Usually in one of those scenarios, you will try to hold, say a fired employee for that long in order to deactivate all their accounts and access anyway... in reality it's not much of an increased risk...
You still could blacklist, but realistically most areas don't need a dedicated revocation check. Some critical areas might, depending on the space.