


08 Oct 26
An employee hands back their laptop on Friday. On Monday, a customer needs a proposal stored in their OneDrive, a supplier portal still lists them as the only administrator, and nobody knows whether their phone can still open work email.
This is an illustrative scenario, but it is a useful test of your process. Good employee offboarding has two outcomes: the departing person loses access at the agreed time, and the business keeps the information and ownership it needs to operate. A request to “delete their account” does not describe either outcome clearly enough.
Start with one offboarding request owned by the manager or nominated HR contact. Record the person’s identity, final working time, the person authorising access removal and the IT contact responsible for completing it. Include the time zone when staff or support teams work interstate.
A planned departure gives you time to organise a handover. An urgent departure needs a coordinated access cut-off. Agree that timing with the authorised business contact; IT should not have to infer it from a calendar invitation or an informal message.
Name a backup approver too. An offboarding process that depends on one person being available is vulnerable precisely when the request is unexpected.
Use the organisation’s application and device records, then ask the manager to identify tools used by their team. Check these areas:
Do not assume a central sign-in change covers every application. Ask each application owner to confirm how that service removes access, including any active sessions and independent credentials.
Microsoft’s guidance for preventing a former employee’s access covers password resets, signing out sessions and blocking sign-in. These are distinct controls, and changes can take time to propagate. Ask your IT team to apply the appropriate controls for your environment and verify the result, rather than treating a changed password as proof that every session has ended.
For applications outside Microsoft 365, record their completion separately. If shared credentials were known to the departing person, arrange their replacement and update dependent systems. If a report or integration runs under that person’s account, arrange a supported ownership change and test it. Keeping their personal sign-in active indefinitely is a poor substitute for a proper handover.
Before removing licences or deleting accounts, identify the information the business needs, its destination and the approved people who need access. Agree any retention requirements with the responsible business owner. Ask IT to check the actual configuration and licensing implications before making changes.
Microsoft documents ways to preserve OneDrive files and provide access to email. That technical capability does not mean every manager needs unrestricted access to everything. Define the purpose and scope of the handover, record approval and set a review date for temporary access.
Decide how customers should reach the team next: an automatic reply, an approved forwarding arrangement or a shared mailbox may suit different situations. Microsoft specifically warns not to delete the account that anchors forwarding or a converted shared mailbox. Account deletion belongs after these decisions, and may not be appropriate for the chosen arrangement.
Record which devices were returned and which remain outstanding. Have IT confirm the approved treatment of company data before equipment is reassigned. For personally owned devices, use the agreed management process and establish what can be removed without affecting personal information. A remote action marked “pending” is still an outstanding task.
Close the request with evidence against each outcome: access controls completed, business files handed over, application ownership accepted, devices accounted for and exceptions assigned an owner and due date. Review temporary mailbox access and forwarding on their agreed expiry dates.
Choose one recent departure and ask the manager and IT team to walk through the record together. Can they show who authorised the cut-off, which systems were checked and who now owns the work? Missing answers give you a concrete improvement list before the next request arrives.
Our view at Zarbtech is that offboarding works best as a repeatable business process with clear technical responsibilities. Our Managed IT services support day-to-day technology operations, while Co-Managed IT provides support alongside an internal team. If responsibility for access, devices and handover falls between teams, bring your current checklist to a conversation with us about the support your organisation needs.