Employee leaving: the business access checklist
When an employee leaves, the most urgent question is often: What time should access be cut off?
The more important question is broader: What access, data and responsibilities did this person actually hold?
A well-managed departure protects the business without deleting useful information too early. It should be coordinated by an authorized decision-maker, usually management, human resources or another designated owner.
This checklist is business guidance. Exact steps depend on legal obligations, employment agreements, internal policies, licences and the systems in use.
01Confirm who authorizes the action and when it happens
Before changing accounts, confirm:
- the person’s exact identity;
- the access cutoff date and time;
- who authorizes the cutoff;
- who takes over responsibilities;
- which data must be preserved;
- which communications must continue;
- which devices and property must be returned;
- any known legal or retention requirements.
Cutting access too early can interrupt an approved transition. Cutting it too late can leave unauthorized access.
02Block new sign-ins and revoke active sessions
In Microsoft 365, disabling the account is only part of the task.
A session already open on a computer, phone or application may remain active for some time. Microsoft recommends blocking sign-in and, where the situation requires it, revoking active sessions and access tokens.
The checklist may include:
- block Microsoft 365 and Entra ID sign-in;
- reset the password when the procedure requires it;
- revoke active sessions;
- remove or reset multifactor authentication methods;
- disable managed or registered devices where appropriate;
- check separate administrative accounts;
- address guest accounts in other organizations.
External or federated accounts may require action with another provider.
03Preserve email, OneDrive and business records
Do not immediately delete the account without deciding what happens to the data.
Depending on the situation, the business may need to:
- preserve the mailbox;
- convert it to a shared mailbox when licensing and use permit;
- provide authorized access to a successor;
- transfer important OneDrive files;
- retain useful calendars, contacts and tasks;
- apply retention or legal hold requirements;
- document who received access and for how long.
Microsoft publishes a specific former-employee process for preserving content and transferring authorized access to Outlook and OneDrive.
Avoid transferring everything without review. Personal, confidential or irrelevant data should be handled according to company policy and applicable obligations.
04Remove access to applications and external services
Microsoft 365 is only the starting point.
Check areas such as:
- accounting software;
- payroll;
- CRM;
- project management tools;
- cloud storage;
- VPN;
- remote desktop and support tools;
- line-of-business applications;
- vendor portals;
- social media;
- marketing and newsletter tools;
- backup services;
- web hosting, domains and DNS;
- banking or payment platforms;
- alarms, access control and cameras;
- passwords saved in browsers.
An offboarding inventory is more reliable than an improvised search afterward.
05Recover devices and authentication factors
Physical recovery should cover:
- laptop or workstation;
- phone and tablet;
- hardware security key;
- authentication token;
- access card;
- physical keys;
- USB storage;
- loaned equipment;
- printed documents;
- authorized local backup copies.
For a remote device, define who arranges return, how the device is protected in transit and when it will be inspected.
Do not automatically erase a device before preservation and transfer needs are confirmed.
06Change shared secrets
Shared passwords are difficult because they do not disappear when the person’s account is disabled.
Change or replace:
- generic accounts;
- internal Wi-Fi passwords;
- alarm codes;
- API keys;
- equipment passwords;
- vendor access;
- social-media accounts;
- password-vault access codes;
- secrets stored in scripts or automations.
The better long-term correction is replacing shared accounts with named access and roles where the system supports it.
07Transfer ownership of groups, automations and accounts
A person may own important resources without that ownership being obvious in daily work.
Review:
- Microsoft 365 groups and Teams;
- distribution lists;
- shared mailboxes;
- SharePoint sites;
- forms;
- Power Automate and other automations;
- shared calendars;
- domain and hosting accounts;
- subscriptions and billing;
- vendor accounts;
- certificates, keys and renewals;
- documentation they alone controlled.
Transfer responsibility before deleting the account to avoid orphaned resources.
08Address personal devices and remote work
When work was done on a personal device, the business should know what company information or applications remain there.
Depending on tools and policies, it may be possible to:
- remove only managed business data;
- revoke application access;
- remove the device from management systems;
- disable VPN profiles;
- confirm deletion of authorized local copies;
- preserve necessary evidence when an incident is involved.
A clear policy before departure works better than an improvised negotiation afterward.
09Prepare communication continuity
Decide:
- who will respond to messages;
- whether an automatic reply is appropriate;
- whether temporary forwarding is needed;
- who takes over clients and vendors;
- how important contacts will be informed;
- how long the mailbox or address remains active.
Permanent invisible forwarding can create privacy concerns. Document its duration, owner and purpose.
10Produce closure evidence
The task is not complete when the primary account is blocked.
The departure record should show:
- actions completed;
- date and time;
- who authorized each important action;
- data preserved;
- access transferred;
- devices recovered;
- exceptions;
- remaining actions;
- final review date.
This evidence helps management, HR, compliance and the next technician.
Quick management checklist
Before closing the file, can you answer yes to these questions?
- Was the cutoff time authorized?
- Were active sessions revoked, not only the password changed?
- Were useful email and files preserved?
- Were external applications reviewed?
- Were devices and authentication factors recovered?
- Were shared secrets changed?
- Do groups, automations and accounts have a new owner?
- Is communication forwarding limited and documented?
- Is there a record of completed actions?
- Is a final review scheduled?
Turn the checklist into a reusable process
The best process uses a standard form or task that starts as soon as a departure is known.
It should accept:
- employee identity;
- role;
- devices;
- known groups and applications;
- cutoff date;
- successor;
- retention requirements;
- approvals;
- results and exceptions.
A Microsoft 365 security assessment can identify the accounts, privileges, sharing and access methods that make employee departures difficult to manage.
If the departure shows that nobody clearly owns the accounts, devices and applications, a managed and co-managed IT review can separate what should remain with your team from what needs an owner.
Contact Montreal IT to build or review a clearly scoped onboarding and offboarding process.