When a sales representative or support agent leaves, removing their Salesforce access sounds simple. In a real Sales Cloud or Service Cloud org, that user may own open opportunities, active cases, scheduled reports, and automation that keeps daily work moving.
I have handled many user offboarding requests where the urgent requirement was “remove access now,” but the safer requirement was “remove access without breaking the org.”
The right approach is to freeze access first when needed, review dependencies, transfer important work, and then deactivate the Salesforce user.
This guide shows how to deactivate user in Salesforce, what to check before you do it, and how to resolve common deactivation errors.
What happens when you deactivate a Salesforce user?
When you deactivate a Salesforce user, Salesforce blocks that person from logging in and makes their user license available for reassignment.
Salesforce keeps the user record and historical activity because deleting users could remove important audit context.
For example, imagine a sales team with 20 representatives. One account executive leaves while owning 60 open opportunities and 180 accounts.
Deactivating the user removes their login access, but it does not automatically transfer those records to a new representative. You must handle record ownership separately.
A deactivated user can still appear in historical records, reports, and activity timelines. This is useful when managers need to review who created an opportunity, updated an account, or closed a case.
Before you deactivate a Salesforce user, remember these key outcomes:
- The user cannot log in to Salesforce.
- Their Salesforce license becomes available for another user.
- Salesforce retains their user record, activity history, and audit details.
- Records owned by the user do not automatically move to another owner.
- Existing automation, scheduled jobs, and email alerts may need a new active user.
- The user may remain in public groups, teams, or sharing-related configurations until you remove them.
Before you Deactivate a Salesforce User
A good offboarding process starts before you uncheck the Active checkbox.
I always treat user deactivation as a small admin project, especially when the person owns customer-facing records or works as an administrator.
Freeze User’s Access in Salesforce
Freezing a user immediately prevents login access. It is useful when someone leaves unexpectedly or when you need time to review ownership and automation dependencies.
Freezing does not free the user license. It only stops the user from accessing Salesforce while you complete the cleanup work.
To freeze a user:
- Click the gear icon and select Setup.
- Enter Users in the Quick Find box.
- Select Users.
- Open the user record.
- Click Freeze.

Use this step when security comes first. For example, freeze a departing support agent before you move their open cases to a new queue or team member.
Pro Tip: In my experience, freezing first avoids rushed changes. It gives you time to check record ownership, scheduled automation, and email recipients without leaving the user’s Salesforce login active.
Review Records Owned by the User
Ownership affects who can edit and manage business records. A departing sales rep may own Accounts, Contacts, Leads, Opportunities, custom-object records, and tasks.
Start by identifying records where the departing person is the owner. You can use list views, reports, or Salesforce’s ownership transfer options.
For a sales representative, review at least:
- Open leads that need follow-up.
- Accounts and contacts assigned to the rep.
- Open opportunities and opportunity teams.
- Tasks, events, and sales activities.
- Quotes, contracts, or custom objects tied to the sales process.
For a support agent, review:
- Open cases.
- Escalated cases.
- Case teams.
- Case queues.
- Knowledge or service-related ownership assignments.
If your business uses automation to assign work, also review your Salesforce assignment rules so new leads and cases do not continue routing to the former employee.
Check Automation & System Dependencies for User in Salesforce
A user can appear in more places than record ownership. Salesforce may prevent deactivation if the person holds an important system assignment.
Review whether the user is:
- The Default Workflow User.
- The default owner for new leads.
- The default owner for new cases.
- An approver in an active Approval Process.
- A recipient in workflow email alerts.
- The running user for scheduled reports or dashboards.
- The owner or submitting user for scheduled jobs.
- An integration user for an API, connected app, or middleware process.
- A delegated administrator or a high-level system administrator.
A Flow is Salesforce automation that runs actions based on a record change, schedule, or user interaction. Review flows that send emails, create records, or assign owners using a specific user. Where possible, use a queue, a custom metadata setting, or a dedicated active integration user instead of naming an individual employee.
If your org relies heavily on automation, review how to create a Salesforce Flow before changing user-related logic.
How to Deactivate User in Salesforce
This is a practical how-to guide. The steps apply to Salesforce Lightning Experience, which most current Salesforce organizations use.
You need the required administrative access to manage users. In most orgs, a System Administrator or someone with user-management permissions completes this task.
Step 1: Open the Users Setup page
- Click the gear icon in the upper-right corner.
- Select Setup.
- In the Quick Find box, type Users.
- Select Users under Administration.
You will now see the list of active and inactive users in your Salesforce org.
Step 2: Find and Open the User
Locate the user you want to deactivate. You can search by name, username, or email address.
Click Edit beside the user’s name. Salesforce opens the user-edit page, where you can review their profile, role, user license, and access settings.
Before changing anything, confirm you selected the correct user. Similar names, shared email aliases, and contractor accounts can cause mistakes in larger organizations.
Step 3: Uncheck the Active Checkbox
On the user-edit page, find the Active checkbox in the general user information section.
Clear the checkbox to mark the user as inactive.
The Active field controls whether that person can access your Salesforce organization. Clearing it starts the deactivation process and tells Salesforce that the user should no longer consume an active license.

Step 4: Save the User Record
Click Save.
Salesforce may display a user deactivation screen or warning message. The available options can vary based on your org setup and the user’s membership in teams or groups.
If Salesforce gives you options to remove the user from opportunity teams or case teams, review them carefully before saving. Remove the user where it supports your ownership and access plan.
Salesforce may stop the save if the user has a dependency, such as being the default case owner or an approval-process approver. Do not work around the error blindly. Identify the dependency, assign an active replacement, and try again.
Step 5: Confirm the User is Inactive
Return to Setup > Users and confirm the user shows as inactive.
You can also use an Inactive Users list view to verify the status. This final check matters because a failed save or unresolved dependency can leave the user active.
Transfer Ownership Before or After Deactivation
Salesforce allows you to transfer many records before or during the offboarding process. The best sequence depends on urgency.
If the user has immediate access that you must stop, freeze them first. Then transfer records and complete deactivation. If the user is still working through their final day, you can transfer ownership in a planned sequence.
For a departing account executive, I would usually follow this order:
- Freeze the user if immediate access removal is necessary.
- Export or report on their open pipeline.
- Reassign accounts, contacts, leads, and opportunities.
- Update opportunity teams and account teams.
- Reassign follow-up tasks and open activities.
- Review scheduled reports, dashboards, and automation.
- Deactivate the Salesforce user.
- Confirm the new owner can access the transferred work.
Use a Report to identify open work quickly. A report is a filtered, organized view of Salesforce data. For example, create an Opportunities report with these filters:
- Opportunity Owner equals the departing user.
- Stage does not equal Closed Won.
- Stage does not equal Closed Lost.
Group the report by Stage and then by Close Date. This helps the sales manager assign high-priority pipeline first.
You can also use a Salesforce report tutorial to build ownership reports for accounts, opportunities, cases, or custom objects.
Deactivate a Salesforce User in Classic
Some organizations still use Salesforce Classic for legacy pages or administrative work. The core action remains the same: clear the Active checkbox on the user record.
- Log in to Salesforce Classic.
- Click Setup.
- Under Manage Users, select Users.
- Locate the required user.
- Click Edit beside their name.
- Clear the Active checkbox.
- Click Save.
- Review any deactivation options or warnings, then save again.
Although Salesforce Classic uses a different interface, do not skip the same planning work. Check ownership, approvals, email notifications, integrations, and scheduled jobs before you deactivate the Salesforce user.
Fix “Unable to Deactivate User” errors
Salesforce blocks user deactivation to protect critical processes. The error message often points to the assignment that needs attention.
1. The User is the Default Workflow User
The Default Workflow User is an active user Salesforce uses in some automation scenarios. If the person leaving holds this assignment, select another active admin or operational user.
In Setup, search for Process Automation Settings. Update the default workflow user, save the change, and then retry the deactivation.
2. The User is the Default Lead or Case Owner
Salesforce may assign new leads or cases to a default user when assignment rules do not find a better match.
Update the Default Lead Owner in Lead Settings and the Default Case Owner in Support Settings. Use an active user or, where appropriate, a queue that your team monitors.
This is especially important in Service Cloud. A former support manager should never remain the fallback owner for new customer cases.
3. The User is an Approver
An Approval Process sends a record through one or more approval steps. If the departing user is a named approver, Salesforce may block deactivation or future approval requests may fail.
Open the relevant approval process and replace the individual approver with another active user, role, queue, or manager-based approver. Use role-based logic where possible because it is easier to maintain when employees change.
Learn more about setting up approval logic with this Salesforce approval process guide.
4. A Validation Rule Blocks the Update
A Validation Rule checks conditions and blocks a save when the record does not meet your business requirements. An overly broad validation rule on the User object can accidentally prevent Salesforce from changing the Active field.
Review Setup > Object Manager > User > Validation Rules. Look for rules that reference IsActive or validate required values during every user update.
A safer validation rule design often includes a condition that excludes a deactivation update when appropriate. Test any change in a sandbox before changing production logic.
5. The User owns Scheduled jobs or integrations
A scheduled job may run Apex, reporting, data processing, or managed-package automation under a specific user. An integration may also authenticate through a named user account.
Review scheduled jobs in Setup and identify jobs submitted by the user. Re-create or reschedule them under an appropriate active automation owner. For integrations, move the authentication to a dedicated integration user instead of another employee’s personal Salesforce account.
Things to Keep in Mind
- Freeze before cleanup: Freeze the account first when you need to stop access immediately but still need time to transfer ownership and resolve dependencies.
- Transfer business records: Deactivation does not automatically reassign accounts, opportunities, cases, leads, tasks, or custom-object records to another user.
- Review automation ownership: Check Flow, approval processes, workflow settings, scheduled jobs, email alerts, and integrations for references to the departing user.
- Use a dedicated integration user: Avoid connecting business-critical integrations through an individual employee’s account. A dedicated user prevents unexpected outages during offboarding.
- Check reports and dashboards: Reassign scheduled reports and dashboard running-user settings so leadership does not lose recurring updates.
- Document the offboarding: Record who transferred ownership, updated automation, changed approvals, and confirmed deactivation. This supports governance and future troubleshooting.
Frequently Asked Questions
Can I delete a Salesforce user instead of deactivating them?
No. Salesforce does not allow you to delete normal user records because they link to historical records, audit details, and activities. Deactivate the user to remove access while preserving that history.
Does deactivating a Salesforce user free a license?
Yes. Deactivating a user makes their Salesforce user license available for reassignment. Freezing a user does not free the license.
What is the difference between freezing and deactivating a user in Salesforce?
Freezing blocks login access but keeps the user active and continues consuming the license. Deactivating blocks access and releases the license, but Salesforce may require you to resolve ownership or system dependencies first.
Can I deactivate a user who owns opportunities and accounts?
Yes, but Salesforce does not automatically change ownership of those records. Transfer important accounts, opportunities, leads, cases, and activities to active users before or immediately after deactivation.
Why can’t I deactivate a Salesforce user?
Salesforce may block deactivation because the user is a default owner, workflow user, approval approver, scheduled-job owner, or part of a configuration that needs an active user. Read the error message, replace the user in that configuration, and then try again.
Can I reactivate a deactivated Salesforce user?
Yes, if you have an available license and the user’s username, profile, and access configuration remain valid. Review their permissions, role, permission sets, and authentication requirements before reactivating the account.
Conclusion
Deactivating a Salesforce user safely requires more than clearing one checkbox: protect access, review dependencies, transfer ownership, and verify the final inactive status.
Start with a simple offboarding checklist, test the process in a sandbox when possible, and use dedicated ownership for business-critical automation.
You May Also Like
- How to deactivate a Salesforce Developer Edition org
- How to check user licenses in Salesforce
- How to activate or deactivate a user from Salesforce Apex
- How to freeze or unfreeze multiple users through Salesforce Data Loader
- How to mass deactivate Salesforce users through Data Loader
I am Bijay Kumar, the founder of SalesforceFAQs.com. Having over 10 years of experience working in salesforce technologies for clients across the world (Canada, Australia, United States, United Kingdom, New Zealand, etc.). I am a certified salesforce administrator and expert with experience in developing salesforce applications and projects. My goal is to make it easy for people to learn and use salesforce technologies by providing simple and easy-to-understand solutions. Check out the complete profile on About us.