Employee leaving: an offboarding checklist for Microsoft 365
A colleague is leaving. What needs to happen in Microsoft 365, and in which order, so no access stays open and no files or email get lost?
When a colleague leaves, their access has to close. But not carelessly: the account holds email, files and ownership of teams and groups that others need to carry on with. Delete the account too soon and you lose data. Too late and access stays open.
This checklist puts the steps in a sensible order. It assumes a normal situation in a small or mid-sized company; if someone leaves on bad terms, speed matters even more.
Before the last working day
Agree the handover. Who takes over the email? Who gets the files? Who becomes owner of the teams and groups the leaver owns? Write it down so the admin knows what to do.
List access outside Microsoft 365. Think of the accounting system, the banking portal, supplier portals, social media accounts and shared passwords. They don’t disappear with the Microsoft account.
On the last day: close access
- Block sign-in. In the Microsoft 365 admin centre you can block sign-in for the user. The account still exists, but nobody can log in with it.
- Revoke active sessions. A blocked account can stay signed in for a while on devices where it was already active. Sign the user out of all sessions so existing sign-ins expire too.
- Set a new password. As an extra safeguard, especially if the password may be known elsewhere.
- Remove MFA methods. Remove registered phones and authenticator apps so an old device can’t approve access any more.
- Check forwarding rules. See whether the mailbox has rules forwarding email to an external address, and remove them.
Hand over email and files
- Convert the mailbox to a shared mailbox. Colleagues can then keep reading and answering the email. A shared mailbox doesn’t need its own licence as long as it stays under 50 GB and has no archive or retention policy that requires one. Consider setting an automatic reply with a new contact address.
- Hand over OneDrive. Give the manager or successor access to the OneDrive files. Note: after a user is deleted, their OneDrive is kept for 30 days by default and then removed. You can change that period in the SharePoint admin centre, but it’s safer to move the files before deleting the account.
- Assign new owners for teams, groups and SharePoint sites the leaver (solely) owned.
Licences and devices
- Remove licences. Once the mailbox and files are sorted, remove the licences from the account. Note: a freed-up licence still costs money while it’s part of your subscription. Reduce the count or assign it to a new colleague.
- Sort out devices. Have the laptop, phone and any access badges returned and record that. If you use Intune or another management platform, wipe or retire company devices and data.
- Change shared passwords the colleague had access to, such as a shared Wi-Fi password or a shared supplier account.
Only then: delete the account
- Delete the user account once everything has been handed over. A deleted user can be restored in Microsoft 365 for 30 days. After that it’s permanent.
Record what you did
Note who carried out which step and when. It seems unnecessary, until an auditor, a client or a court asks a year later whether a former employee’s access was really removed.
Why it so often goes wrong
The problem is rarely that admins don’t know what to do. It’s that in a small company offboarding happens a few times a year. Just often enough to think you know it, just rarely enough to forget a step. Often someone different handles it than last time. And the checklist sits in a document nobody opens at that moment.
In short
- Agree the handover in advance.
- Close access first: block, revoke sessions, remove MFA, check forwarding rules.
- Then hand over email and files, before deleting the account.
- Sort out licences and devices, change shared passwords.
- Delete the account last, and record what you did.
With ClickCheck, this checklist appears by itself the moment someone clicks “Delete user” in the admin centre. Read more about ClickCheck for Microsoft 365.