Offboarding is not simply deleting an account. A departing employee may own mail, files, group memberships, shared access and business knowledge that still matters after their login is blocked.
1. Confirm the departure details
Know the effective date and time, whether the departure is routine or sensitive, who should receive business communications, and who becomes responsible for the person's work.
2. Block interactive access
At the agreed time, disable the user's ability to sign in and review active sessions where appropriate. Do not rely on changing only a password if the account should no longer be usable.
3. Review MFA, devices and privileged roles
- Remove or reset authentication methods that should no longer be valid.
- Check whether the user had administrative roles or unusual permissions.
- Account for company devices and any approved personal-device access.
4. Decide what happens to email
Business continuity may require access to historical mail, a temporary automatic response or forwarding arrangement, or converting the mailbox to a shared workflow. The right choice depends on business need and applicable privacy requirements.
5. Reassign files and collaboration ownership
Check OneDrive, SharePoint, Teams, shared mailboxes and any important workflows the employee owned. Identify data that should be transferred rather than leaving it tied to an inactive identity.
6. Remove group and application access
Microsoft 365 is only one part of the access picture. Review business applications, password managers, VPNs, accounting systems, websites, vendor portals and physical access where relevant.
7. Preserve records before license removal or deletion
Retention requirements vary. Decide what information must remain available and how it will be retained before removing licenses or deleting accounts.
8. Document the result
Record what was disabled, transferred, retained and assigned to a new owner. A repeatable checklist reduces uncertainty and makes future offboarding faster.