REGISTER REVISED SEPTEMBER 2026

Account reconciliation: matching application accounts to people

ILM Reference editors · Published 2026-05-12 · 2 minute read

TRACK: RUNNING THE PROGRAM · LESSON 9 OF 11

SUMMARYREV. 2026-09

Account reconciliation compares the accounts inside an application with your authoritative sources, usually the HR system and a register of non-human account owners. Every account ends up in one of four groups: matched to a current person, matched to a leaver, unmatched, or non-human with a named owner. The leaver and unmatched groups are your orphan candidates.

§ 01

What are the steps?

  1. Extract the account list from the application: from its admin console, its database or its API. Record the extraction date and who ran it.
  2. Normalize the matching fields. Lower-case email addresses, strip domain suffixes if the application uses short names, and keep the employee ID if the application stores one.
  3. Match each account to the HR system on the strongest key available: employee ID first, then work email, then a name match that a person confirms.
  4. Classify every account into one of the four groups below.
  5. Act and record. Assign owners, disable orphans or flag them for the next review, and keep the classified list as evidence.
§ 02

What are the four groups?

Reconciliation outcomes.
GroupWhat it meansAction
Matched, currentLinked to a current employee or contractorKeep; include in reviews
Matched, leaverLinked to a person whose HR record shows they leftDisable now; investigate why the leaver process missed it
UnmatchedNo match to any person or ownerTreat as an orphan candidate; find an owner or disable
Non-humanService, integration or break-glass accountConfirm a named owner; review credentials
§ 03

How do tools help?

Where an application is connected, the governance platform does most of this for you. Microsoft Entra ID Governance documents an account discovery report showing application users that do not match any Entra ID user, and for applications that do not support provisioning it documents exporting the users to CSV, matching them to Entra users and creating role assignments before a review. Discovery tools such as Orchid Security state that they map the accounts inside applications, including local and orphaned accounts, and feed that to the IGA. Veza reveals local, machine and service accounts in the systems it integrates with.

§ 04

What goes wrong?

  • Matching on display names. Two people with the same name, or one person whose name changed, produce false matches.
  • Deleting unmatched accounts before anyone checks them. Some are service accounts that production depends on. Flag first, disable after the owner confirms.
  • Reconciling once. Accounts are created every week; reconciliation belongs before every review and after every major leaver wave.

The orphan accounts guide covers removal safely, and the account states lesson defines each outcome.

Sources

Reviewed Sep 2026

NEXT LESSONREV. 2026-09

Next lesson: Leaver deprovisioning time

One metric, measured per application, that shows where the leaver process is slow.

Related

GUIDEREV. 2026-09
LESSONREV. 2026-09
TERMREV. 2026-09