Employee Offboarding: The Access Your Leavers Still Have

When a member of staff resigns, HR has a checklist. Return the laptop, hand in the access card, sign the exit paperwork. IT usually gets a single line on that list: disable the account. In practice that often means one thing gets done, the mailbox is switched off, and everything else the person could reach is left exactly as it was.
That is the leaver problem. It is not dramatic and it rarely shows up in an audit, but it is one of the most common ways a business quietly loses control of who can get into its systems.
Why "we disabled the account" is not enough
A modern employee does not have one account. They have a Microsoft 365 identity, sign-ins to a dozen cloud tools, a phone with company email on it, saved passwords in a browser, membership of shared mailboxes and Teams channels, and often a personal login to a supplier portal or two that nobody in IT has ever heard of.
Disabling the main account handles the first item on that list. Single sign-on may cover some of the rest, but plenty will not be. Consider what typically survives a standard offboarding:
- Active sessions and tokens. Blocking sign-in stops new logins. It does not always end sessions that are already open on a laptop or phone. Unless sessions are actively revoked in Microsoft Entra, a device that is already signed in can keep working for hours.
- Direct logins to SaaS tools. Accounting software, the CRM, the design tool the marketing team signed up for with a company card. If any of these use their own username and password rather than the company identity, they are untouched.
- Shared credentials. The social media logins, the Wi-Fi password, the admin account for the website, the shared spreadsheet of "useful passwords". If the leaver knew them, they still know them.
- Mobile devices. A personal phone with company email configured will keep syncing until the device is removed or wiped through mobile device management.
- Mail forwarding rules. A forwarding rule set up months earlier, deliberately or through a compromised account, keeps sending copies of email out of the business after the person has gone.
- Third-party and supplier portals. Banking profiles, courier accounts, regulator portals and vendor systems where the employee was the named contact. These sit outside your tenant entirely and are easy to forget. This is the same blind spot we cover in managing third-party vendor risk, just seen from the other side.
None of this requires a malicious leaver. Most former staff never try to log back in. The problem is that the door stays open, and if that person's credentials are ever exposed elsewhere, an attacker inherits the access instead.
The order matters
A good offboarding process is less about the number of steps than the sequence. Access has to be closed before data is handled, otherwise you are tidying the house with the front door open.
Step one: close access
- Block sign-in on the identity and revoke all active sessions and refresh tokens at the same time. Doing one without the other leaves a gap.
- Reset the password anyway, so any cached or saved copy becomes useless.
- Remove or wipe the company profile from mobile devices through your device management tool.
- Remove the user from groups, shared mailboxes, distribution lists and Teams.
- Rotate any shared credentials the person had access to. If you do not know which ones, that is a finding in itself.
Step two: preserve what the business needs
- Convert the mailbox to a shared mailbox or apply a litigation or retention hold before removing the licence, so email is not lost when the account is cleaned up.
- Transfer ownership of OneDrive files, SharePoint sites, Teams and any documents only that person owned. Set an expiry on the access you grant to the manager so it does not become permanent by accident.
- Reassign any automations, flows or scheduled reports that ran under their identity. These fail silently when the account goes.
- Update the named contact on supplier, banking and regulator accounts.
Step three: check and record
- Check for mail forwarding rules and remove them.
- Review the account's recent sign-in logs to confirm nothing unusual happened before the exit.
- Record what was done and when. Under POPIA and GDPR you may need to show that access to personal data was withdrawn promptly.
Contractors and role changes count too
Offboarding is not only for resignations. A contractor whose project ended six months ago, last summer's intern, and the finance manager who moved to operations but kept every old permission all represent the same risk. Access accumulates and rarely gets taken away on its own.
A quarterly review of who has access to what, starting with anything privileged, catches most of this. Pairing that review with phishing-resistant authentication, as discussed in our piece on MFA fatigue attacks, means that even lingering accounts are far harder for an outsider to use.
Making it repeatable
The businesses that get this right do not rely on someone remembering. They have one offboarding checklist owned jointly by HR and IT, triggered when the notice period starts rather than on the last day, and reviewed after each leaver. Where the environment is managed by an MSSP, much of the identity and device work can be automated so that the same steps run every time, in the right order, with a record at the end. That is the kind of discipline a managed IT arrangement should give you as standard, and it is a core part of the identity and access controls that stop a leaver's account from becoming an attacker's way in.
Start with the last three people who left your business and ask a simple question: if they tried to log in to something today, what would still work? The answer is usually more than expected, and it is a useful place to begin.
Want this handled for you?
Talk to the F1 team about cybersecurity, AI and managed IT for your business.



