Why Unneeded Accounts Are a Security Risk
Every backend user with access to your TYPO3 system is a potential point of attack – regardless of whether it's a former employee, an agency you no longer work with, or an external service provider. If an account remains active after that person's involvement ends, it can be misused without anyone noticing right away: for data access, content manipulation, or as a stepping stone for further attacks.
The rule is simple: as soon as someone no longer works for your organization, or their task in the TYPO3 backend is complete, the corresponding account should be deactivated promptly – or deleted entirely if it's no longer needed at all.
How to Spot Inactive Accounts
In the TYPO3 backend, you'll find the full list of backend users under System → Backend Users. The "Last Login" column shows at a glance when an account last signed in. An account that hasn't been used in months is a good candidate for deactivation – especially if you already know the person in question no longer works for you.
We recommend reviewing this list regularly, and at the very least after every personnel change.
Time-Limiting Accounts From the Start
If you already know in advance that someone will only work for your organization for a limited time – an intern, a student assistant, or a project-based contractor, for example – you don't even need to remember to deactivate their account later. TYPO3 lets you give every backend user account a validity period with a start and end date. Once the end date passes, the account can no longer log in automatically, with no manual action required.
This not only reduces administrative effort, but also reliably closes the gap that opens up when a planned deactivation is simply forgotten.