How to Properly Offboard an Employee from Microsoft 365
Most Microsoft 365 offboarding processes are incomplete. Accounts are disabled but active sessions are not revoked. Mailboxes are forwarded but not preserved. Devices are returned but not wiped. Licences are left assigned for months. The gaps are security risks, compliance problems, and wasted spend — often all three at once.
A complete offboarding process needs to happen on the day the person leaves, not when IT gets around to it. A former employee with an active Microsoft 365 account can still reset their password, access email, download files, and authenticate to connected applications — sometimes for weeks after departure.
The complete Microsoft 365 offboarding checklist
- 1
Block the user from signing in immediately
In the Microsoft 365 admin centre, set the account to 'Block this user from signing in'. This prevents new sign-ins but does not terminate existing active sessions. It must be the first step on the day of departure.
- 2
Revoke all active sessions
Blocking sign-in does not end sessions that are already authenticated. In Entra ID, go to the user's profile and select 'Revoke sessions'. This invalidates all current authentication tokens, ending active connections to Outlook, Teams, SharePoint, and any connected applications.
- 3
Reset the account password
Reset to a strong random password that nobody knows. This ensures that even if there is a session token edge case, the account cannot be re-authenticated using the former employee's credentials.
- 4
Remove from distribution lists and shared mailboxes
Remove the user from all distribution groups, mail-enabled security groups, and shared mailbox access. Leaving them in distribution lists means they continue to receive group email if the mailbox is later reactivated. Leaving shared mailbox access means they retain visibility into team communications.
- 5
Set up mailbox auto-reply and forwarding
Configure an out-of-office auto-reply explaining that the person has left and who to contact. If needed, set up email forwarding to their manager or successor for a defined period. Document when forwarding will be removed.
- 6
Export and preserve the mailbox
Before deleting the account, export the mailbox to a PST file or place it on litigation hold. The mailbox contains potentially important business correspondence. Losing it is irreversible. How long to retain it depends on your business requirements and any applicable compliance obligations.
- 7
Transfer OneDrive data ownership
By default, Microsoft deletes OneDrive data 30 days after an account is deleted. Before deletion, assign a manager or secondary owner to the OneDrive and transfer any important files to SharePoint or another user's OneDrive. In the admin centre, you can set the OneDrive secondary admin before account deletion.
- 8
Review and remove SharePoint permissions
If the user was granted direct permissions to any SharePoint sites (not via a group), those permissions remain even after account deletion in some configurations. Review site permissions and remove any explicit access grants.
- 9
Remove from Microsoft Teams and channels
Remove the user from all Teams they are a member of. This revokes access to channel files and conversation history. Note: Teams membership removal does not immediately remove their messages from channel history — that content remains visible to other members.
- 10
Wipe or reclaim managed devices
If the user had a company-managed device enrolled in Intune, either issue a remote wipe (if the device is being returned) or remove the device from Intune management and reset it. For BYOD devices, issue a selective wipe to remove corporate applications and data without wiping the personal device.
- 11
Revoke access to connected applications
Review OAuth applications that the user authorised to access their Microsoft 365 account. Third-party applications (CRM integrations, productivity tools, automation platforms) may retain delegated access after account deactivation. In Entra ID, review the user's app registrations and revoke any that should not persist.
- 12
Remove any admin roles
If the departing employee held any admin roles — Exchange Admin, SharePoint Admin, Teams Admin, or Global Admin — remove those role assignments before or at the time of blocking the account. An active admin role assignment is a significant risk even with sign-in blocked.
- 13
Reclaim and reallocate the licence
Microsoft 365 licences are billed per active assignment. After completing the steps above, unassign the licence from the account. If a replacement hire is joining, reallocate it. If not, this reduces your licence cost. Many organisations carry departed-employee licences for months without realising it.
- 14
Delete or retain the account per your policy
Decide whether to delete the account or retain it in a disabled state. Retaining it preserves the email address for future forwarding configuration and keeps the account visible in historical records. Deleting it starts the 30-day recovery window before permanent deletion. Either approach is valid — what matters is that the decision is deliberate and documented.
The steps most businesses miss
Blocking sign-in and resetting the password are the steps almost everyone does. The steps most organisations miss are revoking active sessions, removing OAuth application access, reviewing SharePoint direct permissions, and preserving OneDrive data before the deletion window expires.
The OneDrive data loss is the most common and most irreversible. A manager contacts IT six weeks after a departure asking for a file the former employee was working on. The account was deleted, the 30-day window has passed, and the data is gone. This happens regularly and is entirely preventable.
The timing question
Offboarding should happen on the last day of employment, not when IT is notified or when someone files a ticket. The gap between departure and account deactivation is the period of highest risk — the person has left, potentially on poor terms, and still has full access to their Microsoft 365 account.
HR and IT need a process that ensures notification happens on or before the last day. In many organisations this is a manual handoff that gets missed. Automating the notification via a Power Automate flow triggered by an HR system update eliminates the gap.
The average time between an employee's last day and account deactivation, for organisations without a documented offboarding process, is measured in days to weeks — not hours. That window is a security and compliance exposure that grows with every hour it remains open.
Automating the process
Employee offboarding is one of the highest-value processes to automate in Microsoft 365. A Power Automate flow triggered by an HR system update or a simple form submission can initiate most of the steps above automatically: blocking sign-in, revoking sessions, sending manager notifications, creating a checklist of manual steps, and setting calendar reminders for licence reclamation.
The manual steps — data review, device collection, role removal decisions — still require human action. But the immediate security steps can happen without IT involvement within minutes of the notification.
Next step
Managed Cloud
Managed Cloud includes documented offboarding procedures, licence management, and ongoing environment hygiene — so departures are handled consistently and nothing falls through the gap.
Learn more