Stepwork logoStepwork logo
ProcedureDeterministic AgentsMarketplaceSecurityClaude Co-Work Alternative
Book a Demo
ProcedureDeterministic AgentsMarketplaceSecurityClaude Co-Work Alternative
Book a Demo
  1. Home
  2. Marketplace
  3. Deactivate IAM user in AWS

Deactivate IAM user in AWS

Automatically deactivate a departing employee’s IAM user in AWS from a Slack request with Stepwork. Disable console sign-in and deactivate every active access key.

Matt SilvaEngineering Lead

Book a DemoSee the process
Use case
Employee offboardingIT
Best for
Cloud Administrator, IT Manager
Applications used
  • AWS
  • Slack
Business outcome
Risk reduction

On this page

  1. The problem
  2. The outcome
  3. The process
  4. Why Stepwork
  5. Similar use cases
  6. FAQ
IT
  • AWS

Deactivate IAM user

One Slack request. Console sign-in off, access keys deactivated.

Book a Demo

The problem

They’ve left. Their AWS keys still work.

IAM has no single switch that turns a user off. An admin has to disable the console password and then deactivate each access key, and on a busy offboarding day the second half is easy to miss.

A forgotten access key keeps working from any laptop or script, with the same reach into production it had the day before. Nobody records when cloud access ended, so the audit question has no answer.

The outcome

Console and key access both end

Stepwork disables console sign-in and deactivates every active access key on the IAM user. The user stays in place for the audit trail, and the run records who asked and when each change was made. It is the cloud step of employee offboarding, done in the right order.

Employee offboarding
  • Console sign-in is disabled.
  • Every active access key is deactivated, not deleted.
  • The run stops if no IAM user has that name.

The process

From Slack request to deactivated IAM user

A teammate posts the request in Slack. Stepwork turns off the user’s access in the IAM console, in the same order every time.

  1. Step 1

    Request it in Slack

    A teammate posts the departing employee’s IAM user name in the offboarding channel. That message starts the flow, and Stepwork records who asked and when.

    Slack message in #offboarding asking to deactivate IAM user jlee-temp in AWS
  2. Step 2

    Find the IAM user

    Stepwork signs in to the AWS console with a credential read from 1Password at run time and opens the IAM user with that exact name. If there is no match, the run stops instead of guessing.

    AWS IAM users search for jlee-temp, showing one active match
  3. Step 3

    Disable console sign-in

    On the user’s security credentials, Stepwork turns off console access. The password no longer signs them in.

    IAM user jlee-temp with console sign-in disabled and both access keys still active
  4. Step 4

    Deactivate access keys

    Stepwork deactivates each active access key, so scripts and command-line tools using them stop working. Then it confirms both changes and replies in Slack.

    IAM user jlee-temp with console sign-in still disabled and both access keys inactive
Slack message in #offboarding asking to deactivate IAM user jlee-temp in AWS
AWS IAM users search for jlee-temp, showing one active match
IAM user jlee-temp with console sign-in disabled and both access keys still active
IAM user jlee-temp with console sign-in still disabled and both access keys inactive

Why Stepwork

Both halves, every departure

A deterministic agent runs both steps on every departure: console access, then access keys. It does not skip the keys when the request only mentions the console, and it stops if the user name matches nobody.

Deterministic agents
Book a Demo

Similar use cases

Similar use cases

  • Remove user from Identity Center in AWSRemoves a user's IAM Identity Center assignments and disables their access across AWS accounts.Learn more
  • Deactivate access keys for user in AWSLocates a user's active access keys in IAM and deactivates them, cutting programmatic access.Learn more
  • Deactivate user account in OktaSigns into the Okta admin console, locates the user by email, deactivates the account, and confirms the status change ended all SSO sessions.Learn more

FAQ

Common questions

  • Post the IAM user name in Slack. Stepwork disables console sign-in and deactivates every active access key, then replies with the result.
  • No. The user and its keys stay in place, deactivated, so the history remains for audits. A deactivated key can be turned back on if needed.
  • Those are separate from IAM users. A different flow removes the user from Identity Center.
    Remove user from Identity Center in AWS

See it run on a process you already repeat

Bring one. We will show you what it looks like as a flow and what each run records.

Book a Demo
Stepwork

Deterministic agents for work that must run the same way every time.

ProcedureDeterministic AgentsMarketplaceSecurityClaude Co-Work AlternativeFAQ
Terms and ConditionsPrivacy PolicyData Processing AgreementSubprocessors

2261 Market Street #4481, San Francisco, CA 94114, USA

Loot Discount inc dba Stepwork

© 2026 Stepwork. All rights reserved.