Account Management | Disable Inactive Accounts
User accounts will be monitored monthly and accounts will be disabled after 90 days of inactivity; this will be a manual review process every 30 days. 18F generates a credential report that lists all IAM users and the status of their credentials, including passwords, access keys, and MFA devices.
Access Control Policies for 18F
18F manages information system identifiers for users and devices by: Disabling the user identifier after ninety (90) days of inactivity for general user accounts and thirty (30) days for administrator level accounts.