Microsoft 365 Offboarding Checklist for Departing Employees
When an employee leaves, the safest approach is to follow a planned sequence: confirm the departure details, block access, revoke active sessions, preserve business data, transfer ownership, recover equipment and only then remove licenses or accounts according to your retention requirements.
The checklist below gives the business owner, manager and IT administrator a shared record of what must happen and who approved it. Adapt the timing to the departure and to any legal, contractual or regulatory obligations that apply.
Before the Departure: Assign an Owner and Exact Cutoff Time
One person should own the offboarding record from start to finish. Record:
Employee name, department and manager
Last working date and exact access cutoff time
Whether the departure is routine, urgent or potentially hostile
Company devices, keys, cards and other assets assigned to the employee
Mailboxes, shared folders, applications and customer accounts the employee can access
The manager or replacement employee who should receive business data
Any retention, investigation or legal-hold instruction from authorized leadership or counsel
Do not rely on a casual message that someone is leaving “Friday.” A specific cutoff time helps HR, management and IT coordinate access removal without disabling the account too early or leaving it open after the person has departed.
1. Preserve Instructions and Approvals
Create a written ticket before making changes. Capture the departure request, authorization, cutoff time and data-transfer owner.
If litigation, an investigation, a regulatory requirement or a contractual retention rule may apply, pause destructive actions and obtain the appropriate business or legal instruction. Offboarding should protect the organization without deleting records that it is required to retain.
2. Block Sign-In and Reset the Password
At the approved cutoff time, block the user's Microsoft 365 sign-in and reset the password to a strong random value controlled by an authorized administrator. Do not give the replacement password to the departing employee or place it in the offboarding ticket.
Microsoft's former-employee guidance recommends resetting the password, signing the user out of all sessions and blocking access. Microsoft notes that an account block can take time to apply, which is why the password reset and session-revocation steps should not be skipped.
3. Revoke Active Sessions
Blocking new sign-ins does not necessarily end every session at the same instant. Use the Microsoft 365 or Entra administration controls to sign the user out and revoke sessions. Microsoft's Entra access-revocation guidance explains that applications and token types can respond differently, so administrators should understand that access revocation is a process rather than a single checkbox.
For a higher-risk departure, review recent sign-ins, authentication methods and unexpected forwarding or inbox rules. Escalate suspicious activity through your incident-response process.
4. Remove Privileged and Third-Party Access
Remove the employee from administrative roles, security groups, distribution groups, Teams, shared mailboxes and application assignments that are no longer required. Microsoft 365 is only one part of the access map. Check other systems such as:
Line-of-business and finance applications
Customer relationship management platforms
Point-of-sale, inventory and ecommerce systems
Password managers and shared credentials
Remote support, VPN and network-management tools
Social media, advertising and domain accounts
Building access, alarm, camera and physical access systems
Rotate shared passwords or access codes that the person knew. A disabled Microsoft account does not protect a separate vendor portal that still uses a shared credential.
5. Secure Company Devices and Business Data
Recover laptops, phones, tablets, security keys, badges and storage devices. Record the return condition and update the asset register. For a company-managed mobile device that cannot be recovered promptly, use the organization's approved device-management controls to protect business data.
Do not erase or reissue equipment until necessary files, security evidence and retention requirements have been addressed. For personal devices, follow documented bring-your-own-device and privacy procedures.
6. Preserve the Mailbox and OneDrive Content
Decide who needs access to active customer conversations, business records and working files. Microsoft's former-employee overview provides a sequence for saving mailbox content, managing mobile access, forwarding email or converting a mailbox, granting access to OneDrive and Outlook data, and later removing licenses or the account.
Choose the mailbox treatment deliberately. A shared mailbox, forwarding arrangement or automatic reply should have an owner, purpose and review date. Document who approved the transfer.
7. Transfer Ownership of Shared Work
Identify work that may not sit entirely inside the user's mailbox or OneDrive. Transfer ownership or administration for:
Teams and Microsoft 365 groups
SharePoint sites and shared libraries
Power Automate flows and Forms
Shared calendars and meeting series
Vendor portals and recurring reports
Documentation, encryption keys and service accounts
Test the replacement owner's access before removing the former employee's license. A file being retained is not the same as the next employee being able to find and use it.
8. Configure Customer and Staff Continuity
Work with the manager to decide whether the former address should receive mail temporarily, forward to another employee or display an automatic reply. Use neutral, approved language. Do not disclose private employment details.
Update public contact pages, internal directories, phone routing and customer assignments when necessary. If the employee was responsible for scheduled meetings, recurring reports or vendor communications, assign those obligations to a named owner.
9. Remove Licenses and Delete the Account at the Right Time
Before removing licenses, verify that required mailbox and OneDrive data is preserved, ownership transfers are complete and retention instructions are documented.
Microsoft's guidance separates access blocking, data preservation, mailbox handling, license removal and account deletion into distinct steps. Your deletion timing should reflect the organization's retention policy and any applicable requirements. Record the final action and date so the business can later explain what happened to the account and data.
10. Close the Record and Review for Gaps
The owner should verify that access is blocked, sessions were revoked, privileged roles and third-party access were removed, equipment was recovered, data was transferred and license/account actions were completed or scheduled. Attach evidence where appropriate without placing passwords or sensitive content in the ticket.
After the first few offboardings, review the checklist for systems that were repeatedly missed. Those omissions become updates to the standard process and access inventory.
One-Page Microsoft 365 Offboarding Checklist
Departure authorization and exact cutoff time recorded
Sign-in blocked and password reset
Active sessions revoked
Administrative roles, groups and application assignments reviewed
Shared credentials and access codes rotated where needed
Company devices, keys and security tokens recovered
Mailbox and OneDrive retention plan approved
Mail forwarding, shared mailbox or automatic reply configured if needed
Teams, SharePoint, Forms, flows and recurring work transferred
Third-party, VPN, POS, building and vendor access removed
License removal and account deletion timed to the retention plan
Manager and IT owner confirmed completion
Make Offboarding Repeatable
A dependable offboarding process protects company data and keeps customer work moving. It also reduces the chance that forgotten accounts, shared passwords or abandoned automations remain active after an employee leaves.
Sosa Solutions NYC helps small and midsize businesses organize Microsoft 365 administration, account lifecycle procedures and ongoing IT support. If employee access changes are being handled through last-minute messages, review our Microsoft 365 and cloud services, managed IT services and cybersecurity services to build a controlled process for your team.



Comments