Keep Control of Your IT Access
Prevent vendor lock-in and make renewals and support easier. Book a Fit Check to verify your license ownership, admin access, and recovery controls, then get a clear list of any gaps.
Offboarding Checklist (Remove Access Safely When Someone Leaves)
Last updated
April 19, 2026
Reviewed by
Reviewed by: IT Service Delivery Lead
Speakable Summary
Offboarding removes access fast and protectsbusiness data. Book a Fit Check to standardize offboarding and preventlingering account risk.
Opening
Offboarding is where many SMBs get hurt. Accessstays active, shared passwords remain unchanged, and business data walks outthe door by accident or intent.
Good offboarding is not harsh. It is clean andconsistent. It protects the business, protects the team, and prevents paniclater when a former employee still has access.
This page provides a copy/paste offboardingchecklist and explains what should be done immediately, what should beverified, and what should be documented.
Direct Answer
Offboarding is the process of removing accessand securing business data when someone leaves. It reduces risk by closing accountsquickly and documenting what changed.
LINK: IT Support page
LINK: Managed IT Services
LINK: Managed IT Pricing
What’s included vs what’s usually extra
Typically included in offboarding support
Usually extra as a project
Disabling accounts and removing access
Large system redesign of permissions
License removal and mailbox handling
Tenant migrations and major restructures
MFA reset and session revoke steps
Rebuilding identity and access architecture
Device retrieval coordination and wipe steps
Full device refresh programs
Closeout notes and completion confirmation
Legal discovery and forensic work
●
Disable access and revoke sessions immediately
● Transfer ownership of files andshared resources
● Confirm completion with adocumented checklist
Included means routine access removal withinscope. Extra means major permission rebuilds and large structural changes.
Copy/paste offboarding checklist
Immediate steps
● Confirm the exact separation timeand who approves access removal
● Disable the user account at theseparation time
● Revoke active sessions andsign-ins
● Reset and remove MFA methods whereapplicable
● Remove the user from all groupsand distribution lists
● Remove privileged roles and adminaccess first
● Disable or rotate any sharedpasswords the user knew
● Remove access to line of businessapps and vendor portals
● Forward or block inbound email asapproved
● Document the actions withtimestamps in the ticket
LINK: Microsoft 365 Support
LINK: Cybersecurity
Data and ownership protection
● Transfer ownership of OneDrive andkey cloud folders
● Preserve mailbox data based onpolicy and legal needs
● Remove access to shared mailboxesand delegated permissions
● Reassign ownership of sharedcalendars and Teams channels
● Review file shares and removeaccess paths
● Confirm the user does not owncritical vendor accounts
● Update password vault entries andaccess lists
● Confirm who now owns the user’stickets and work queues
● Document what was transferred andto whom
Device and physical access
● Confirm device return timing andshipping process if remote
● Disable device access if neededbefore return
● Wipe devices only after datahandling is confirmed
● Remove device from management orassign to a new user
● Remove access to Wi Fi networksand VPN if used
● Collect badges and physical keyswhere applicable
● Document device serial numbers andfinal status
● Confirm printing access and shareddevice access is removed
● Confirm any local data backupneeds are addressed
LINK: Help Desk
LINK: FAQ
Final verification
● Confirm the account cannot sign in
● Confirm mailbox handling matchespolicy
● Confirm shared resources no longershow the user as owner
● Confirm group membership and adminroles are cleared
● Confirm vendor portals show accessremoved
● Confirm shared passwords wererotated
● Confirm device status is secured
● Close the ticket with clearcloseout notes and timestamps
● Confirm manager approval thatoffboarding is complete
What varies and why
● It depends on the separation typeand the timing requirements.
● It depends on whether the user hadprivileged access or admin roles.
● It depends on how many businessapps and vendor portals exist.
● It depends on whether sharedaccounts and shared passwords are used.
● It depends on legal retention andmailbox preservation rules.
● It depends on device returnlogistics for remote staff.
Decision matrix
Situation
Choose
Because
Separation is immediate
Disable and revoke sessions first
Risk window must close fast
User had admin access
Remove roles before anything else
Blast radius is larger
Many shared passwords exist
Rotate passwords immediately
Lingering access is likely
User owned key files
Transfer ownership
Business continuity depends on it
Remote device is not returned
Disable and wipe when approved
Data risk increases
Vendor portal access is unclear
Audit access and remove
Lockout risk must drop
Comparisons
Disable account vs delete account
Disabling preserves evidence and data whileaccess is removed. Deleting can remove important records and complicaterecovery.
Action
Best for
Trade off
Disable
Most offboarding events
Requires retention policy
Delete
Rare cases with clear policy
Can remove history
Offboarding in Microsoft 365 vs offboarding everywhere
Microsoft 365 offboarding is critical but notsufficient. Vendor portals and line of business apps often hold the real risk.
Scope
Best for
Trade off
Microsoft 365 only
Basic environments
Leaves vendor risk
Full access sweep
Most SMBs
Requires a checklist
Common mistakes
● Waiting hours or days and fix itby scheduling offboarding at the separation time.
● Removing email but forgettingvendor portals and fix it by doing a full access sweep.
● Leaving shared passwords unchangedand fix it by rotating them immediately.
● Deleting accounts too soon and fixit by disabling and following retention policy.
● Closing the ticket without proofand fix it by confirming sign-in denial and documenting completion.
Common objections
We trust the employee. Trust does not removeaccess risk. Clean offboarding protects everyone and prevents accidents.
We do not have shared passwords. Many teams dowithout realizing it. A quick vault and app review confirms reality.
Offboarding is too much work. A standardchecklist makes it fast. The time saved later is worth it.
We only need to disable email. Access exists inmany places beyond email. Vendor portals and file shares must be included.
We will handle it later. Later creates a riskwindow. Immediate steps reduce exposure fast.
How we operate
We run offboarding through a ticketing frontdoor with clear timing and approvals. Each step is documented with timestampsso completion is provable.
We reduce repeat access gaps by standardizingjoiner mover leaver steps and enforcing credential ownership. Practicalcontrols align to NIST standards without heavy process.
We protect business continuity by transferringownership of data and access cleanly. Backup monitoring and restore testingsupport recovery if mistakes happen.
LINK: Backup & Disaster Recovery
What we measure
● Time from separation to accessremoval
● Percentage of offboardingscompleted on time
● Shared password rotationcompletion rate
● Vendor portal access removalcompletion rate
● Documentation quality in closeoutnotes

