Concerns with deleting SySAdmin in CASB
search cancel

Concerns with deleting SySAdmin in CASB

book

Article ID: 438680

calendar_today

Updated On:

Products

CASB Gateway Advanced CASB Advanced Threat Protection CASB Audit CASB Gateway CASB Security Advanced CASB Security Advanced IAAS CASB Security Premium CASB Security Premium IAAS CASB Security Standard CASB Securlet IAAS CASB Securlet SAAS CASB Securlet SAAS With DLP-CDS

Issue/Introduction

Are there any concerns with removing a CloudSOC SySAdmin?

Resolution

Before permanently deleting a SysAdmin user, disable the account for a designated grace period. A disabled account can be instantly restored if critical services fail, whereas a deleted account is irrecoverable.

Critical CloudSOC Dependencies

Service ImpactedRisk & VerificationResolution Steps
CASB SecurletsIf the Securlet was activated using the SysAdmin's personal credentials rather than a dedicated service account.

Verify: Contact Support to confirm the activating user.

Fix: Reactivate the Securlet using a service account with SysAdmin rights.

CloudSOC API KeysAPI keys generated by a SysAdmin will be invalidated upon account deletion.

Verify: Check the "Last Used" date on API keys created by this user.

Fix: Recreate necessary keys under a service account.

SpanVA OwnershipNote: Ownership is no longer required as of SpanVA .170 (Shipping early May 2026).Verify and fix: Update SpanVA ownership in CloudSOC | Settings | SpanVA details