Keep Control of Your IT Access

Prevent vendor lock-in and make renewals and support easier. Book a Fit Check to verify your license ownership, admin access, and recovery controls, then get a clear list of any gaps.

Offboarding Checklist (Remove Access Safely When Someone Leaves)

Last updated

April 19, 2026

Reviewed by

Reviewed by: IT Service Delivery Lead

Speakable Summary

Offboarding removes access fast and protectsbusiness data. Book a Fit Check to standardize offboarding and preventlingering account risk.

Opening

Offboarding is where many SMBs get hurt. Accessstays active, shared passwords remain unchanged, and business data walks outthe door by accident or intent.

Good offboarding is not harsh. It is clean andconsistent. It protects the business, protects the team, and prevents paniclater when a former employee still has access.

This page provides a copy/paste offboardingchecklist and explains what should be done immediately, what should beverified, and what should be documented.

Direct Answer

Offboarding is the process of removing accessand securing business data when someone leaves. It reduces risk by closing accountsquickly and documenting what changed.

LINK: IT Support page
LINK: Managed IT Services
LINK: Managed IT Pricing

What’s included vs what’s usually extra

Typically   included in offboarding support

Usually   extra as a project

Disabling accounts and removing access

Large system redesign of permissions

License removal and mailbox handling

Tenant migrations and major restructures

MFA reset and session revoke steps

Rebuilding identity and access architecture

Device retrieval coordination and wipe steps

Full device refresh programs

Closeout notes and completion confirmation

Legal discovery and forensic work

●    
Disable access and revoke sessions immediately

●    Transfer ownership of files andshared resources

●    Confirm completion with adocumented checklist

Included means routine access removal withinscope. Extra means major permission rebuilds and large structural changes.

Copy/paste offboarding checklist

Immediate steps

●    Confirm the exact separation timeand who approves access removal

●    Disable the user account at theseparation time

●    Revoke active sessions andsign-ins

●    Reset and remove MFA methods whereapplicable

●    Remove the user from all groupsand distribution lists

●    Remove privileged roles and adminaccess first

●    Disable or rotate any sharedpasswords the user knew

●    Remove access to line of businessapps and vendor portals

●    Forward or block inbound email asapproved

●    Document the actions withtimestamps in the ticket

LINK: Microsoft 365 Support
LINK: Cybersecurity

Data and ownership protection

●    Transfer ownership of OneDrive andkey cloud folders

●    Preserve mailbox data based onpolicy and legal needs

●    Remove access to shared mailboxesand delegated permissions

●    Reassign ownership of sharedcalendars and Teams channels

●    Review file shares and removeaccess paths

●    Confirm the user does not owncritical vendor accounts

●    Update password vault entries andaccess lists

●    Confirm who now owns the user’stickets and work queues

●    Document what was transferred andto whom

Device and physical access

●    Confirm device return timing andshipping process if remote

●    Disable device access if neededbefore return

●    Wipe devices only after datahandling is confirmed

●    Remove device from management orassign to a new user

●    Remove access to Wi Fi networksand VPN if used

●    Collect badges and physical keyswhere applicable

●    Document device serial numbers andfinal status

●    Confirm printing access and shareddevice access is removed

●    Confirm any local data backupneeds are addressed

LINK: Help Desk
LINK: FAQ

Final verification

●    Confirm the account cannot sign in

●    Confirm mailbox handling matchespolicy

●    Confirm shared resources no longershow the user as owner

●    Confirm group membership and adminroles are cleared

●    Confirm vendor portals show accessremoved

●    Confirm shared passwords wererotated

●    Confirm device status is secured

●    Close the ticket with clearcloseout notes and timestamps

●    Confirm manager approval thatoffboarding is complete

What varies and why

●    It depends on the separation typeand the timing requirements.

●    It depends on whether the user hadprivileged access or admin roles.

●    It depends on how many businessapps and vendor portals exist.

●    It depends on whether sharedaccounts and shared passwords are used.

●    It depends on legal retention andmailbox preservation rules.

●    It depends on device returnlogistics for remote staff.

Decision matrix

Situation

Choose

Because

Separation is immediate

Disable and revoke sessions first

Risk window must close fast

User had admin access

Remove roles before anything else

Blast radius is larger

Many shared passwords exist

Rotate passwords immediately

Lingering access is likely

User owned key files

Transfer ownership

Business continuity depends on it

Remote device is not returned

Disable and wipe when approved

Data risk increases

Vendor portal access is unclear

Audit access and remove

Lockout risk must drop

Comparisons

Disable account vs delete account

Disabling preserves evidence and data whileaccess is removed. Deleting can remove important records and complicaterecovery.

Action

Best   for

Trade   off

Disable

Most offboarding events

Requires retention policy

Delete

Rare cases with clear policy

Can remove history

Offboarding in Microsoft 365 vs offboarding everywhere

Microsoft 365 offboarding is critical but notsufficient. Vendor portals and line of business apps often hold the real risk.

Scope

Best   for

Trade   off

Microsoft 365 only

Basic environments

Leaves vendor risk

Full access sweep

Most SMBs

Requires a checklist

Common mistakes

●    Waiting hours or days and fix itby scheduling offboarding at the separation time.

●    Removing email but forgettingvendor portals and fix it by doing a full access sweep.

●    Leaving shared passwords unchangedand fix it by rotating them immediately.

●    Deleting accounts too soon and fixit by disabling and following retention policy.

●    Closing the ticket without proofand fix it by confirming sign-in denial and documenting completion.

Common objections

We trust the employee. Trust does not removeaccess risk. Clean offboarding protects everyone and prevents accidents.

We do not have shared passwords. Many teams dowithout realizing it. A quick vault and app review confirms reality.

Offboarding is too much work. A standardchecklist makes it fast. The time saved later is worth it.

We only need to disable email. Access exists inmany places beyond email. Vendor portals and file shares must be included.

We will handle it later. Later creates a riskwindow. Immediate steps reduce exposure fast.

How we operate

We run offboarding through a ticketing frontdoor with clear timing and approvals. Each step is documented with timestampsso completion is provable.

We reduce repeat access gaps by standardizingjoiner mover leaver steps and enforcing credential ownership. Practicalcontrols align to NIST standards without heavy process.

We protect business continuity by transferringownership of data and access cleanly. Backup monitoring and restore testingsupport recovery if mistakes happen.

LINK: Backup & Disaster Recovery

What we measure

●    Time from separation to accessremoval

●    Percentage of offboardingscompleted on time

●    Shared password rotationcompletion rate

●    Vendor portal access removalcompletion rate

●    Documentation quality in closeoutnotes

Get My 15 Minute Fit Check

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.