All Resources
IT Support

IT Offboarding Checklist: What to Do When an Employee Leaves

How you offboard an employee is often more consequential than how you onboard them. Poor offboarding leaves active accounts, forwarded email, orphaned OneDrive files, and personal devices with company data. This checklist walks through the exact steps to offboard cleanly, protect the business, and preserve the data you're legally required to keep. Do not skip steps in a hurry — but also do not take irreversible actions like deleting mailboxes before data has been secured.

Published July 22, 2026 10 min read Greater Sudbury & Ontario

Disable sign-in

The first action, timed with the employee's departure, is to disable sign-in on the Microsoft 365 account. This prevents further access while preserving the mailbox and OneDrive contents for retention. Do not delete the account — deletion is later and only after data is secured.

Revoke sessions

Disabling sign-in alone doesn't cancel already-authenticated sessions. Explicitly revoke sessions in Entra ID so any open browser or mobile app tokens are invalidated immediately.

Reset or transfer access

  • Reset the password (further blocks re-authentication)
  • Remove from all groups that grant application or file access
  • Remove any admin roles
  • Transfer ownership of files, sites, and Teams they owned

Email and OneDrive retention

Depending on your industry, you may need to retain email and files for months or years. Apply your retention policy before deletion. In Microsoft 365 you can typically convert the mailbox to shared, apply a litigation or retention hold, and move OneDrive contents to a designated location.

Shared mailbox conversion

Converting the mailbox to shared preserves the email history and can be accessed by a manager or successor without holding a licence. For roles where the ex-employee received customer email, this is often the safest option.

Device return

  • Collect the laptop, dock, and any assigned peripherals
  • Sign out and wipe the device via endpoint management
  • Reimage for the next user or return to inventory
  • Recover any mobile phones or tablets issued by the business

MFA methods

Remove any MFA methods tied to the user's personal device (authenticator app, personal phone number) so they cannot be used to re-authenticate. This is often overlooked.

Password changes

Rotate any shared credentials the employee had access to — service accounts, shared inboxes, Wi-Fi keys, admin passwords. This is the biggest gap in most offboarding processes.

Third-party applications

  • Line-of-business software: revoke the user's access
  • SaaS tools with individual accounts (CRM, accounting, project tools)
  • External vendor portals they had login to
  • Password manager: transfer any business-critical vaults, then remove the user

Data ownership

Confirm that any business data on personal devices (BYOD phones, personal laptops if allowed) is removed. If your MDM policies allow selective wipe, run it. If not, treat this as a gap to close in your policy.

Documentation

Record the offboarding date, who performed each step, and what was retained or transferred. This is essential for audit trails and for any future data requests.

Frequently asked questions

Should we delete a Microsoft 365 account when someone leaves?

Not immediately. Disable sign-in and revoke sessions right away. Convert the mailbox to shared or apply retention. Only delete the account after your retention window has passed and all required data has been transferred.

How quickly do we need to disable a departing employee's access?

As close to the departure moment as possible — ideally at the same time as the exit conversation. Delays are how disgruntled departures cause damage.

What about the employee's OneDrive files?

Transfer ownership to a manager or move the folder to a shared location. Don't rely on the user having saved everything to shared sites already — most people haven't.

Do we need to rotate every shared password?

Yes, every credential the ex-employee had access to should be rotated. Passwords are only as private as the people who know them.

Who's responsible for the process — HR or IT?

HR triggers the process and owns the human side. IT executes the technical checklist. Both should sign off before the file is closed.

Book a free 30-minute IT assessment

See exactly where your business technology stands and get a clear, no-pressure plan for what to fix first — no obligation and no sales pressure.

Keep exploring

Related services, locations, and resources

Related services

Related resources