Skip to main content
ChecklistPeople and account security5 min read

Someone Is Leaving: A Cyber Security Offboarding Checklist

A staff offboarding checklist to help you close accounts, end active sessions, collect devices and hand over the work when someone leaves.

AI-assisted guidance from RightCyber. Sources checked on 16 September 2026.

BylineWritten by RightCyber · Published by RightCyber

PublicationPublished · Updated

Source statusReviewed 16 September 2026 · Review due 16 December 2026

At a glance

Agree when access ends, check each system and hand over the work. Keep a record of what’s been closed and who is handling anything unfinished.

On this pageArticle contents

Share this article

LinkedInEmail

Suppose a colleague hands back their laptop on Friday. On Monday, their account still owns the customer spreadsheet, their phone can open work email and nobody knows who now controls the company’s social media account.

It’s a useful way to test your leaving process. You might have collected every piece of equipment and still have plenty left to do. Someone needs to close the accounts, look after the work and take over the responsibilities that would otherwise fall through the gaps.

The NCSC’s guidance on using cloud services recommends a joiners, movers and leavers process covering both employees and external users. If you’re a small organisation, start with one person responsible for the process and a checklist they can work through with the manager and IT provider.

Agree the handover and the access deadline

Before a planned departure, the manager, HR contact and IT provider should agree exactly when access ends. “Remove them on Friday” leaves too much room for interpretation. If someone finishes at lunchtime, their account shouldn’t stay active until somebody remembers after the weekend.

Write down:

  • the person’s name, work accounts and last authorised working time
  • the manager who approves the handover
  • the IT contact responsible for removing access
  • the systems, equipment and shared responsibilities to check
  • an owner and deadline for anything that can’t be completed straight away

For an unexpected or sensitive departure, agree the timing with the people responsible for HR and security. If you suspect account misuse, involve your incident responder and preserve the relevant evidence. Deleting an account too soon could also delete information needed for the investigation.

Look beyond the main email account

Start with the main work account, then compare the person’s responsibilities with your application list. Check email, file storage, the password manager, finance systems, customer records, remote access, website administration and social media.

Ask the manager about free trials, supplier portals and services bought on a company card. These are easy to overlook if IT didn’t set them up. Include guest accounts in customer or partner systems, and ask those organisations to confirm removal where you can’t do it yourself.

Single sign-on helps, but some applications may have separate accounts or another way to sign in. The NCSC recommends central identity management and automated account controls where possible. Where you can’t automate the process, review access regularly and remove it when it’s no longer needed.

For each system, ask: “How have we checked that this person can no longer get in?”

Block access and deal with existing sessions

Ask an authorised administrator to follow the provider’s current offboarding procedure. Record which accounts were disabled, which sessions were ended and any separate steps taken for email or connected applications.

For Microsoft 365, Microsoft documents password reset, signing out sessions and blocking sign-in as separate actions. Their effects aren’t always immediate. Clicking one button doesn’t necessarily close every application the person already has open.

Pay particular attention to administrator accounts, recovery methods and shared passwords the person could use. If a shared password or other secret is still needed, replace it and check the systems that depend on it. Keep passwords and recovery codes out of the offboarding ticket.

Ask IT to check for automated jobs that run under the departing person’s account. An integration may need a supported replacement identity. Set that up and test it so you can close the old account without breaking the job.

Preserve the work without preserving the person’s login

The organisation may still need information held in the account. Decide who takes over active work, files, calendars and customer contact before deleting accounts or removing licences.

Microsoft’s former-employee guidance separates blocking access from preserving mailbox contents, handing over OneDrive information and eventual account deletion. Retention and licensing details depend on the service and configuration, so check them before making changes.

Use approved delegation, ownership transfer or shared-mailbox features where appropriate. Don’t give the replacement colleague the former employee’s password. Limit access to retained information to people with an authorised business need, and follow your retention policy and any legal hold.

For example, a new account manager may need the active client folders. That doesn’t automatically mean they should be able to read every historic message.

Collect equipment and update recovery contacts

Record returned laptops, phones, security keys and removable storage. Check whether corporate data also exists on personally owned devices. The NCSC’s insider-risk guidance specifically highlights recovering official devices and closing accounts, including considering bring-your-own-device arrangements.

For personal devices, follow your agreed process for managing business data. Check what a remote removal action will erase before using it. A complete device wipe may affect personal information too.

Check whether the departing person’s phone number or email address is a recovery contact for a company service. Replace it with a contact the organisation controls. You don’t want a future password reset to depend on tracking down a former colleague.

Finish with a second check

Have the manager and IT contact review the completed record together. Spell out anything unfinished. “Supplier portal removal awaiting confirmation” gives them something to follow up. An unchecked box buried in an email chain is much easier to miss.

Before closing the record, check that access has ended, necessary work has been handed over and equipment is accounted for. Anything outstanding needs a named owner. Use the same process for contractors and adapt it for people changing roles.

If you find unexpected account activity, use the first-hour incident checklist and involve your IT provider. Keep the completed leaving record somewhere the manager and IT team can find it if a question comes up later.

Provenance

Sources reviewed

Reviewed 16 September 2026

Sources reviewed by RightCyber on 16 September 2026. A source’s classification describes where it came from; it is not a blanket claim about every source.

Disclaimer

RightCyber is independent and is not affiliated with or endorsed by the NCSC, Microsoft, or any source linked here. This article is general guidance, not legal, financial, or incident-response advice.

Clarifications

Frequently asked questions

Is collecting a departing employee’s laptop enough?
No. You also need to check cloud accounts, active sessions, remote access, personal devices used for work, shared passwords and recovery contacts. Record what you’ve disabled or handed over, and give any unfinished task a named owner.
Should I delete a former employee’s Microsoft 365 account immediately?
Block unauthorised access using the provider’s current procedure, then plan what information to keep and hand over before deleting the account. Deleting accounts or removing licences can affect access to retained data. Microsoft’s offboarding guidance treats these as separate decisions.
Does blocking sign-in immediately close every active session?
Don’t assume it does. Microsoft documents separate controls for resetting passwords, signing out sessions and blocking sign-in, and they can take different amounts of time to work. Ask your administrator to follow the current procedure and check the affected services afterwards.

Continue reading

Continue with a related article

Check how sign-ins, sessions and recovery settings work together to protect the accounts your team still uses.

Keep exploring

Browse the RightCyber Blog
  • People and account security

    Why MFA Isn't Enough on Its Own

    MFA still blocks a huge amount of password abuse, but phishable prompts and stolen sessions remain. Move important accounts towards passkeys or FIDO2, then review recovery, session controls, and monitoring.

  • Resilience and incident response

    What to Do in the First Hour of a Cyber Attack

    Put one person in charge, contain the incident without making evidence loss automatic, start trusted calls and a time-stamped record, stop suspicious payments, and assess each reporting duty separately.

  • People and account security

    How Cyber Attacks Often Start

    Many incidents begin with an ordinary request to click, reset, scan, or pay. Verify money movements, bank-detail changes, and account recovery through a separate trusted channel every time.