top of page
Search

Microsoft 365 Offboarding Checklist for Departing Employees

Sep 5
5 min read

When an employee leaves, the safest approach is to follow a planned sequence: confirm the departure details, block access, revoke active sessions, preserve business data, transfer ownership, recover equipment and only then remove licenses or accounts according to your retention requirements.

The checklist below gives the business owner, manager and IT administrator a shared record of what must happen and who approved it. Adapt the timing to the departure and to any legal, contractual or regulatory obligations that apply.

Before the Departure: Assign an Owner and Exact Cutoff Time

One person should own the offboarding record from start to finish. Record:

  • Employee name, department and manager

  • Last working date and exact access cutoff time

  • Whether the departure is routine, urgent or potentially hostile

  • Company devices, keys, cards and other assets assigned to the employee

  • Mailboxes, shared folders, applications and customer accounts the employee can access

  • The manager or replacement employee who should receive business data

  • Any retention, investigation or legal-hold instruction from authorized leadership or counsel

Do not rely on a casual message that someone is leaving “Friday.” A specific cutoff time helps HR, management and IT coordinate access removal without disabling the account too early or leaving it open after the person has departed.

1. Preserve Instructions and Approvals

Create a written ticket before making changes. Capture the departure request, authorization, cutoff time and data-transfer owner.

If litigation, an investigation, a regulatory requirement or a contractual retention rule may apply, pause destructive actions and obtain the appropriate business or legal instruction. Offboarding should protect the organization without deleting records that it is required to retain.

2. Block Sign-In and Reset the Password

At the approved cutoff time, block the user's Microsoft 365 sign-in and reset the password to a strong random value controlled by an authorized administrator. Do not give the replacement password to the departing employee or place it in the offboarding ticket.

Microsoft's former-employee guidance recommends resetting the password, signing the user out of all sessions and blocking access. Microsoft notes that an account block can take time to apply, which is why the password reset and session-revocation steps should not be skipped.

3. Revoke Active Sessions

Blocking new sign-ins does not necessarily end every session at the same instant. Use the Microsoft 365 or Entra administration controls to sign the user out and revoke sessions. Microsoft's Entra access-revocation guidance explains that applications and token types can respond differently, so administrators should understand that access revocation is a process rather than a single checkbox.

For a higher-risk departure, review recent sign-ins, authentication methods and unexpected forwarding or inbox rules. Escalate suspicious activity through your incident-response process.

4. Remove Privileged and Third-Party Access

Remove the employee from administrative roles, security groups, distribution groups, Teams, shared mailboxes and application assignments that are no longer required. Microsoft 365 is only one part of the access map. Check other systems such as:

  • Line-of-business and finance applications

  • Customer relationship management platforms

  • Point-of-sale, inventory and ecommerce systems

  • Password managers and shared credentials

  • Remote support, VPN and network-management tools

  • Social media, advertising and domain accounts

  • Building access, alarm, camera and physical access systems

Rotate shared passwords or access codes that the person knew. A disabled Microsoft account does not protect a separate vendor portal that still uses a shared credential.

5. Secure Company Devices and Business Data

Recover laptops, phones, tablets, security keys, badges and storage devices. Record the return condition and update the asset register. For a company-managed mobile device that cannot be recovered promptly, use the organization's approved device-management controls to protect business data.

Do not erase or reissue equipment until necessary files, security evidence and retention requirements have been addressed. For personal devices, follow documented bring-your-own-device and privacy procedures.

6. Preserve the Mailbox and OneDrive Content

Decide who needs access to active customer conversations, business records and working files. Microsoft's former-employee overview provides a sequence for saving mailbox content, managing mobile access, forwarding email or converting a mailbox, granting access to OneDrive and Outlook data, and later removing licenses or the account.

Choose the mailbox treatment deliberately. A shared mailbox, forwarding arrangement or automatic reply should have an owner, purpose and review date. Document who approved the transfer.

7. Transfer Ownership of Shared Work

Identify work that may not sit entirely inside the user's mailbox or OneDrive. Transfer ownership or administration for:

  • Teams and Microsoft 365 groups

  • SharePoint sites and shared libraries

  • Power Automate flows and Forms

  • Shared calendars and meeting series

  • Vendor portals and recurring reports

  • Documentation, encryption keys and service accounts

Test the replacement owner's access before removing the former employee's license. A file being retained is not the same as the next employee being able to find and use it.

8. Configure Customer and Staff Continuity

Work with the manager to decide whether the former address should receive mail temporarily, forward to another employee or display an automatic reply. Use neutral, approved language. Do not disclose private employment details.

Update public contact pages, internal directories, phone routing and customer assignments when necessary. If the employee was responsible for scheduled meetings, recurring reports or vendor communications, assign those obligations to a named owner.

9. Remove Licenses and Delete the Account at the Right Time

Before removing licenses, verify that required mailbox and OneDrive data is preserved, ownership transfers are complete and retention instructions are documented.

Microsoft's guidance separates access blocking, data preservation, mailbox handling, license removal and account deletion into distinct steps. Your deletion timing should reflect the organization's retention policy and any applicable requirements. Record the final action and date so the business can later explain what happened to the account and data.

10. Close the Record and Review for Gaps

The owner should verify that access is blocked, sessions were revoked, privileged roles and third-party access were removed, equipment was recovered, data was transferred and license/account actions were completed or scheduled. Attach evidence where appropriate without placing passwords or sensitive content in the ticket.

After the first few offboardings, review the checklist for systems that were repeatedly missed. Those omissions become updates to the standard process and access inventory.

One-Page Microsoft 365 Offboarding Checklist

  • Departure authorization and exact cutoff time recorded

  • Sign-in blocked and password reset

  • Active sessions revoked

  • Administrative roles, groups and application assignments reviewed

  • Shared credentials and access codes rotated where needed

  • Company devices, keys and security tokens recovered

  • Mailbox and OneDrive retention plan approved

  • Mail forwarding, shared mailbox or automatic reply configured if needed

  • Teams, SharePoint, Forms, flows and recurring work transferred

  • Third-party, VPN, POS, building and vendor access removed

  • License removal and account deletion timed to the retention plan

  • Manager and IT owner confirmed completion

Make Offboarding Repeatable

A dependable offboarding process protects company data and keeps customer work moving. It also reduces the chance that forgotten accounts, shared passwords or abandoned automations remain active after an employee leaves.

Sosa Solutions NYC helps small and midsize businesses organize Microsoft 365 administration, account lifecycle procedures and ongoing IT support. If employee access changes are being handled through last-minute messages, review our Microsoft 365 and cloud services, managed IT services and cybersecurity services to build a controlled process for your team.

Comments


bottom of page