Why Offboarding Matters
Every month an ex-staff account stays active is a risk. Credentials get leaked, ex-staff access systems they should not, data leaves the business, and compliance gets breached. A rushed or inconsistent offboarding is one of the most common audit findings and one of the most common breach vectors.
Before the Last Day
- Agree the exit date, last login day, and handover plan with HR
- Identify shared accounts, shared mailboxes, and owned resources the person controls
- Transfer ownership of Teams, SharePoint sites, group mailboxes, licences
- Plan mailbox disposition (shared mailbox, delegation, forward)
- Plan OneDrive disposition (transfer critical files to manager)
- Flag any privileged roles for emergency revocation
- Prepare device return process and shipping labels if remote
Day of Departure
Disable the user account
Do not delete yet. Disable in Entra ID / AD. Sign-out all sessions (revoke refresh tokens).
Revoke MFA methods and passkeys
Remove all registered authenticators. Force password reset.
Disable email forwarding and inbox rules
Attackers (or departing staff) often set these up ahead of time.
Remove from admin roles and PIM
Any elevated access revoked immediately.
Remove from shared mailbox delegations
No continuing access via shared resources.
Disable VPN, remote access, RMM, any non-SSO apps
Catch the apps that do not federate.
Collect physical devices, access cards, tokens
Laptop, phone, hardware keys, access fobs, credit cards.
Change shared credentials they knew
Wifi passwords, service account passwords, shared admin logins.
After Departure
- Convert mailbox to shared or apply litigation hold for compliance
- Transfer OneDrive content to manager. Microsoft allows 30-day delegated access by default
- Reassign or revoke M365 licence after 30 days (keep for legal hold if required)
- Wipe and reassign device (Autopilot reset or full reimage)
- Revoke from all SaaS tools not behind SSO (Xero, HubSpot, Canva, GitHub, etc.)
- Archive documents, close tickets, transfer knowledge base articles
- Delete account entirely after 90 days (or longer if required by retention policy)
- Record date of offboarding, items handled, exceptions, in audit log
Hostile Terminations
When someone is being terminated against their will, coordination between HR, legal, and IT is critical. Moves happen in minutes, not hours.
- IT briefed 24+ hours in advance, under strict confidentiality
- All disables happen at the moment HR begins the conversation, not after
- MFA and passkeys revoked, sessions terminated, password reset
- Devices collected during the meeting, not asked for later
- Building access revoked simultaneously
- Alerts enabled for any sign-in attempts from the account post-termination
- Check for any inbox rules, file exfiltration, or USB use in the week prior
Common Mistakes
Account left enabled for months
Standard finding in every audit. Credentials get leaked or used by attackers.
Forgetting non-SSO SaaS apps
GitHub, Xero, Canva, HubSpot. Manual revocation required. Keep an app register.
No mailbox disposition plan
Customers email someone who no longer exists. Delegate, forward, or share mailbox.
Device left in the field
Remote staff do not return hardware. Send shipping labels, follow up.
Shared credentials not rotated
Ex-staff still know the WiFi, the social media login, the shared inbox password.
No audit trail
Cannot prove offboarding was completed. Compliance and insurance problem later.
Related: New Starter IT Checklist, Password Manager Guide.
Make Offboarding Automatic
We build automated offboarding workflows in Entra ID, Intune, and your SaaS stack, plus run the manual tasks as part of managed services.

Remote Support