Disable user account in Microsoft Entra ID
Automatically disable a departing employee’s Entra ID account from a Slack request with Stepwork. Find the user and block sign-in across Microsoft services.
- Use case
- Employee offboardingIT
- Best for
- IT Administrator, Helpdesk Technician
- Applications used
Microsoft Entra ID
Slack
- Business outcome
- Risk reduction
The problem
Gone from HR. Still signed in to Microsoft 365.
Blocking sign-in in Microsoft Entra ID ends Microsoft 365 and every app that signs in through it. Done by hand, it waits in the helpdesk queue behind every other ticket.
Until it happens, the person who left can still open Outlook, Teams, and SharePoint. When an auditor asks when access ended, the only answer is a closed ticket.
The outcome
Microsoft 365 stops accepting them when the request lands
Stepwork blocks sign-in in Microsoft Entra ID. Outlook, Teams, SharePoint, and the apps behind Entra stop accepting the person, and the run records who asked and when sign-in was blocked.
- Sign-in is turned off for the account.
- The run stops if the email has no match.
- The Slack reply includes the time access ended.
The process
From Slack request to blocked sign-in
A teammate posts the request in Slack. Stepwork blocks sign-in in the Microsoft Entra admin center, which ends access to Microsoft 365 and the apps that sign in through Entra.
- Step 1
Request it in Slack
A teammate posts the departing employee’s work email in the offboarding channel. That message starts the flow, and Stepwork records who asked and when.

- Step 2
Find the user by email
Stepwork signs in to the Microsoft Entra admin center and opens the user with that exact work email. If there is no match, the run stops instead of guessing.

- Step 3
Block sign-in
Stepwork turns off sign-in for the account. Microsoft 365 and the apps behind Entra stop accepting the person.

- Step 4
Confirm and reply in Slack
Stepwork checks that the account reads as disabled, then posts the result back in Slack with a timestamp.

Why Stepwork
Sign-in is blocked the same way for every departure
Stepwork runs the path you recorded in the Microsoft Entra admin center: find the user by email, turn off sign-in, and confirm the account is disabled. The time access ended is part of the run, not a note in a closed ticket.
Similar use cases
Similar use cases
Deactivate user account in OktaSigns into the Okta admin console, locates the user by email, deactivates the account, and confirms the status change ended all SSO sessions.
Suspend user account in Google WorkspaceSigns into the Google Admin console, locates the user, and suspends the account, blocking sign-in while preserving data.
Deactivate member account in SlackSigns into Slack admin, locates the member, and deactivates their account, removing workspace access.
FAQ





