Skip to main content
Dig IT Solutions logo

Cyber Security

Employee offboarding IT security checklist: closing the doors leavers leave open

Why former employees are a hidden security risk for UK small businesses, and a step-by-step IT offboarding checklist for accounts, devices and shared passwords.

By Dig IT SolutionsUpdated 8 September 20266 min read

Short answer

When someone leaves, disable their Microsoft 365 and every other account on their last day, revoke sessions and MFA, recover devices, wipe work data from personal phones, change any shared passwords they knew, redirect their mailbox and transfer file ownership. Most businesses miss two or three of these, which is why leavers are a common source of breaches.

When a member of staff leaves, most businesses collect the laptop, disable the email and consider the matter closed. Then an audit six months later finds them still able to log in to the CRM, the accounts package and the shared Wi-Fi, or a customer receives an email from a mailbox nobody knew was still forwarding. Former employees leave behind more risk than businesses realise, almost always by accident, and the fix is a checklist rather than a policy statement.

This article explains where the risk sits and gives you the checklist we use.

Where leavers leave risk

Accounts that stay active. A person in a 30-person firm typically has logins to ten or more systems: Microsoft 365, the line-of-business application, accounts software, the CRM, the phone system, remote access, the website, social media, the door entry and alarm, the bank's online portal, various SaaS tools. Disabling Microsoft 365 covers one. The rest are only disabled if someone has the list. A dormant account with a password that also appeared in a consumer breach is exactly what automated attacks look for, because nobody notices when it is used.

Accumulated permissions. People collect access over years: temporary admin rights for a project, a finance folder from a previous role, a shared mailbox they covered once. The leaver's own account may go, but the shared accounts and group memberships they touched stay as they were.

Shared passwords they know. The Wi-Fi, the router, the alarm code, the "office" Microsoft account, the supplier portal login on a sticky note. If these are not changed, the person's access has not really ended.

Personal devices. Company email cached on a personal phone, files synced to a personal laptop, a VPN profile on a home PC. Without mobile application management, the business has no way to remove them. See BYOD security risks.

Mailbox and forwarding. Rules the person created, auto-forwarding to a personal address, customers still writing to them. A mailbox left active and unwatched is both a security and a customer-service problem.

Knowledge that was never written down. Who the software supplier is, where the licence keys are, how the month-end export works, what the NAS password is. Operationally painful rather than a security breach, but it is the same root cause: no process.

Third-party relationships tied to the person. Domain registrations, SaaS subscriptions, cloud accounts and even the Google Business profile are routinely found registered to an individual's email rather than a company account. When they leave, the business can lose control of its own assets.

Compliance. Under UK GDPR the ICO expects access to personal data to be limited to those who need it, and enforcement action has followed cases where former staff retained access. Cyber Essentials asks directly how quickly leaver accounts are removed. Insurers ask too.

Most of this is accidental. The deliberate insider, copying the client database on the way out, is rarer but real, and the same controls catch both.

The offboarding checklist

Use this as the template for your own list. The right time to start is the day the leaving date is known, not the last day.

Before the last day

  • Manager or HR submits a leaver notification with the leaving date and time. (Our client portal has a leaver form for exactly this purpose.)
  • Build the person's system list: pull group memberships and app assignments from Microsoft 365, check every other system they were set up on, and ask their manager what else they used.
  • Identify shared accounts, passwords and codes they had access to.
  • Identify what they own: files in OneDrive, Teams and SharePoint sites, mailbox rules, scheduled reports, subscriptions, domain and vendor accounts.
  • Agree the handover: who takes over the mailbox, who inherits the files, who becomes the contact for their suppliers and customers.
  • For sensitive roles or contested departures, plan to remove access at the moment of notification rather than at the close of their last day.

On the last day

  • Disable the Microsoft 365 account (do not delete yet), revoke all sign-in sessions and refresh tokens, and remove registered MFA methods and devices.
  • Disable or remove the account in every other system on the list, including remote access, VPN, the phone system, the CRM, accounts software, industry applications, website admin, social media and door entry.
  • Reset any shared passwords and codes the person knew: Wi-Fi, router and firewall, alarm, shared mailboxes, supplier portals. Move shared credentials into a password manager if they are not already there.
  • Collect company devices: laptop, phone, tokens, keys, access cards. Record serial numbers against the leaver.
  • Wipe work data from personal devices through Intune app protection or MDM, and confirm the wipe completed.
  • Convert the mailbox to a shared mailbox, grant the manager access, remove any user-created forwarding and inbox rules, set an auto-reply with the new contact and a forwarding period.
  • Transfer ownership of OneDrive files, SharePoint sites, Teams, Planner boards and any Power Automate flows.
  • Remove the person from distribution lists, Teams channels and shared calendars.
  • Transfer ownership of any external accounts registered to them (domains, SaaS, cloud consoles, Google Business profile) to a company-owned account.

Within the following week

  • Review the collected devices: wipe and re-image before reissue, or securely erase and record disposal.
  • Review access and administrator rights on any shared accounts or systems the person administered.
  • Check sign-in logs for the disabled accounts to confirm no successful use after the leaving date.
  • Cancel or reassign licences and subscriptions.
  • Update documentation: system list, supplier contacts, procedures they owned.
  • Record what was done, by whom and when, and file it with the HR record. This is the evidence for audits, insurers and any later dispute.

After the retention period

  • Delete the disabled accounts and the shared mailbox in line with your data retention policy.
  • Remove them from the password manager and any remaining reference lists.

Make it routine, not heroic

A checklist run from memory is a checklist that gets skipped when the office is busy. Three things make offboarding reliable.

A single trigger. HR or the manager submits one form, and everything else follows from it. If IT only finds out because the leaver's laptop appears on a desk, the process has already failed.

Named accounts and a system inventory. If you do not know every system a person could log in to, you cannot close them all. Keeping an inventory is part of the first Cyber Essentials control, and it is what onboarding and offboarding as a managed service exists to maintain.

Periodic access reviews. Even with a good process, run a quarterly check for accounts with no sign-ins in 60 days, administrator roles, and external accounts. Audits regularly find people who left years earlier, and the review is how you catch what the process missed. Our self-assessment guide covers the access review in full.

Onboarding is the other half

Most offboarding problems are created at onboarding: access granted "the same as Dave" with no record, shared passwords handed over verbally, subscriptions registered to whoever happened to sign up. Starting people properly, with named accounts, least-privilege access requested by a manager, MFA enrolled and a written record, is what makes leaving people properly possible. The two processes should be one document.

What to do next

If you cannot list every system a recent leaver had access to, or cannot say when shared passwords were last changed, an access review will tell you what was left open. Our IT health check includes a review of active accounts, administrator rights and leaver handling across Microsoft 365 and your other systems.

Frequently asked questions

What is the biggest security risk from a former employee?
Retained access. An account that was never disabled, a shared password that never changed, a VPN certificate on a personal laptop, or company email still cached on a personal phone. Most of the risk is accidental rather than malicious, but a dormant account is exactly what an attacker with a leaked password looks for, because nobody notices when it is used.
How quickly should accounts be disabled when someone leaves?
On the last working day, before they walk out, and for sensitive roles or difficult departures at the moment they are told. Disable rather than delete on day one so email and files can be transferred, then delete after your retention period. A same-day standard is also what Cyber Essentials assessors and cyber insurers expect to see.
What should happen to a leaver's mailbox?
Convert it to a shared mailbox in Microsoft 365 (which keeps the content without a licence), give the manager access, set an auto-reply naming the new contact, and forward for a defined period. Remove any inbox rules and forwarding the user set up. Decide a retention date in line with your data policy and delete when it arrives.
Are former employees really a common cause of breaches?
They contribute to a meaningful share of incidents, mostly indirectly. Dormant accounts get used with leaked passwords, ex-staff keep client lists on personal devices, and audits regularly find people who left years ago still active in a system or two. The ICO has fined organisations where former staff retained access to personal data.
What is employee offboarding from an IT point of view?
It is the structured removal of a person's access and the recovery of the business's assets and knowledge: disabling accounts across every system, revoking sessions and tokens, collecting devices, wiping work data from personal devices, changing shared credentials, transferring ownership of files and processes, and documenting what was done. It is the reverse of onboarding and should be just as formal.
Can our IT provider manage offboarding for us?
Yes, and it works best when the provider has a leaver form that HR or the manager submits with the leaving date, so the technical steps run on schedule. The business still owns the decision and the list of systems, the provider executes accounts, devices and data. Ask for a completion record for each leaver so you can evidence it later.

Next step

Not sure how exposed you are?

An IT health check reviews your security, backups, Microsoft 365 and network and gives you a prioritised list, whether or not you work with us afterwards.

WhatsApp us