Deactivate IAM user in AWS
Automatically deactivate a departing employee’s IAM user in AWS from a Slack request with Stepwork. Disable console sign-in and deactivate every active access key.
- Use case
- Employee offboardingIT
- Best for
- Cloud Administrator, IT Manager
- Applications used
AWS
Slack
- Business outcome
- Risk reduction
The problem
They’ve left. Their AWS keys still work.
IAM has no single switch that turns a user off. An admin has to disable the console password and then deactivate each access key, and on a busy offboarding day the second half is easy to miss.
A forgotten access key keeps working from any laptop or script, with the same reach into production it had the day before. Nobody records when cloud access ended, so the audit question has no answer.
The outcome
Console and key access both end
Stepwork disables console sign-in and deactivates every active access key on the IAM user. The user stays in place for the audit trail, and the run records who asked and when each change was made. It is the cloud step of employee offboarding, done in the right order.
- Console sign-in is disabled.
- Every active access key is deactivated, not deleted.
- The run stops if no IAM user has that name.
The process
From Slack request to deactivated IAM user
A teammate posts the request in Slack. Stepwork turns off the user’s access in the IAM console, in the same order every time.
- Step 1
Request it in Slack
A teammate posts the departing employee’s IAM user name in the offboarding channel. That message starts the flow, and Stepwork records who asked and when.

- Step 2
Find the IAM user
Stepwork signs in to the AWS console with a credential read from 1Password at run time and opens the IAM user with that exact name. If there is no match, the run stops instead of guessing.

- Step 3
Disable console sign-in
On the user’s security credentials, Stepwork turns off console access. The password no longer signs them in.

- Step 4
Deactivate access keys
Stepwork deactivates each active access key, so scripts and command-line tools using them stop working. Then it confirms both changes and replies in Slack.

Why Stepwork
Both halves, every departure
A deterministic agent runs both steps on every departure: console access, then access keys. It does not skip the keys when the request only mentions the console, and it stops if the user name matches nobody.
Similar use cases
Similar use cases
Remove user from Identity Center in AWSRemoves a user's IAM Identity Center assignments and disables their access across AWS accounts.
Deactivate access keys for user in AWSLocates a user's active access keys in IAM and deactivates them, cutting programmatic access.
Deactivate user account in OktaSigns into the Okta admin console, locates the user by email, deactivates the account, and confirms the status change ended all SSO sessions.
FAQ





