---
title: "Deactivate user"
method: POST
path: "/users/{userId}/deactivate"
tags: ["users"]
---

# Deactivate user

`POST /users/{userId}/deactivate`

Deactivates the user associated with the current Smartsheet plan, blocking the user from using Smartsheet in any way. Deactivating a user does not affect their existing permissions on owned or shared items.

Optionally, with Enterprise Plan Manager (EPM) enabled, you can deactivate a user from child organizations.

> **Who can use this operation?**
> 
> **Permissions:** System Admin
>
> This operation is unavailable for Smartsheet Gov.

Attempting to deactivate a user that matches any of the following criteria results in an error:
- The user's primary email address belongs to an ISP domain (e.g., `gmail.com`, `yahoo.com`, `outlook.com`). For example, see the common ISP domains listed below.
- The user's primary email address is unassociated with the current Smartsheet plan domain(s).
- The user is managed by an external source, such as an identity provider (IdP) or directory integration (DI) provider. External source examples include Okta and Azure AD. Deactivating such a user can only be done via the external source.

Users with primary email addresses on the following ISP domains cannot be deactivated:
- `aol.com`
- `charter.net`
- `comcast.net`
- `duck.com`
- `email.com`
- `gmail.com`
- `hotmail.com`
- `icloud.com`
- `live.com`
- `mail.com`
- `mail.ru`
- `outlook.com`
- `rocketmail.com`
- `usa.com`
- `verizon.net`
- `web.de`
- `yahoo.com`

## Response `200`

Returns the result object.

- GenericResult
  - `message` 'PARTIAL_SUCCESS' | 'SUCCESS' — Message that indicates the outcome of the request. (One of `SUCCESS` or `PARTIAL_SUCCESS`.)
  - `resultCode` 0 | 3 — * '0' Success * '3' Partial Success of Bulk Operation

## Other responses

- `400` — The user is managed from a directory service. Example response: ```json { "errorCode": 5697, "message": "This person is managed from your directory service. Please deactivate them through your directory service instead.", "refId": "abcd1234" } ```
- `403` — This can be caused by the following situations: - User account has a common ISP domain email. ```json { "errorCode": 1359, "message": "User account with a common ISP domain email cannot be deactivated. You can only remove them from the Org.", "refId": "abcd1234" } ``` - User is external: in your org, not in your EPM child org, or has no internal planMembership in your plan. ```json { "errorCode": 1004, "message": "You are not authorized to perform this action.", "refId": "abcd1234" } ```
- `default` — Generic Error Payload

---

[API](https://skmtc.net/smartsheet/apis/smartsheet-openapi-reference.md) · [All operations](https://skmtc.net/smartsheet/apis/smartsheet-openapi-reference/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/smartsheet/smartsheet-openapi-reference/versions/b4afda95fb51/schema)
