Suppose a colleague hands back their laptop on Friday. On Monday, their account still owns the customer spreadsheet, their phone can open work email and nobody knows who now controls the company’s social media account.
It’s a useful way to test your leaving process. You might have collected every piece of equipment and still have plenty left to do. Someone needs to close the accounts, look after the work and take over the responsibilities that would otherwise fall through the gaps.
The NCSC’s guidance on using cloud services recommends a joiners, movers and leavers process covering both employees and external users. If you’re a small organisation, start with one person responsible for the process and a checklist they can work through with the manager and IT provider.
Agree the handover and the access deadline
Before a planned departure, the manager, HR contact and IT provider should agree exactly when access ends. “Remove them on Friday” leaves too much room for interpretation. If someone finishes at lunchtime, their account shouldn’t stay active until somebody remembers after the weekend.
Write down:
- the person’s name, work accounts and last authorised working time
- the manager who approves the handover
- the IT contact responsible for removing access
- the systems, equipment and shared responsibilities to check
- an owner and deadline for anything that can’t be completed straight away
For an unexpected or sensitive departure, agree the timing with the people responsible for HR and security. If you suspect account misuse, involve your incident responder and preserve the relevant evidence. Deleting an account too soon could also delete information needed for the investigation.
Look beyond the main email account
Start with the main work account, then compare the person’s responsibilities with your application list. Check email, file storage, the password manager, finance systems, customer records, remote access, website administration and social media.
Ask the manager about free trials, supplier portals and services bought on a company card. These are easy to overlook if IT didn’t set them up. Include guest accounts in customer or partner systems, and ask those organisations to confirm removal where you can’t do it yourself.
Single sign-on helps, but some applications may have separate accounts or another way to sign in. The NCSC recommends central identity management and automated account controls where possible. Where you can’t automate the process, review access regularly and remove it when it’s no longer needed.
For each system, ask: “How have we checked that this person can no longer get in?”
Block access and deal with existing sessions
Ask an authorised administrator to follow the provider’s current offboarding procedure. Record which accounts were disabled, which sessions were ended and any separate steps taken for email or connected applications.
For Microsoft 365, Microsoft documents password reset, signing out sessions and blocking sign-in as separate actions. Their effects aren’t always immediate. Clicking one button doesn’t necessarily close every application the person already has open.
Pay particular attention to administrator accounts, recovery methods and shared passwords the person could use. If a shared password or other secret is still needed, replace it and check the systems that depend on it. Keep passwords and recovery codes out of the offboarding ticket.
Ask IT to check for automated jobs that run under the departing person’s account. An integration may need a supported replacement identity. Set that up and test it so you can close the old account without breaking the job.
Preserve the work without preserving the person’s login
The organisation may still need information held in the account. Decide who takes over active work, files, calendars and customer contact before deleting accounts or removing licences.
Microsoft’s former-employee guidance separates blocking access from preserving mailbox contents, handing over OneDrive information and eventual account deletion. Retention and licensing details depend on the service and configuration, so check them before making changes.
Use approved delegation, ownership transfer or shared-mailbox features where appropriate. Don’t give the replacement colleague the former employee’s password. Limit access to retained information to people with an authorised business need, and follow your retention policy and any legal hold.
For example, a new account manager may need the active client folders. That doesn’t automatically mean they should be able to read every historic message.
Collect equipment and update recovery contacts
Record returned laptops, phones, security keys and removable storage. Check whether corporate data also exists on personally owned devices. The NCSC’s insider-risk guidance specifically highlights recovering official devices and closing accounts, including considering bring-your-own-device arrangements.
For personal devices, follow your agreed process for managing business data. Check what a remote removal action will erase before using it. A complete device wipe may affect personal information too.
Check whether the departing person’s phone number or email address is a recovery contact for a company service. Replace it with a contact the organisation controls. You don’t want a future password reset to depend on tracking down a former colleague.
Finish with a second check
Have the manager and IT contact review the completed record together. Spell out anything unfinished. “Supplier portal removal awaiting confirmation” gives them something to follow up. An unchecked box buried in an email chain is much easier to miss.
Before closing the record, check that access has ended, necessary work has been handed over and equipment is accounted for. Anything outstanding needs a named owner. Use the same process for contractors and adapt it for people changing roles.
If you find unexpected account activity, use the first-hour incident checklist and involve your IT provider. Keep the completed leaving record somewhere the manager and IT team can find it if a question comes up later.