How do I de-provision Workplace users who have left my organization or company?
When an employee leaves your organization, it's important to ensure that their Workplace account is disabled on a timely basis. This is true even if you use single-sign on for authentication because authentication tokens don't expire immediately.
If you're using automated provisioning through an IDP or AD Sync, this should be enabled by default. If you're using manual provisioning or CSV, you should ensure that the deactivation of Workplace accounts is a part of your employee termination process flow.