Skip to main content

How do you revoke remote access?

You revoke remote access by deactivating the relevant accounts, keys, or sessions in the system granting access, such as a VPN server, a remote desktop tool, or an identity management platform. This applies to employees leaving the company, contractors whose contracts are expiring, or devices that have been lost or stolen. In the sections below, we cover the most common methods and steps. Do you have questions about your specific situation? Feel free to contact us With Sellox, we are happy to help you further.

What methods exist to grant remote access?

The most commonly used methods for granting remote access are VPN connections, remote desktop software (such as RDP or TeamViewer), cloud-based access platforms, and SSH keys for server management. Each method has its own mechanism for granting and revoking access, which determines the steps you need to take to effectively lock someone out.

It is important to know which methods are active within your organization, because access sometimes occurs via multiple channels simultaneously. For example, an employee may have both a VPN account and a remote desktop connection. Effective access control therefore starts with a complete overview of all active connections and the associated accounts.

How do you revoke remote access via a VPN?

You revoke remote access via a VPN by deactivating or deleting the user account in the VPN management console, revoking the associated certificates, and forcibly terminating any active sessions. As long as the account remains active on the VPN server, the user can reconnect, even if other access rights have already been revoked.

The exact steps depend on the VPN software you are using. With solutions such as OpenVPN, Cisco AnyConnect, or WireGuard, you manage users via an admin panel or configuration files. Remember to also deactivate any two-factor authentication tokens or hardware keys linked to the account. With cloud-based VPN services, revoking access is often handled through a central identity platform such as Azure Active Directory or Okta.

How do you remove remote desktop access from a device?

You remove remote desktop access by disabling the remote desktop function on the target device, removing the user account from the list of allowed users, and ending active sessions via the session management settings of the operating system or the software used. For third-party tools, such as TeamViewer or AnyDesk, you also remove the device from the administrator's account overview.

Disabling Remote Desktop Protocol (RDP) on Windows

Go to System Properties, click on the “Remote” tab, and disable the option for remote connections. Then, remove any users who had explicit access via the “Select Users” button. This ensures that no one can connect to the device via RDP anymore.

Revoke access to third-party remote desktop software

For tools such as TeamViewer or AnyDesk, log in to the management console of the corporate account. Remove the relevant device or user from the shared devices list there. Also change the password of the administrator account if the user had access to it, and check that no unattended access modes are active.

What should you do after revoking remote access?

After revoking remote access, verify that all active sessions have actually been terminated, document the actions performed with a timestamp, and scan the log files for suspicious activity that occurred before the revocation. These are the steps that determine whether the revocation is complete and verifiable.

  • Check the audit logs of the VPN server, the operating system, and any remote desktop tools for recent connections.
  • Verify that the account is also disabled in linked systems, such as email, cloud storage, and internal applications.
  • Save a written confirmation of the date and time at which access was revoked.
  • Inform the relevant colleagues or the security team about the changes made.

Also, do not forget to change passwords for shared accounts if the departing user had access to them. Shared credentials are a common security vulnerability that is overlooked when offboarding employees or contractors.

Why is revoking remote access a security risk if it happens too late?

If remote access is not immediately revoked after the termination of employment or collaboration, an active access channel to sensitive systems remains open. This increases the risk of data breaches, unauthorized modifications, and sabotage, because the former user can technically still log in as if nothing has changed.

In practice, many security incidents can be traced back to accounts that were not deactivated in a timely manner. A former employee holding a grudge, or an attacker using stolen credentials, can remain active undetected for weeks or months without a monitoring process. The longer the delay, the greater the potential damage. Good access management therefore requires that revoking access be part of a standardized offboarding process, not a manual oversight.

How do you prevent unauthorized remote access in the future?

Unauthorized remote access is prevented by a combination of strict identity verification, regular account reviews, and automated deactivation upon termination. A central identity management platform makes it possible to revoke access quickly and completely from a single point, instead of manually going through multiple systems.

Additional measures that further reduce the risk:

  • Multi-factor authentication (MFA): Even if login credentials are stolen, an attacker cannot log in without the second factor.
  • Minimal access rights (least privilege): Give users access only to the systems they really need for their work.
  • Regular access reviews: Periodically check who has access to which systems and remove unnecessary rights.
  • Automated offboarding: Link HR processes to access management so that accounts are automatically deactivated upon termination of employment.
  • Monitoring and alerting: Set up notifications for unusual login attempts or connections outside business hours.

A proactive approach to access management is the most effective way to prevent former users or malicious actors from retaining access to systems they are no longer authorized to use. Would you like to know how Sellox can support your organization with this? Contact us and discuss the possibilities with one of our specialists.

Frequently Asked Questions

How soon must remote access be revoked after termination?

Remote access should ideally be revoked the moment employment or collaboration officially ends — preferably before the last working day. In sensitive situations, such as summary dismissal, it is advisable to revoke access immediately and simultaneously via all channels to eliminate any risk. Automate this process by linking HR systems to your identity management platform so that no delays occur due to manual actions.

What do I do if I don't know through which channels an employee had access?

Start by auditing your identity management platform (such as Azure AD or Okta) and check all active accounts, roles, and linked applications for the user in question. Additionally, consult the log files of your VPN server, remote desktop tools, and cloud environments for recent activity of that account. If no central overview is available, this is a strong signal that it is time to implement a centralized access management system.

Can a user still gain access if I only reset the password but do not deactivate the account?

Yes, a password reset alone is insufficient to permanently block access. If the account remains active, a user can still gain access via password recovery processes, linked SSO sessions, or active tokens. The only reliable method is to completely deactivate or delete the account and terminate all active sessions in every affected system.

How do I handle revoking access for freelancers or external contractors who have completed multiple projects?

At the start of every collaboration, make clear agreements regarding the scope and duration of access, and document this in an access policy. Use time-bound accounts or licenses that automatically expire at the end of a contract so that you are not dependent on manual action. Conduct an access review at the end of each project to verify that all rights have been revoked, including access to cloud storage, project management software, and communication tools.

What are the most common mistakes when revoking remote access?

The most common errors are: deactivating only the primary account but forgetting to update linked systems, failing to force-end active sessions, and not changing shared passwords after a user leaves. Another common mistake is the lack of documentation, making it impossible to demonstrate retrospectively when and how access was revoked. A standardized offboarding checklist helps to prevent these errors structurally.

How do I know if unauthorized login attempts are still occurring after access has been revoked?

Configure monitoring and alerting at the level of your VPN server, identity management platform, and remote desktop tools so that you automatically receive a notification for login attempts using deactivated accounts. Additionally, regularly check the audit logs for attempts using the former user's username or email address. If you use a Security Information and Event Management (SIEM) system, you can set specific rules that immediately flag suspicious activity related to deactivated accounts.

Is it necessary to also wipe or block devices when revoking remote access?

That depends on whether the device is owned by the organization or by the user themselves (BYOD). For company devices, it is recommended to perform a remote wipe or blocking via Mobile Device Management (MDM) so that sensitive company data remains inaccessible. For private devices, revoking access rights and deleting company profiles or applications via the MDM system, in accordance with your organization's privacy policy, is sufficient.