I’ve searched for an official BestPractice on user  deletion (leave company), but can’t find anything that is official-ish.


Two options:


  1. Change user psswd to nonsense, then expire account.
  2. DROP user.


There are +/- to both.


I prefer #1, as it gives the exact timestamp of expire (protects company and ex-employee), but corporate auditors disagree.


What do you do?  Any official guidance on this?



