Employee Offboarding Checklist: Can Your Old Employees Still Log In?

When an employee leaves your business, there’s usually a familiar checklist to work through. Return the laptop. Hand back the keys. Tell payroll. Redirect their...

Employee offboarding checklist for Microsoft 365 and business system access

Table of Contents

When an employee leaves your business, there’s usually a familiar checklist to work through.

Return the laptop. Hand back the keys. Tell payroll. Redirect their calls. Let customers and colleagues know who their new contact is.

But there’s another question businesses should be asking:

Can that employee still log in?

Over time, employees can build up access to far more than their company email. They may have access to Microsoft 365, Teams, SharePoint, OneDrive, your CRM, accounting software, supplier portals, cloud applications and shared accounts.

If that access isn’t properly removed when someone leaves, accounts and permissions can remain active long after they’re needed.

That’s why a good employee offboarding checklist needs to cover digital access as well as company equipment.

Ways former employees can retain access to business systems and accounts with Employee offboarding checklist

Why employee offboarding matters for cyber security

Employee offboarding isn’t just an HR task. It should also form part of your business cyber security process.

One of the basic principles of good user access management is making sure people only have access to the systems and information they need.

The UK’s National Cyber Security Centre recommends having a formal joiners, movers and leavers process, so access can be added, changed or removed as an employee’s relationship with the business changes. NCSC – Identity and Access Management

Why does this matter?

Because an attacker doesn’t always need to find a complicated way into a business if they can simply sign in using credentials for an account that nobody remembers is still active.

Cloud services also mean business systems can often be accessed from outside the office, making it particularly important to know who has access and to remove it when it’s no longer required.

A clear employee leaver process can help reduce that risk.

Employee offboarding checklist: what should you check?

Every organisation uses different systems, so there isn’t a single checklist that will cover everything.

However, there are some key areas every business should consider whenever an employee leaves.

1. Block Microsoft 365 sign-in

If the employee uses Microsoft 365, preventing them from signing back into their account should be one of your first steps.

Microsoft includes blocking a former employee’s access as part of its own recommended process for removing former employees from Microsoft 365.

But simply removing a Microsoft 365 licence shouldn’t be treated as the entire offboarding process.

You also need to consider their email, files, devices, active sessions and any other applications they could still access.

Microsoft provides a detailed guide covering these steps.

2. Sign out of active sessions

Changing someone’s password might seem like the obvious solution, but think beyond the password itself.

The employee may already be signed in on a laptop, mobile phone, tablet or browser.

That means your Microsoft 365 offboarding process should include reviewing existing access and active sessions rather than assuming that changing a password has completed the job.

The same principle applies to other cloud applications used across your business.

Ask yourself: where could this person still be signed in?

It’s a simple question, but one that can uncover access you might otherwise have missed.

3. Keep the email your business still needs

Removing an employee’s access doesn’t necessarily mean deleting everything associated with their account.

There may be important emails your business needs to retain, or customers and suppliers may continue contacting that employee after they leave.

For Microsoft 365 users, one option is to convert the employee’s mailbox into a shared mailbox so appropriate colleagues can continue accessing relevant business communications while the former employee loses access.

This is an important distinction in any employee offboarding process.

You want to remove the person’s access without accidentally removing information the business still needs.

4. Hand over OneDrive and important files

The same applies to documents.

Employees can accumulate years of useful information in OneDrive, SharePoint and other cloud storage platforms.

Before removing an account, identify any files or folders the business needs and make sure responsibility is handed over to the appropriate colleague.

Consider project documents, customer information, proposals, spreadsheets, supplier details and anything else that could be important after the employee has gone.

Microsoft’s former employee guidance also covers providing another employee with access to a former employee’s OneDrive and Outlook data.

A good leaver checklist should therefore include both removing access and retaining business information.

5. Recover laptops, mobiles and other equipment

Digital access and physical equipment should be considered together.

Your checklist might include recovering:

  • Company laptops and desktop computers
  • Mobile phones and tablets
  • Headsets and other communications equipment
  • Security keys or authentication devices
  • Building access cards
  • Other company-owned equipment

It’s worth keeping a clear record of which equipment has been assigned to each employee.

For businesses without the time or internal resources to manage users, devices and systems themselves, Managed IT Support can help keep everything monitored and managed as employees join, change roles and leave.

6. Remove access to third-party and cloud applications

Microsoft 365 may only be the start.

Think about all the applications someone might gain access to during their time with your business.

Depending on their role, this could include your CRM, accounting software, HR platform, project management tools, supplier portals, website, social media accounts, cloud storage or industry-specific applications.

The longer someone has worked for the business, the easier it can be to forget exactly which platforms they have been given access to.

The NCSC recommends applying joiner, mover and leaver processes to cloud and Software-as-a-Service applications too.

Keeping a simple record of the systems each employee can access can make future offboarding much easier.

7. Change shared passwords

Ideally, employees should have their own individual accounts wherever possible.

However, many businesses still have shared accounts or passwords for certain systems.

If an employee knows the password for one of these accounts, disabling their individual Microsoft 365 account won’t remove that knowledge.

As part of your employee leaver checklist, identify any shared credentials the employee knew and change them where necessary.

It’s also a good opportunity to review whether those accounts really need to be shared.

Moving towards individual user accounts can make it much easier to control who has access and remove permissions when someone leaves.

8. Remove administrator permissions

Administrator accounts deserve particular attention because they can provide much greater control over systems, settings and business information.

Was the employee an administrator for Microsoft 365?

What about your CRM, website, phone system, network, finance software or other applications?

Admin permissions can sometimes be granted for a particular task and then forgotten.

Your offboarding process should therefore include checking for elevated or administrator privileges and removing them where they’re no longer required.

Don’t forget employees who change roles

Access management isn’t only important when someone leaves.

The same principle applies when an employee moves to another role or department.

Imagine someone moves from finance into a completely different part of the business.

They’re given access to all the systems they need for their new role, but nobody checks whether they still need everything they could access in finance.

Over time, employees can gradually accumulate permissions they no longer need.

This is why good access management focuses on joiners, movers and leavers.

When someone changes role, ask two questions:

What new access do they need?

And just as importantly:

What old access do they no longer need?

A role change is a useful trigger for a quick access review.

Make access reviews a regular habit

You don’t have to wait until somebody leaves to review access.

A simple habit is to check user permissions whenever someone joins, changes role or leaves, then carry out a wider review periodically.

Look for old user accounts, unnecessary administrator permissions, third-party applications that are no longer used, shared credentials and temporary accounts that should have been removed.

The goal isn’t to make accessing business systems unnecessarily difficult.

It’s simply to make sure the right people have access to the right systems — and people who no longer need access don’t still have it.

Regular reviews can also make employee offboarding much easier because you have a clearer picture of your systems, users and permissions before somebody leaves.

Removing access doesn’t mean losing your data

One concern businesses sometimes have is that removing an employee’s account could mean losing important emails, documents or customer information.

It doesn’t have to.

Mailboxes can be handed over or converted appropriately, files can be transferred to colleagues and business information can be retained while the former employee’s ability to access it is removed.

That’s why it’s worth having a repeatable employee offboarding checklist rather than simply deleting accounts as soon as someone leaves.

A good process protects access while maintaining business continuity.

Not sure if a former employee still has access?

When your business uses Microsoft 365 alongside multiple cloud applications, shared accounts, mobile devices and third-party systems, it isn’t always obvious where old access might still exist.

Yellowcom can help.

Our experts can review your current setup, help identify potential access gaps and make sure the right people have access to the right systems.

Whether someone has recently left, changed roles or you simply haven’t reviewed user access for a while, it’s a good opportunity to check that nothing has been missed.

Get in touch with Yellowcom today to arrange a free access review.

Tools Already Built In CTA
Yellowcom Logo - White Com
Looking for a Smarter Way to Stay Connected? We Help Businesses Cut Costs and Improve Communication.
Share this post:
Related Posts

When was the last time you chose a business without checking what other customers had to say about it? Whether...

Remote and hybrid working have changed what businesses need from their phone systems. Employees may be working from the office,...

Three days, three countries, plenty of challenges and one fantastic result for Team Yellowcom. The Gamma Ball Rally 2026 brought...