Employee Offboarding: The Access Nobody Remembers
Disabling the mailbox is the easy part. Here is the access that outlives a departure, the order to work in, and the 30-day clock most owners never hear about.
By Cohesive Security
Someone hands in their notice. HR knows on Monday, the team knows by Wednesday, and IT finds out the following Tuesday when a laptop turns up on a desk with nobody sure what to do with it.
By then the email account has usually been switched off, and everyone considers the matter closed. It rarely is. Access accumulates quietly over a few years across dozens of systems, most of which were never written down, and switching off the mailbox closes exactly one of them.
None of this assumes bad intent. The overwhelming majority of departures are ordinary, and the checklist is not an accusation. It is also a protection for the person leaving, because an account that stays live after they have gone makes anything that happens on it ambiguous.
Key takeaways:
- Disable, do not immediately delete. Deleting a Microsoft 365 account starts a 30-day clock after which the mailbox and files are gone permanently.
- Changing a password does not sign someone out. Active sessions have to be revoked separately, and that is the step most often missed.
- The accounts that outlive a departure are the ones outside your directory: the domain registrar, the payment processor, the social accounts, the tool someone expensed.
- Shared logins are why offboarding is hard. Every one of them has to be changed by hand, for everyone.
The real problem is that nobody has the list
Ask most small businesses what a departing employee could reach and the honest answer is a shrug and a guess. That is the actual failure, and everything below is downstream of it.
The fix is not glamorous: keep a list of what each role gets access to, and update it when you add a tool rather than when someone leaves. Then offboarding becomes a lookup instead of an archaeology project conducted under time pressure. If you build nothing else after reading this, build that.
The first hour, in order
Sequence matters here, because a couple of these steps undo each other if you do them backwards.
Block sign-in, do not delete the account. This is step one in Microsoft’s own offboarding guidance and it is deliberate. Blocking stops access immediately while leaving everything intact and recoverable. Deletion is a decision for later, once you are sure nothing is needed.
Revoke active sessions. The one people miss. Someone signed in on a phone or a home laptop has a live session that a password change does not necessarily end, so they can stay signed in for a surprisingly long time. Sign the account out of everything explicitly.
Remove their MFA devices. Their phone is still a registered second factor, which also means it can be used in an account recovery flow. Take it off the account.
Deal with the mobile device. If company mail was on a personal phone, remove the organization’s data from it. Microsoft’s process covers wiping and blocking the device; the important part is that it happens while you still have a working relationship rather than three weeks later.
Collect the hardware, and check what is on it. Laptop, any external drives, access badge, hardware tokens.
The 30-day clock nobody mentions
This is the detail that catches people, and it is worth knowing before you tidy up rather than after.
In Microsoft 365, deleting a user account or removing their license starts a countdown. Microsoft’s documentation is specific: when you remove or delete a license, the former employee’s email, contacts, and calendar are retained for 30 days and are then deleted permanently. Delete the account itself and the OneDrive and Outlook content is likewise retained for 30 days.
There is a useful wrinkle in the same guidance. If you remove the license but do not delete the account, the content in that person’s OneDrive remains accessible to you even after the 30 days. So the safe order is: block sign-in, get what you need out, hand the mailbox and files to whoever is taking over the work, and only then decide about deletion.
Two practical moves. Convert the mailbox to a shared mailbox, or forward it, so that customers emailing the old address still reach a human. And if there is any prospect of a dispute or an investigation, put the data on legal hold before touching anything, and take advice on that rather than improvising. If your accounts sync from an on-premises directory, note that deletions have to happen there, not in the cloud admin center.
The long tail, and why it is long
Your directory covers the accounts you provisioned. The problem is everything else, and this is the part that quietly stays open for years.
Work through: the domain registrar and DNS host, the website admin, social media accounts, the payment processor, the accounting and payroll systems, the phone system, remote access accounts, the file-sharing tools, any client system where they had their own login, and every application somebody signed up for on a company card without telling anyone. Then the technical leftovers: API keys they generated, scheduled reports and automations running under their name, and anything pointing at their personal phone number for verification.
The registrar deserves singling out. Whoever controls it can redirect your website and your email, and it is almost never in anyone’s offboarding checklist.
Then the awkward category: shared and generic logins. The “accounts@” mailbox everyone uses, the wifi password, the login for the supplier portal that only has one seat. These cannot be revoked, only changed, and every change means telling everyone still there. If that sounds like a bad afternoon, it is, and it is the argument for a password manager with a company vault: rotation becomes a handful of clicks instead of a scavenger hunt, and you get a record of who could see what.
Rotate what they knew, not just what they held
Anything the person could have memorized or written down is still theirs after their access is gone. Shared passwords, the alarm code, the safe combination, the wifi key.
The test is simple: if knowing it is enough to use it, change it. If holding something is required, revoking the thing they held is enough. Related: if administrator credentials were ever shared with them, those get changed too, and while you are there it is a good moment to check the strength of the second factor protecting those accounts.
Write down that you did it
Dated, with what was disabled and by whom. This takes two minutes and pays off twice.
Compliance frameworks ask for evidence of access removal, not an assurance that it happens. So do cyber insurance questionnaires, which increasingly want to know that offboarding is a defined process. A short record per departure is the cheapest way to have an answer ready.
One boundary worth naming: what you may monitor, retain, or access in a departing employee’s mailbox is a legal question as much as a technical one, and it varies by where you and they are. If a departure is contentious, talk to your employment counsel before you start pulling data.
Making it routine
The version that works is boring: a written checklist, kept with the access list, run the same way every time, whether the person is the office junior or a partner. Most of the risk here comes from improvisation on a busy week.
Keeping that current across a growing set of applications is a standing job rather than a one-off, and it is part of what managed IT covers: an inventory that stays accurate, so offboarding is a lookup. It matters most in firms where people join and leave around client work, which is why we build it into how we support professional services clients.
If you would like a look at what your last few departures actually left open, that is something we check in a free assessment. Or email hello@cohesivesecurity.com and we will send you the checklist we use.