logs, identity-provider records, role assignments, tickets and subsequent access attempts. Check whether the account was later re-enabled and by whom.

Do not assume the named administrator personally made the decision if the event was generated by an automated workflow or service account.

Operational takeaway

An account-disable event records a change in account status, but the reason, initiating actor, scope and effect on existing sessions must be established before wider conclusions are drawn.


Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.