Microsoft 365 offboarding checklist: what to do when someone leaves
A leaver who can still read company email a month later is one of the most common security gaps in small businesses. Here is the checklist, in the order to do it.
When someone leaves, most businesses remember to collect the laptop. Far fewer make sure the person’s account actually stops working. A leaver who can still sign in to email, shared files or the accounting system weeks later is one of the most common security gaps in small businesses, and it is entirely avoidable.
This checklist covers Microsoft 365. Do it in this order, on or before the person’s last day, and agree the timing with whoever manages the departure.
1. Stop access
- Block sign-in for the account in the Microsoft 365 or Entra admin centre. Blocking first, rather than deleting, keeps the mailbox and files intact while you deal with them.
- Reset the password, so any saved credentials stop working.
- Sign the user out of all sessions. Revoking sessions forces every device and app to sign in again, which it now cannot.
- Remove their multi-factor authentication methods and registered devices, so a phone still in their pocket cannot be used to regain access.
2. Look for what they set up
- Mail forwarding and inbox rules. Check for rules forwarding mail to a personal address. They are easy to miss and easy to abuse.
- Admin roles. If the person held any administrator role, remove it, and check that at least one other person still has admin access.
- Shared passwords. Change any shared credentials the person knew: banking, suppliers’ portals, social media, the website.
- Apps and integrations connected with their account, which may stop working or keep running under their name.
3. Deal with email
- Convert the mailbox to a shared mailbox if the team still needs access to it, or set up forwarding to a manager for a fixed period. In most cases, a shared mailbox under 50 GB does not need its own licence.
- Set an automatic reply telling senders who to contact instead.
- Remove them from distribution lists and groups, so they stop receiving team mail.
4. Deal with files
- Give the manager access to their OneDrive and move anything the business needs into a shared location. When an account is deleted, its OneDrive is kept for a limited period, 30 days by default, before it is removed.
- Transfer ownership of Teams and SharePoint sites the person owned, so they do not become orphaned.
5. Deal with devices
- Company devices: retire or wipe them through Intune or your device management tool, then reset them for the next person.
- Personal devices used for work: remove company data only, with a selective wipe, rather than wiping the whole phone.
- Collect hardware, and record what came back.
6. Tidy up licences
Once email and files are handled, remove the licences so you stop paying for them, and delete the account when you no longer need it.
Make it a process, not a memory
The checklist only works if it happens every time. Turn it into a written procedure owned by one person, triggered by the same event every time, such as HR confirming a leaving date. Do the same for new starters, so everyone gets the right access on day one, and nothing more.
When to get help
If nobody is sure which accounts, devices and admin roles exist today, start there. Our IT, security and access work reviews who has access to what, puts proper joiner and leaver procedures in place, and enrols devices so they can be managed and wiped remotely. Leaver access is also a classic route into supplier bank detail fraud, so it is worth closing properly.
Share this