We should warn the admin that the account will be deleted or disabled if the user owns API keys.
Usually, when deleting or disabling a user who owns api keys, we should disable or delete them to avoid security issues.
Everything that the user can take outside of the admin console and can be used to read or write anything in the system should be deleted to avoid security issues.