Remove user from Identity Center in AWS
Automatically remove a departing employee from IAM Identity Center from a Slack request with Stepwork. Remove their AWS account assignments and disable their access.
- Use case
- Employee offboardingIT
- Best for
- Cloud Administrator, IT Manager
- Applications used
AWS
Slack
- Business outcome
- Risk reduction
The problem
One person. A dozen AWS accounts.
Teams with many AWS accounts give people access through IAM Identity Center, one account assignment at a time. When someone leaves, each of those assignments has to go.
Done by hand, an admin works through the accounts one by one, or disables the user and leaves the assignments in place. Either way, there is no single record of when access ended across all of them.
The outcome
Access ends across every AWS account at once
Stepwork removes every account assignment for the user and disables their access in IAM Identity Center. The AWS access portal stops working for them, and the run records who asked and which accounts were cleared.
- Every account assignment is removed.
- The user’s access is disabled.
- The Slack reply lists the accounts that were cleared.
The process
From Slack request to no AWS account access
A teammate posts the request in Slack. Stepwork clears the user’s assignments in the IAM Identity Center console, account by account, in the same order every time.
- Step 1
Request it in Slack
A teammate posts the departing employee’s work email in the offboarding channel. That message starts the flow, and Stepwork records who asked and when.

- Step 2
Find the user
Stepwork signs in to the AWS console, opens IAM Identity Center, and finds the user with that exact email. If there is no match, or more than one, the run stops instead of guessing.

- Step 3
Remove account assignments
Stepwork removes the user from every AWS account they are assigned to, along with the permission sets on each.

- Step 4
Disable and reply in Slack
Stepwork disables the user’s access, checks that no assignments are left, then posts the list of cleared accounts in Slack.

Why Stepwork
Every account, not just the ones you remember
Stepwork runs the path you recorded in IAM Identity Center. It works through every account assignment the user has, not a list someone wrote down, then disables their access.
Similar use cases
Similar use cases
Deactivate IAM user in AWSDisables console access and deactivates credentials for an IAM user in the AWS console.
Deactivate user account in OktaSigns into the Okta admin console, locates the user by email, deactivates the account, and confirms the status change ended all SSO sessions.
Disable user account in Microsoft Entra IDSigns into the Entra admin center, locates the user, and blocks sign-in, disabling the account across Microsoft services.
FAQ





