IT Offboarding Checklist: What to Do When an Employee Leaves
How you offboard an employee is often more consequential than how you onboard them. Poor offboarding leaves active accounts, forwarded email, orphaned OneDrive files, and personal devices with company data. This checklist walks through the exact steps to offboard cleanly, protect the business, and preserve the data you're legally required to keep. Do not skip steps in a hurry — but also do not take irreversible actions like deleting mailboxes before data has been secured.
Disable sign-in
The first action, timed with the employee's departure, is to disable sign-in on the Microsoft 365 account. This prevents further access while preserving the mailbox and OneDrive contents for retention. Do not delete the account — deletion is later and only after data is secured.
Revoke sessions
Disabling sign-in alone doesn't cancel already-authenticated sessions. Explicitly revoke sessions in Entra ID so any open browser or mobile app tokens are invalidated immediately.
Reset or transfer access
- Reset the password (further blocks re-authentication)
- Remove from all groups that grant application or file access
- Remove any admin roles
- Transfer ownership of files, sites, and Teams they owned
Email and OneDrive retention
Depending on your industry, you may need to retain email and files for months or years. Apply your retention policy before deletion. In Microsoft 365 you can typically convert the mailbox to shared, apply a litigation or retention hold, and move OneDrive contents to a designated location.
Shared mailbox conversion
Converting the mailbox to shared preserves the email history and can be accessed by a manager or successor without holding a licence. For roles where the ex-employee received customer email, this is often the safest option.
Device return
- Collect the laptop, dock, and any assigned peripherals
- Sign out and wipe the device via endpoint management
- Reimage for the next user or return to inventory
- Recover any mobile phones or tablets issued by the business
MFA methods
Remove any MFA methods tied to the user's personal device (authenticator app, personal phone number) so they cannot be used to re-authenticate. This is often overlooked.
Password changes
Rotate any shared credentials the employee had access to — service accounts, shared inboxes, Wi-Fi keys, admin passwords. This is the biggest gap in most offboarding processes.
Third-party applications
- Line-of-business software: revoke the user's access
- SaaS tools with individual accounts (CRM, accounting, project tools)
- External vendor portals they had login to
- Password manager: transfer any business-critical vaults, then remove the user
Data ownership
Confirm that any business data on personal devices (BYOD phones, personal laptops if allowed) is removed. If your MDM policies allow selective wipe, run it. If not, treat this as a gap to close in your policy.
Documentation
Record the offboarding date, who performed each step, and what was retained or transferred. This is essential for audit trails and for any future data requests.
Frequently asked questions
Should we delete a Microsoft 365 account when someone leaves?
Not immediately. Disable sign-in and revoke sessions right away. Convert the mailbox to shared or apply retention. Only delete the account after your retention window has passed and all required data has been transferred.
How quickly do we need to disable a departing employee's access?
As close to the departure moment as possible — ideally at the same time as the exit conversation. Delays are how disgruntled departures cause damage.
What about the employee's OneDrive files?
Transfer ownership to a manager or move the folder to a shared location. Don't rely on the user having saved everything to shared sites already — most people haven't.
Do we need to rotate every shared password?
Yes, every credential the ex-employee had access to should be rotated. Passwords are only as private as the people who know them.
Who's responsible for the process — HR or IT?
HR triggers the process and owns the human side. IT executes the technical checklist. Both should sign off before the file is closed.
Book a free 30-minute IT assessment
See exactly where your business technology stands and get a clear, no-pressure plan for what to fix first — no obligation and no sales pressure.
Related services, locations, and resources
Related services
- Cybersecurity Services
Endpoint protection, MFA, email filtering, and M365 hardening.
- Microsoft 365 Support
Exchange, Teams, SharePoint, OneDrive, and licensing.
- Business IT Support
Remote and on-site help desk for day-to-day issues.
Related service areas
Related resources
- How to Choose the Best MSP in Sudbury for Your Business
How to evaluate managed service providers in Greater Sudbury: what to expect, what to ask, and the warning …
- IT Support Sudbury: What Services Should a Business IT Company Provide?
A plain-language breakdown of the services a Sudbury business should expect from a competent IT support com…
- Local IT Company vs National MSP: Which Is Better for Sudbury Businesses?
How to compare a local Sudbury IT company with a national MSP fairly — accountability, on-site coverage, re…
- When Should a Small Business Hire an MSP?
The warning signs that tell a small business it's time to move from ad-hoc IT to a managed service provider…
