Employee offboarding involves more than collecting a laptop and disabling an email address.
A departing employee may have access to files, cloud platforms, shared credentials, remote systems, vendor portals, phones and business processes that are not visible from a single account.
A consistent process protects company information while preserving the communication, records and work the organization still needs.
The main point
Access should end at a defined time, but required business information should be preserved before accounts, licenses or data are deleted.
Human resources, the employee’s manager and IT should agree on the employee’s final access time. For an involuntary departure or a position with elevated access, changes may need to happen immediately and in close coordination with the employee notification.
Microsoft’s guidance for former employees begins with preventing sign-in, securing company data and preserving appropriate access to email and files before licenses or accounts are removed.
CISA also treats joining, changing positions and leaving as connected parts of the identity and access life cycle.
A practical offboarding sequence
1. Confirm the effective time
Document the employee’s final working date and the exact time access should change.
Do not rely on an informal message or assume the end of the business day is appropriate in every situation. The timing should be approved by the people responsible for the departure.
2. Block sign-in and revoke sessions
At the approved time:
- Block the employee’s primary account.
- Revoke active sign-in sessions.
- Remove VPN and remote-access privileges.
- Disable privileged or administrator accounts.
- Remove access to password managers and single sign-on services.
- Recover or deactivate physical access credentials.
Changing the password alone may not end active sessions or remove access through other systems.
3. Preserve required business information
Before deleting accounts or removing licenses, determine who needs access to the employee’s:
- Email and calendar
- Files and shared documents
- Project records
- Business contacts
- Recurring reports
- Application data
- Client or vendor correspondence
Transfer file and project ownership where the platform supports it.
Preserving business records does not mean automatically giving a manager unrestricted access to every communication. The organization should follow its policies, retention requirements and legal obligations.
4. Recover company equipment
Collect assigned equipment, including:
- Computers
- Phones and tablets
- Storage devices
- Security keys and authentication tokens
- Access cards and physical keys
- Chargers and specialized accessories
Record what was returned and its condition.
Before a device is reassigned, confirm that required business data has been preserved, remove the former employee’s access and prepare the device through the organization’s standard process.
5. Review third-party and shared access
Remove the employee from:
- Shared mailboxes and distribution groups
- Collaboration platforms
- Vendor and customer portals
- Financial or payment systems
- Social media accounts
- Website and domain-management platforms
- File-sharing services
- Password vaults
Rotate shared credentials when the employee knew them.
This is one reason shared usernames and passwords should be minimized. Individual accounts create clearer ownership and make offboarding more reliable.
6. Reassign communication and ownership
Assign responsibility for active projects, client relationships, approvals, recurring reports and vendor communication.
Configure an appropriate automatic response, mailbox delegation or forwarding arrangement based on company policy. Review any forwarding rules or delegated access that the former employee created.
7. Verify and document completion
Use a checklist that records:
- The system or asset
- The required action
- The responsible person
- The completion time
- Any exception or follow-up
Complete a final verification that access has been removed and required business information remains available.
What to avoid
Do not:
- Delete an account before preserving required information.
- Assume removing an email license ends access everywhere.
- Leave former employees in shared groups or vendor portals.
- Depend on the departing employee to identify every system used.
- Leave personal recovery addresses or phone numbers attached to business accounts.
- Keep shared credentials unchanged after a sensitive departure.
Maintain an application and access inventory so offboarding is based on company records rather than memory.
When to involve IT
IT should be involved whenever an employee or contractor has company accounts, equipment or access.
Immediate coordination is especially important for administrators, finance personnel, executives, remote employees and anyone with access to sensitive or regulated information.
A reliable offboarding process does not begin on the employee’s last day. It begins with individual accounts, documented equipment, clear ownership and access that can be reviewed throughout employment.
Need a more reliable onboarding and offboarding process? Book a consultation.