Leave-of-absence access refers to how an employer manages an employee's system and facility permissions while that person is away on extended leave. It is a genuine gap in most access governance, because the employee has not left — so offboarding does not apply — but they are also not working, which means their credentials sit unused and unmonitored for weeks or months.
Dormant accounts with valid credentials are attractive targets precisely because nobody is watching them. If an account belonging to someone on a three-month leave is compromised, there is no user to notice anything unusual.
Suspending access during leave reduces exposure. It also carries risks of its own, and they are not purely operational.
Employees on protected leave are entitled to be restored to their position, and to be free from retaliation for taking leave. Access changes that go beyond a security rationale — or that are applied inconsistently — can look like adverse treatment. An employee returning from medical leave to find their access reduced relative to what they held before has a plausible complaint, particularly if colleagues on other kinds of leave were treated differently.
There is also a practical dimension. Employees on leave frequently need continued access to benefits information, pay statements, and leave status. Cutting off all access can leave someone unable to check whether their benefits are continuing or their leave has been approved, which is both unhelpful and likely to generate its own dispute.
The approach that satisfies both concerns is differentiated suspension: suspend operational access, retain self-service access.
That means network, email, and business system access is suspended for the duration of the leave, while the employee retains access to the self-service portal for pay statements, benefits information, and leave status. The security exposure of a dormant operational account is removed; the employee's legitimate needs are preserved.
Two conditions make this defensible. It must be applied uniformly to all extended leaves regardless of reason, and it must be documented as standard practice rather than decided case by case. Consistency is what distinguishes a security control from selective treatment.
Employers occasionally handle access differently depending on why someone is out — treating a medical leave differently from a sabbatical, or an investigation-related suspension differently from parental leave. Some of those distinctions have legitimate bases, but they need to be articulated in advance and applied by category, not improvised.
The specific risk is that access decisions reveal information about the leave that should remain confidential. If the organization handles medical leaves visibly differently, colleagues can infer the reason for someone's absence from how their accounts were handled. Medical information is subject to confidentiality obligations, and inadvertent disclosure through operational practices is still disclosure.
Work continues while someone is on leave, which means someone else needs access to what they were handling. This is where a second, quieter problem develops.
The common shortcut is granting a colleague access to the absent employee's account or mailbox. That destroys attribution — actions taken appear to come from the person on leave — and creates a credential-sharing practice that tends to persist after the leave ends.
The correct approach is granting the covering employee appropriate access under their own identity, with delegated mailbox access where needed rather than shared credentials, and a defined end date tied to the expected return. That delegation should then be reviewed and removed when the employee comes back — a step that is regularly skipped, leaving the covering employee with permissions they no longer need.
Restoration should return the employee to the access they held before, promptly, as part of the return process. Two failures are common.
The first is delay — an employee returning to find they cannot do their job for several days because access restoration was not prepared in advance. Beyond the operational cost, it undermines the employer's position on restoration obligations.
The second is incompleteness. Access suspended across multiple systems is often restored only partially, because there was no record of everything that was suspended. Documenting what was suspended at the start of the leave makes restoration verifiable rather than reconstructed.
Employer's Guardian helps employers administer extended leaves consistently, including the documentation and process that keep handling defensible, through leave-of-absence management.
This article provides general educational information, not legal advice. Leave entitlements and restoration obligations vary by jurisdiction. Consult qualified counsel before establishing leave practices.