I am trying to use federated authentication (OAuth2 / SAML) in a web application. While federating authentication and possibly, authorization, how to deal with data of users who are deleted?
AFAIK there are no delete events propagated to applications from identity providers when a user is deleted.
Example: Deleting the data associated with user, when the account is deleted from external identity provider (Google, Facebook, or some enterprise identity server).