Cybersecurity · Offboarding
What to do before, during and after an employee’s last day so they lose access to everything and the business keeps everything.
Timed steps from notice to deletion
Microsoft 365 and Google Workspace specifics
The systems people usually forget
30 minutes of data collection, your report the next day, yours to keep with no obligation. Or pick a time now. Or call 954-539-5678.
An employee offboarding checklist for IT has one goal: on the person’s last day, they lose access to everything, and the business keeps everything. In practice that means five jobs, in this order:
Below is the full checklist we use, split by timing, with the specific steps for Microsoft 365 and Google Workspace.
Most access left behind is not malicious. It is forgotten. The office manager disables the email account, but nobody remembers the accounting software login, the shared social media password, the domain registrar or the free file-sharing account the person set up three years ago. Those forgotten accounts are how former employees, or whoever steals their passwords later, get back in.
The fix is a written list that covers every system, owned by one person, done the same way every time. Federal security guidance treats this as a standard control: NIST SP 800-53 includes personnel termination (PS-4), which calls for disabling access, retrieving company property and keeping access to company information within a defined time after someone leaves.
This is the step where “same-day removal of leavers” matters. Delays of a week or two are common when nobody owns the list, and that is the window that causes problems.
Microsoft’s own sequence for removing a former employee is a good backbone:
Watch the clock: according to Microsoft, after you delete an account or remove a license, email is kept for 30 days and then permanently deleted. Move what you need before then. If you sync accounts from an on-premises Active Directory, disable the user there, not just in Microsoft 365.
Our free Technology Health Assessment reviews access, accounts and security in about 30 minutes of data collection, then gives you a plain-language report the next day with the gaps rated and next steps in order. It is yours to keep, with no obligation. Book your free assessment.
The checklist is the same; the timing is not.
Use the notice period for handover. Have the person document passwords they manage, transfer account ownership and walk their successor through recurring tasks. Watch for unusual downloads or forwarding rules in the final weeks, and cut access at the end of the last day.
Cut access while the conversation is happening. Have IT on standby, block sign-in, end sessions and disable remote access at the agreed minute. Collect devices in the meeting. Do the handover work afterward from the preserved data.
Also cover contractors, interns and vendors. They often get accounts with no end date and no one tracking them, which is why a quarterly access review matters.
The checklist only works if it runs the same way every time. Three habits make that happen:
JLB USA handles onboarding and offboarding as part of our managed IT services for businesses with roughly 25 to 100 employees, with same-day removal of leavers and regular access reviews under our cybersecurity service. Call 954-539-5678 or start with the free assessment.
Book it now
Choose a slot that suits you. We’ll confirm by email, collect the data with you on the call, and send your report the next day. It’s free, and the report is yours to keep with no obligation.
Prefer to talk first? Call 954-539-5678, or send the form and we’ll contact you.
On their last day, ideally within the hour of their exit, and at the start of the meeting for an involuntary exit. Delays of days or weeks are when most problems happen.
No. Block sign-in first, save or transfer their mailbox and OneDrive, then remove the license and delete the account. Microsoft keeps email for only 30 days after deletion or license removal, so move what you need before then.
If the phone is enrolled in mobile device management, you can wipe just the company data. If it is not, block their account and end active sessions, and consider requiring enrollment for all staff going forward.
Both. HR triggers it and handles the people side; IT, or your IT provider, cuts access and signs off the checklist. One named owner for the IT checklist prevents gaps.
That depends on your retention policy, contracts and any legal holds. Most businesses keep email and files for a set period through a shared mailbox, archive license or backup. Confirm requirements with your counsel.