Employee Owned Since 2022  |  Serving Chicagoland since 1996Support: 630-523-0220Sales: 630-526-8030Remote support

WEBIT Learning Hub

Secure Employee Offboarding: The Steps Most Companies Skip

Most companies have an offboarding checklist. Far fewer follow it the same way every time, and the gaps are where former employees keep access for weeks. Secure employee offboarding depends less on the checklist itself and more on timing, ownership, and the steps that fall between HR and IT.

Where offboarding breaks down

From the service desk side, the failure pattern is consistent. HR knows about a departure days in advance, yet IT hears about it on the last afternoon, or after the person has already left. Then the technician rushes, disables the main account, and closes the ticket.

Disabling the Microsoft 365 account is necessary, but it is only the most visible step. The accounts and sessions that live outside your main directory are the ones that linger.

The problem is rarely skill. Instead, it is a process that depends on someone remembering to send an email at the right moment.

Timing depends on the kind of exit

Not every departure carries the same risk. A retiring employee who gives a month’s notice is different from a termination the person does not see coming.

Planned departures

For planned exits, IT should get notice as soon as HR does. That lead time lets the team transfer file ownership, change shared credentials, and schedule the cutoff for the end of the final day.

Involuntary departures

For terminations, access removal should happen during or just before the conversation. So HR and IT need a quiet, prearranged signal that lines the cutoff up with the meeting. Waiting an hour leaves time to download files or forward email.

The secure employee offboarding steps most companies skip

These are the items I see missed most often.

  • Active sessions: Disabling an account does not instantly end every signed-in session. Microsoft’s guidance on revoking user access in Microsoft Entra ID treats disabling the account and revoking sessions as separate steps.
  • Mobile devices: Phones and tablets with company email need company data removed, not just a password change.
  • Mailbox rules: Look for rules that forward mail outside the company, and delete them.
  • MFA methods: Remove the person’s registered sign-in methods so nobody can reuse them.
  • Apps outside single sign-on: Vendor portals, social media accounts, and industry tools often use separate logins that nobody tracks.
  • Shared passwords: Change any shared credential the person knew, such as a Wi-Fi key or a common admin login.
  • Owned automations: Flows, scheduled reports, and shared folders tied to the account can break or stay exposed.
  • Physical access: Keys, badges, and alarm codes still matter.

The FTC’s guide to protecting personal information makes the same point plainly. It advises businesses to have a procedure that removes departing workers’ access to sensitive information, including ending their passwords and collecting keys and ID cards.

Handle the data, not just the access

Access removal protects you from the former employee. However, you also need to protect the work they leave behind.

First, decide who receives the person’s email going forward. Converting the mailbox to a shared mailbox, or granting a manager access, keeps customer messages from bouncing. Next, move OneDrive files to the manager before any retention window expires. Finally, confirm your retention settings meet legal and contract obligations before you delete anything.

Licensing deserves a line too. Unused licenses keep billing every month, so reclaim them once the data handoff is complete.

Make HR and IT share one workflow

Offboarding fails most often at the handoff. The fix is a single workflow that both departments use, rather than an email from HR and a separate checklist in IT.

A good workflow starts when HR enters a departure date. It then notifies IT, the manager, and whoever handles facilities. Each group signs off on its own section, and the ticket stays open until every section is done.

Managers matter here more than people expect. They know which vendor portals, shared accounts, and side tools the employee actually used. Ask them directly, because those systems rarely appear in any central inventory.

Audit 30 days later

A short follow-up review catches what the first pass missed. About a month after the departure, check sign-in logs for activity on the old account. Also confirm that forwarding rules stayed removed and that licenses came back.

This audit takes minutes, yet it turns secure employee offboarding from a one-time task into a process you can prove. That proof matters when a cyber insurer or auditor asks how you handle departures.

Keep the completed checklist with the ticket, so you have a record of who did what and when.

Special cases that need extra care

Administrators and IT staff

When someone with admin rights leaves, the scope grows quickly. Change every admin password they knew, review service accounts they created, and check firewall and remote access settings. Also confirm they no longer appear as an owner on your cloud tenant or domain registrar.

Executives

Executive mailboxes often hold contracts, board material, and banking conversations. So plan carefully who gets access afterward, and keep the mailbox under retention rather than deleting it.

Remote employees

Remote staff usually have company laptops at home. Arrange the return before the last day, with prepaid shipping if needed. Meanwhile, keep the device locked or remotely wiped until it arrives, because an unreturned laptop is both a data risk and an asset loss.

How WEBIT approaches this

We treat offboarding as a scheduled change, not an urgent scramble. Each client gets a standard runbook, so every departure follows the same steps no matter which technician handles it.

When a departure is urgent, speed matters, and our managed IT services acknowledge tickets within 15 minutes. We also connect offboarding to broader identity and access work through our cybersecurity services.

Key takeaways

  • Disabling the main account is necessary but not sufficient.
  • Revoke sessions, remove company data from phones, and clear forwarding rules and MFA methods.
  • Involuntary exits need access removed during the conversation, not after it.
  • One shared HR and IT workflow closes most of the gaps.
  • A 30-day audit turns secure employee offboarding into something you can prove.

Want a second opinion on your offboarding process? Talk to an owner.

Talk to an owner

Want help applying this to your business? A 30-minute discovery call gets you honest advice.

Schedule a discovery call

Industry whitepapers

In-depth guides for 13 industries, from medical to manufacturing.

Browse whitepapers →

Estimate your IT cost

Real per-unit pricing, updated as you go.

Open the calculator →

Keep reading

Two new clients per month. Maximum.

Ready to talk to an owner?

Every conversation starts with an honest look at where you are today. No pressure, no pitch deck, and no obligation.