Account reconciliation: matching application accounts to people
ILM Reference editors · Published 2026-05-12 · 2 minute read
TRACK: RUNNING THE PROGRAM · LESSON 9 OF 11
Account reconciliation compares the accounts inside an application with your authoritative sources, usually the HR system and a register of non-human account owners. Every account ends up in one of four groups: matched to a current person, matched to a leaver, unmatched, or non-human with a named owner. The leaver and unmatched groups are your orphan candidates.
What are the steps?
- Extract the account list from the application: from its admin console, its database or its API. Record the extraction date and who ran it.
- Normalize the matching fields. Lower-case email addresses, strip domain suffixes if the application uses short names, and keep the employee ID if the application stores one.
- Match each account to the HR system on the strongest key available: employee ID first, then work email, then a name match that a person confirms.
- Classify every account into one of the four groups below.
- Act and record. Assign owners, disable orphans or flag them for the next review, and keep the classified list as evidence.
What are the four groups?
| Group | What it means | Action |
|---|---|---|
| Matched, current | Linked to a current employee or contractor | Keep; include in reviews |
| Matched, leaver | Linked to a person whose HR record shows they left | Disable now; investigate why the leaver process missed it |
| Unmatched | No match to any person or owner | Treat as an orphan candidate; find an owner or disable |
| Non-human | Service, integration or break-glass account | Confirm a named owner; review credentials |
How do tools help?
Where an application is connected, the governance platform does most of this for you. Microsoft Entra ID Governance documents an account discovery report showing application users that do not match any Entra ID user, and for applications that do not support provisioning it documents exporting the users to CSV, matching them to Entra users and creating role assignments before a review. Discovery tools such as Orchid Security state that they map the accounts inside applications, including local and orphaned accounts, and feed that to the IGA. Veza reveals local, machine and service accounts in the systems it integrates with.
What goes wrong?
- Matching on display names. Two people with the same name, or one person whose name changed, produce false matches.
- Deleting unmatched accounts before anyone checks them. Some are service accounts that production depends on. Flag first, disable after the owner confirms.
- Reconciling once. Accounts are created every week; reconciliation belongs before every review and after every major leaver wave.
The orphan accounts guide covers removal safely, and the account states lesson defines each outcome.
Sources
- Microsoft Learn, existing users of an application
- Microsoft Learn, apps that do not support provisioning
- Orchid Security, platform
- Veza access reviews
- AC-2 control text, catalog mirror
Reviewed Sep 2026
Next lesson: Leaver deprovisioning time
One metric, measured per application, that shows where the leaver process is slow.