Deactivating vs Freezing Users (Users Cannot Be Deleted)
5 minutes
5 Questions
In Salesforce, users cannot be deleted from an organization. This design choice preserves data integrity because users are tied to records, historical data, audit trails, and various relationships throughout the platform. Instead of deletion, administrators have two options for managing user access…In Salesforce, users cannot be deleted from an organization. This design choice preserves data integrity because users are tied to records, historical data, audit trails, and various relationships throughout the platform. Instead of deletion, administrators have two options for managing user access: deactivating and freezing.
Deactivating a user permanently removes their ability to log in and frees up a Salesforce license, which can then be reassigned to another person. When a user is deactivated, their historical data remains intact, and they can still appear in record ownership fields. However, deactivation may not be possible right away if the user is part of certain configurations, such as being assigned in workflow email alerts, being a default lead owner, or holding a role with subordinates. In these cases, the administrator must first reassign or update those references before completing the deactivation.
Freezing a user is a quicker action that prevents the user from logging in temporarily but does not release their license. Freezing is useful when an administrator needs to block access fast, for example during a security concern or while preparing to fully deactivate someone who has complex dependencies. Because freezing does not free up a license, it is considered a temporary measure rather than a permanent solution.
The key difference is that freezing halts access quickly while keeping the license consumed, whereas deactivation stops access and returns the license for reuse. A common best practice is to freeze a user first to secure the account, then resolve any blocking dependencies, and finally deactivate the user to reclaim the license. Both approaches maintain the user's associated records and history, ensuring that reporting, ownership, and compliance requirements remain accurate across the organization while controlling active access appropriately.
Deactivating vs Freezing Users (Users Cannot Be Deleted)
Overview In Salesforce, one of the most fundamental administrative concepts is understanding that users cannot be deleted. Once a user record is created, it remains in the system permanently. This is because users are tied to records they own, activities they logged, and audit history. To manage users who no longer need access, administrators rely on two key options: Deactivating and Freezing.
Why This Is Important Understanding the difference between deactivating and freezing users is essential for maintaining data integrity, security, and license management. When an employee leaves the company or changes roles, an administrator must know the correct action to take. Choosing the wrong option could leave sensitive access open or fail to free up a valuable user license.
What Is Deactivating a User? Deactivating a user permanently revokes their login access and frees up their Salesforce license, which can then be assigned to another person. When a user is deactivated:
• They can no longer log in to Salesforce. • Their license becomes available for reassignment. • Their historical data, records, and ownership remain intact. • They can be reactivated later if needed.
However, there is an important consideration. If a user is referenced in certain configuration areas, they may not be able to be deactivated until those references are reassigned. Examples include:
• Being the recipient of workflow email alerts. • Being selected in a custom hierarchy field. • Being assigned as the sole approver in an approval process.
What Is Freezing a User? Freezing a user is a quicker, temporary action that blocks a user from logging in but does not free up their license. Freezing is useful when you need to stop access quickly while you handle the longer process of reassigning records and configuration references before full deactivation.
Key points about freezing:
• The user can no longer log in. • Their license remains consumed (it is NOT released). • It is a temporary measure that can be reversed by unfreezing. • It happens faster than deactivation because it does not check configuration dependencies.
How It Works Together A common real-world workflow is to first freeze a departing employee to halt access at once, then work through reassigning their records, workflow references, and approval steps, and finally deactivate them to reclaim the license. This two-step approach balances security with proper data management.
Key Differences Summary
• Deactivate: Blocks login AND releases the license. May require clearing configuration references first. • Freeze: Blocks login only. License stays consumed. Fast and reversible. • Delete: NOT possible for users in Salesforce.
Exam Tips: Answering Questions on Deactivating vs Freezing Users (Users Cannot Be Deleted)
• Remember the golden rule: users can never be deleted in Salesforce. If an answer option says to delete a user, it is incorrect.
• When a question emphasizes freeing up a license, the correct answer is deactivate.
• When a question emphasizes stopping access quickly or temporarily, the correct answer is freeze.
• Watch for scenarios where an admin cannot deactivate a user right away. This usually points to a configuration dependency, such as workflow email alerts or approval process assignments, that must be reassigned first.
• If a scenario describes a suspected security breach needing an urgent response, freezing is often the best first step since it is fast and reversible.
• Freezing does NOT release a license, so eliminate any option that claims freezing frees up a license.
• Look for keywords in the question: temporary and quick lean toward freezing, while permanent and reassign license lean toward deactivation.
• Some questions combine both actions, describing a freeze followed by cleanup and then deactivation. Recognize this as the recommended best-practice workflow.