All Guides
People and Identity

IT Offboarding: The Complete Checklist

Offboarding is where businesses get breached, sued, or leak IP. This guide covers every step for staff departing: before, day-of, after, and handling hostile exits.

Last reviewed September 2026

Why Offboarding Matters

Every month an ex-staff account stays active is a risk. Credentials get leaked, ex-staff access systems they should not, data leaves the business, and compliance gets breached. A rushed or inconsistent offboarding is one of the most common audit findings and one of the most common breach vectors.

Before the Last Day

  • Agree the exit date, last login day, and handover plan with HR
  • Identify shared accounts, shared mailboxes, and owned resources the person controls
  • Transfer ownership of Teams, SharePoint sites, group mailboxes, licences
  • Plan mailbox disposition (shared mailbox, delegation, forward)
  • Plan OneDrive disposition (transfer critical files to manager)
  • Flag any privileged roles for emergency revocation
  • Prepare device return process and shipping labels if remote

Day of Departure

Disable the user account

Do not delete yet. Disable in Entra ID / AD. Sign-out all sessions (revoke refresh tokens).

Revoke MFA methods and passkeys

Remove all registered authenticators. Force password reset.

Disable email forwarding and inbox rules

Attackers (or departing staff) often set these up ahead of time.

Remove from admin roles and PIM

Any elevated access revoked immediately.

Remove from shared mailbox delegations

No continuing access via shared resources.

Disable VPN, remote access, RMM, any non-SSO apps

Catch the apps that do not federate.

Collect physical devices, access cards, tokens

Laptop, phone, hardware keys, access fobs, credit cards.

Change shared credentials they knew

Wifi passwords, service account passwords, shared admin logins.

After Departure

  • Convert mailbox to shared or apply litigation hold for compliance
  • Transfer OneDrive content to manager. Microsoft allows 30-day delegated access by default
  • Reassign or revoke M365 licence after 30 days (keep for legal hold if required)
  • Wipe and reassign device (Autopilot reset or full reimage)
  • Revoke from all SaaS tools not behind SSO (Xero, HubSpot, Canva, GitHub, etc.)
  • Archive documents, close tickets, transfer knowledge base articles
  • Delete account entirely after 90 days (or longer if required by retention policy)
  • Record date of offboarding, items handled, exceptions, in audit log

Hostile Terminations

When someone is being terminated against their will, coordination between HR, legal, and IT is critical. Moves happen in minutes, not hours.

  • IT briefed 24+ hours in advance, under strict confidentiality
  • All disables happen at the moment HR begins the conversation, not after
  • MFA and passkeys revoked, sessions terminated, password reset
  • Devices collected during the meeting, not asked for later
  • Building access revoked simultaneously
  • Alerts enabled for any sign-in attempts from the account post-termination
  • Check for any inbox rules, file exfiltration, or USB use in the week prior

Common Mistakes

Account left enabled for months

Standard finding in every audit. Credentials get leaked or used by attackers.

Forgetting non-SSO SaaS apps

GitHub, Xero, Canva, HubSpot. Manual revocation required. Keep an app register.

No mailbox disposition plan

Customers email someone who no longer exists. Delegate, forward, or share mailbox.

Device left in the field

Remote staff do not return hardware. Send shipping labels, follow up.

Shared credentials not rotated

Ex-staff still know the WiFi, the social media login, the shared inbox password.

No audit trail

Cannot prove offboarding was completed. Compliance and insurance problem later.

Related: New Starter IT Checklist, Password Manager Guide.

Make Offboarding Automatic

We build automated offboarding workflows in Entra ID, Intune, and your SaaS stack, plus run the manual tasks as part of managed services.