What Should a Business Do When an Employee Leaves? IT Offboarding Checklist
When an employee leaves your business, removing their access to company systems is just as important as collecting their keys and laptop. A poorly managed offboarding process can leave former employees with access to Microsoft 365, business data and other systems long after they have left.
This IT offboarding checklist explains what businesses should do when an employee leaves, from securing their Microsoft 365 account to recovering company devices and protecting business data.
Why Employee Offboarding Matters
When an employee leaves, there is often a lot to organise. HR needs to process the departure, managers need to redistribute responsibilities and equipment may need to be returned.
IT access can sometimes be overlooked in the process.
A former employee may have access to email, Microsoft 365, cloud applications, shared files, company devices, VPNs or other business systems. If these accounts and devices are not dealt with properly, your business could be left with unnecessary security risks.
A good employee offboarding process ensures that access is removed at the right time, important business information is retained and company equipment is recovered.
For businesses using Microsoft 365, this is particularly important because a single user account can provide access to email, Teams, SharePoint, OneDrive and other business services.
Employee IT Offboarding Checklist
When an employee leaves, your IT team or IT support provider should work through a consistent checklist.
- Confirm the Employee’s Departure Date and Time
The first step is to establish exactly when the employee’s access should be removed.
This is particularly important when an employee leaves unexpectedly or under sensitive circumstances. IT should know whether access needs to be removed immediately or at the end of the employee’s final working day.
Ideally, HR or management should notify the IT team before the employee’s departure rather than after it.
Your offboarding process should record:
- Employee name
- Final working date
- Exact time access should be removed
- Manager responsible for the employee
- Whether the departure is planned or immediate
- Whether the employee has company-owned devices
- Which systems the employee uses
Having this information ready allows IT to act quickly and consistently.
- Disable the Employee’s Microsoft 365 Account
For businesses using Microsoft 365, disabling the employee’s account should be a priority.
Simply changing the password may not be enough. The account may have active sessions, registered devices or authentication methods that could allow continued access.
Depending on your Microsoft 365 configuration, your IT team may need to:
- Block the user’s sign-in
- Revoke active sessions
- Remove or review authentication methods
- Review registered devices
- Remove unnecessary application access
- Check the user’s Microsoft 365 licences
- Review administrator permissions
The exact process will depend on how your Microsoft 365 environment is configured.
Businesses using Microsoft Entra ID and Microsoft Intune can also use these platforms to manage identities and devices as part of the offboarding process.
- Secure the Employee’s Email
An employee’s email account can contain a significant amount of sensitive business information.
Before deleting or permanently removing the account, your business should consider whether emails need to be retained and who needs access to ongoing correspondence.
Depending on the circumstances, this may involve:
- Setting up an automatic reply
- Redirecting relevant business communications
- Delegating access to an appropriate employee
- Preserving required emails
- Reviewing mailbox permissions
- Removing the account from unnecessary groups
Avoid simply forwarding all email indefinitely to another employee. A controlled approach is usually more secure and easier to manage.
Your business should also consider how long information needs to be retained based on its own policies and any applicable legal or regulatory requirements.
- Transfer Important OneDrive and SharePoint Data
An employee leaving should not mean that important business information disappears with their account.
Before removing an account, check whether the employee has stored business-critical documents in OneDrive or other locations that are not already accessible to colleagues.
Important information may include:
- Customer documents
- Project files
- Contracts
- Financial information
- Business processes
- Reports
- Marketing materials
- Other operational documents
Where appropriate, important files should be transferred to the correct company-owned location, such as SharePoint or a suitable shared folder.
This is one reason businesses should avoid relying on individual employee accounts as the primary location for important company information.
- Remove Access to Other Business Applications
Microsoft 365 is rarely the only system an employee uses.
Businesses should maintain a list of applications and services that employees can access and review them when someone leaves.
This may include:
- CRM systems
- Accounting software
- HR platforms
- Project management tools
- Cloud storage
- Password managers
- VPNs
- Remote access tools
- Industry-specific software
- Website administration
- Social media accounts
Where possible, access should be centrally managed through your identity platform. This makes it easier to identify and remove access when employees leave.
It is also important to check whether the employee knows shared passwords or has access to credentials that are not tied to their individual account.
- Recover Company Devices
Company equipment should be accounted for as part of the offboarding process.
This may include:
- Laptops
- Desktop computers
- Mobile phones
- Tablets
- Monitors
- Security keys
- Headsets
- Other IT equipment
Your IT asset register should be updated to show which equipment has been returned.
If a device is not returned, your IT provider should be informed so that appropriate security measures can be taken. Depending on the device and configuration, this could include remotely locking or wiping the device.
- Check Local Administrator Access
Some businesses give employees administrator access to their computers for convenience.
This can create a security problem if the employee leaves and retains knowledge of administrator credentials or shared passwords.
As part of offboarding, check whether the employee had:
- Local administrator access
- Shared administrator credentials
- Access to network equipment
- Access to servers
- Privileged application accounts
Privileged access should be limited to people who genuinely require it.
- Remove Access to Remote Systems
Remote access should also be reviewed.
Depending on your IT environment, this could include:
- VPN access
- Remote Desktop
- Remote management software
- Cloud applications
- Virtual desktops
- Remote support tools
If the employee uses a company laptop outside the office, the device should also be checked to ensure it remains secure and compliant.
- Review Shared Passwords and Credentials
This is an area that is easily overlooked.
If an employee knew passwords for shared accounts, those credentials may need to be changed.
Examples could include:
- Shared email accounts
- Website administration
- Social media
- Wi-Fi
- Network equipment
- Supplier portals
- Cloud services
- Business applications
Where possible, businesses should avoid shared accounts altogether and provide individual user accounts with appropriate permissions.
Using a business password manager can also help organisations control access to shared credentials and remove access when employees leave.
- Remove the Employee From Groups and Distribution Lists
An employee may be a member of multiple Microsoft 365 groups, Teams, distribution lists or security groups.
These should be reviewed as part of the offboarding process.
Removing the account itself may not be enough if the employee has access through another account or shared resource.
A structured checklist helps ensure that less obvious access is not forgotten.
What Happens If You Don’t Properly Offboard an Employee?
Poor employee offboarding can create several risks for a business.
Unauthorised Access
If an account remains active, a former employee could potentially access business systems after leaving.
Even if the former employee has no malicious intentions, a compromised account could provide an attacker with an opportunity to access your systems.
Data Loss
Important files may be stored in an employee’s individual account rather than a central company location.
If the account is removed without checking its contents, important business information could become difficult to recover.
Security Vulnerabilities
Old accounts, unused permissions and forgotten credentials increase the number of potential entry points into your IT environment.
Good access management reduces the number of accounts and permissions that need to be protected.
Business Disruption
If customers continue emailing a former employee or important documents are stored in their account, their departure can create operational problems.
A well-managed offboarding process helps ensure that the transition is as smooth as possible.
How Microsoft 365 Can Help With Employee Offboarding
Microsoft 365 provides businesses with several tools that can support a structured employee offboarding process.
Microsoft Entra ID can help manage user identities and access, while Microsoft Intune can help businesses manage company devices.
Microsoft 365 also provides tools for managing services such as:
- Exchange Online
- Microsoft Teams
- OneDrive
- SharePoint
- Microsoft Entra ID
However, having Microsoft 365 does not automatically mean that employee offboarding is being managed correctly.
The platform still needs to be configured properly, and businesses need clear processes for what happens when an employee joins, changes role or leaves.
Why an Employee Offboarding Process Should Be Automated Where Possible
The more manual your offboarding process is, the easier it is for something to be missed.
A structured process can reduce this risk.
For example, when HR confirms an employee’s departure, the IT process could automatically trigger tasks for:
- Disabling the user’s account.
- Revoking access.
- Recovering company equipment.
- Transferring important files.
- Reviewing licences.
- Removing access from applications.
- Updating the asset register.
- Confirming completion.
Automation does not replace human oversight, but it can make the process more consistent.
Employee Offboarding Checklist
For a quick reference, businesses can use the following checklist:
- Confirm departure date and time
- Notify IT or your managed IT provider
- Disable the Microsoft 365 account
- Revoke active sessions and authentication access
- Review email and mailbox requirements
- Transfer important OneDrive and SharePoint files
- Remove access to business applications
- Remove VPN and remote access
- Recover company devices
- Review administrator privileges
- Change shared passwords where necessary
- Remove the employee from groups and distribution lists
- Update your IT asset register
- Confirm that offboarding is complete
How Managed IT Support Can Help
Employee offboarding is just one part of managing a business’s IT environment.
For growing businesses, keeping track of users, devices, applications and permissions can quickly become difficult to manage internally.
A managed IT provider can establish standard processes for employee onboarding and offboarding, maintain user and device records, manage Microsoft 365 environments and help ensure access is removed when employees leave.
This is particularly useful for businesses where employees join and leave regularly, or where staff work across multiple locations.
At Ventrix IT, we help businesses manage the technology behind their day-to-day operations, from Microsoft 365 and user access to device management, cyber security and ongoing IT support.
A consistent approach to employee offboarding can help reduce security risks while making sure important business information remains accessible to the people who need it.
Frequently Asked Questions
Should you delete an employee’s Microsoft 365 account when they leave?
Not necessarily immediately. Businesses should first consider whether emails, files or other information need to be retained or transferred. The account should be secured and access removed in line with your offboarding process.
How quickly should IT access be removed when an employee leaves?
Access should be removed at the agreed time specified by the business. For sensitive or involuntary departures, immediate removal may be appropriate.
What happens to an employee’s OneDrive when they leave?
The appropriate process depends on your Microsoft 365 configuration and retention requirements. Important business files should be identified and transferred to an appropriate company-controlled location before the account is permanently removed.
What should happen to a company laptop when an employee leaves?
The laptop should be recovered, recorded in the company’s IT asset register and checked before being reassigned. Depending on your security policies, the device may need to be wiped, reconfigured and enrolled in device management before another employee uses it.
Do I need an IT company to offboard employees?
Not necessarily. Smaller businesses can manage basic offboarding internally, provided they have the appropriate knowledge and processes. However, businesses with larger IT environments or more complex Microsoft 365 setups may benefit from managed IT support to ensure offboarding is handled consistently.
Conclusion
When an employee leaves, disabling their email account is only one part of the IT offboarding process.
Businesses also need to consider Microsoft 365 access, company devices, cloud applications, shared credentials, remote access and important business data. Missing one of these areas can leave unnecessary security risks or cause problems later.
A documented employee offboarding checklist gives your business a repeatable process and helps ensure nothing important is overlooked.
For businesses without the time or expertise to manage this internally, a managed IT provider can take responsibility for the process and help keep users, devices and systems secure as employees join, change roles and leave.
Need help managing your business IT? Ventrix IT provides managed IT support, Microsoft 365 and cyber security services for businesses across Kent and the South East.




