954-539-5678Free audit
Menu

Cybersecurity · Offboarding

The IT offboarding checklist that closes every door

What to do before, during and after an employee’s last day so they lose access to everything and the business keeps everything.

Timed steps from notice to deletion

Microsoft 365 and Google Workspace specifics

The systems people usually forget

Get your free Technology Health Assessment

30 minutes of data collection, your report the next day, yours to keep with no obligation. Or pick a time now. Or call 954-539-5678.

The short version

An employee offboarding checklist for IT has one goal: on the person’s last day, they lose access to everything, and the business keeps everything. In practice that means five jobs, in this order:

  1. Cut access to email, files, apps, VPN, Wi-Fi and the building, timed to the exit conversation.
  2. Kill active sessions so a phone or laptop that is already signed in stops working too.
  3. Recover devices and wipe company data from any personal phone.
  4. Keep the data: mailbox, files and anything the business or the law needs.
  5. Change what they knew: shared passwords, door codes, admin credentials.

Below is the full checklist we use, split by timing, with the specific steps for Microsoft 365 and Google Workspace.

Why offboarding fails in small businesses

Most access left behind is not malicious. It is forgotten. The office manager disables the email account, but nobody remembers the accounting software login, the shared social media password, the domain registrar or the free file-sharing account the person set up three years ago. Those forgotten accounts are how former employees, or whoever steals their passwords later, get back in.

The fix is a written list that covers every system, owned by one person, done the same way every time. Federal security guidance treats this as a standard control: NIST SP 800-53 includes personnel termination (PS-4), which calls for disabling access, retrieving company property and keeping access to company information within a defined time after someone leaves.

Before the last day

  • HR or the manager notifies IT with the date, time and whether the exit is voluntary or not.
  • Pull an access list for the person: every app, shared mailbox, distribution list, admin role, MFA device, key card and shared password they know. Single sign-on (SSO) and a password manager make this much easier.
  • Decide who takes over their email, files, open tickets, client relationships and recurring tasks.
  • Identify anything only they control: vendor accounts, the domain registrar, social media, payment portals, the phone system, cloud subscriptions billed to their card.
  • Transfer ownership of those accounts to a company-controlled address now, while the person is still cooperative.
  • For an involuntary exit, schedule the access cut for the moment the meeting starts, not after.

On the last day: the first hour

  • Block sign-in to the main account (Microsoft 365 or Google Workspace). Do not delete it yet.
  • Reset the password and revoke all active sessions and tokens.
  • Remove MFA methods and app passwords registered to the account.
  • Disable SSO-connected apps, VPN and remote access tools.
  • Remove any admin roles, in your tenant and in every other system.
  • Collect the laptop, phone, key card, keys and security key. Record serial numbers.
  • Remote-wipe company data from personal phones and tablets enrolled in mobile device management.
  • Disable the badge or key card and change door or alarm codes if they knew them.

This is the step where “same-day removal of leavers” matters. Delays of a week or two are common when nobody owns the list, and that is the window that causes problems.

Microsoft 365 steps

Microsoft’s own sequence for removing a former employee is a good backbone:

  1. In the Microsoft 365 admin center, block sign-in and sign the user out of all sessions.
  2. Save mailbox contents or place them on hold if there is a legal or business need (Purview eDiscovery supports legal holds).
  3. Wipe and block their mobile devices.
  4. Convert the mailbox to a shared mailbox, or forward email to the person taking over, so customer email is not lost.
  5. Give the successor access to their OneDrive files.
  6. Remove the license so you stop paying for it.
  7. Delete the account when you no longer need it.

Watch the clock: according to Microsoft, after you delete an account or remove a license, email is kept for 30 days and then permanently deleted. Move what you need before then. If you sync accounts from an on-premises Active Directory, disable the user there, not just in Microsoft 365.

Google Workspace steps

  1. In the Google Admin console, reset the password and reset sign-in cookies to end active sessions.
  2. Remove recovery email and phone, app passwords, security keys and authorized third-party apps (OAuth tokens).
  3. Wipe the account from mobile devices.
  4. Transfer Drive files, calendar and other data to a new owner.
  5. Set up mail routing or an alias so incoming email reaches someone.
  6. Suspend the account, or assign an Archived User license if you need to keep the data under Vault.
  7. Delete the account only after data is preserved. Google notes that deleting a user also deletes their data, including data held in Vault.

Not sure what a leaver could still reach?

Our free Technology Health Assessment reviews access, accounts and security in about 30 minutes of data collection, then gives you a plain-language report the next day with the gaps rated and next steps in order. It is yours to keep, with no obligation. Book your free assessment.

Systems people forget

  • Accounting, payroll, banking and payment portals.
  • CRM, marketing email platforms, ad accounts and website admin logins.
  • Social media business accounts and the Google Business Profile.
  • Domain registrar and DNS, which can take your whole email and website offline if lost.
  • Phone system extensions, voicemail and mobile numbers that should be ported to the company.
  • Shared logins in browsers or spreadsheets. Change every one the person could see.
  • Personal cloud storage or USB drives used for work files.
  • Printer and copier scan-to-email profiles.
  • Vendor portals where they were the named contact. Update the contact so password resets do not go to them.

Voluntary vs involuntary exits

The checklist is the same; the timing is not.

Resignation with notice

Use the notice period for handover. Have the person document passwords they manage, transfer account ownership and walk their successor through recurring tasks. Watch for unusual downloads or forwarding rules in the final weeks, and cut access at the end of the last day.

Termination or sudden exit

Cut access while the conversation is happening. Have IT on standby, block sign-in, end sessions and disable remote access at the agreed minute. Collect devices in the meeting. Do the handover work afterward from the preserved data.

Also cover contractors, interns and vendors. They often get accounts with no end date and no one tracking them, which is why a quarterly access review matters.

Within the first week

  • Confirm the laptop is backed up if needed, then wipe and reimage it before reissuing.
  • Check sign-in logs for any attempts on the old account.
  • Remove the person from groups, shared mailboxes, Teams or Chat spaces and distribution lists.
  • Set an auto-reply naming the new contact, if appropriate.
  • Reassign or cancel licenses and subscriptions so you stop paying for them.
  • Update your documentation and the access list for the successor.

Within 30 to 90 days

  • Decide on retention: keep, archive or delete the mailbox and files based on your retention policy and any legal hold.
  • Delete the account once data is safe, or keep it disabled under an archive license.
  • Run a quick access review across all systems to catch anything missed.
  • File the completed checklist with HR records. Cyber-insurance questionnaires and audits increasingly ask how quickly leavers lose access.

Make it repeatable

The checklist only works if it runs the same way every time. Three habits make that happen:

  • One trigger. HR’s exit notice automatically opens an IT ticket with the checklist attached.
  • One owner. A named person, or your IT provider, signs off that every line is done.
  • One source of access. The more apps sign in through Microsoft 365 or Google Workspace, the more one click cuts off. Our systems integration and automation work often starts here.

JLB USA handles onboarding and offboarding as part of our managed IT services for businesses with roughly 25 to 100 employees, with same-day removal of leavers and regular access reviews under our cybersecurity service. Call 954-539-5678 or start with the free assessment.

Book it now

Pick a time for your 30 minutes

Choose a slot that suits you. We’ll confirm by email, collect the data with you on the call, and send your report the next day. It’s free, and the report is yours to keep with no obligation.

Prefer to talk first? Call 954-539-5678, or send the form and we’ll contact you.

Questions we hear

How quickly should a departing employee lose IT access?

On their last day, ideally within the hour of their exit, and at the start of the meeting for an involuntary exit. Delays of days or weeks are when most problems happen.

Should I delete a former employee’s Microsoft 365 account right away?

No. Block sign-in first, save or transfer their mailbox and OneDrive, then remove the license and delete the account. Microsoft keeps email for only 30 days after deletion or license removal, so move what you need before then.

What about employees who use personal phones for work email?

If the phone is enrolled in mobile device management, you can wipe just the company data. If it is not, block their account and end active sessions, and consider requiring enrollment for all staff going forward.

Who should own offboarding, HR or IT?

Both. HR triggers it and handles the people side; IT, or your IT provider, cuts access and signs off the checklist. One named owner for the IT checklist prevents gaps.

What should we keep from a former employee’s account?

That depends on your retention policy, contracts and any legal holds. Most businesses keep email and files for a set period through a shared mailbox, archive license or backup. Confirm requirements with your counsel.

Related services

Want to know where your business stands?

Pick a time for my free assessmentCall 954-539-5678