Local Business

The day an employee leaves: an IT offboarding checklist

A step-by-step IT offboarding checklist for small businesses — disable accounts the same day, revoke sessions and MFA, reclaim devices, transfer files, and rotate shared credentials — and why every hour of delay is a security risk.

August 28, 2026 7 min read offboardingsmall businesssecurityITMicrosoft 365

Someone gives notice, or is let go, and the calendar fills with the human parts: the handover meeting, the farewell lunch, the paperwork from HR. The IT side tends to get a mental note — “I’ll clean up their access next week” — and next week rarely comes. That gap is where most small-business offboarding goes wrong, because a former employee’s still-live accounts are not a tidy-up task. They are an open door.

The person may leave on perfectly good terms. That is not the point. The point is that their credentials, their saved passwords, their session tokens on a personal phone, and their access to your shared drives all keep working until someone deliberately switches them off. Accounts do not expire because a relationship ended. Someone has to close them, on purpose, on the day.

Here is the checklist we work through, and why the timing matters as much as the steps.

Do these the same day

The moment the departure is confirmed — ideally before the person has left the building or logged off for the last time — the following should happen together, not spread across a week:

  • Disable the primary account, do not delete it. In Microsoft 365 or Google Workspace, block sign-in first. Deleting immediately can destroy mail and files you still need; disabling stops access instantly while preserving the data for transfer. Deletion comes later, deliberately.
  • Revoke active sessions and sign the account out everywhere. Disabling the account does not always kick out a session that is already open on a laptop or phone. Force a sign-out of all sessions and revoke refresh tokens so a cached login on a personal device stops working.
  • Remove multi-factor methods tied to the person. Their authenticator app, their phone number, their security keys. If those stay registered, a re-enabled account or a password reset can still be approved from a device you no longer control.
  • Reset the password anyway. Belt and braces. If any process re-activates the account, it should not open with the password the person still remembers.

If you do nothing else on the first day, do these four. Everything below can follow over the next day or two without much risk. These four cannot.

Reclaim and secure the devices

  • Collect company hardware — laptop, phone, tablet, any hardware keys or USB drives. Log what came back and what is outstanding.
  • Wipe or reassign each device. A managed device can be remotely wiped or reset to a clean state and handed to the next person without a manual rebuild. If devices are not centrally managed, this is the day you feel the absence — you are trusting that the person removed nothing and left nothing behind. Central device management turns offboarding a laptop into a single action; we wrote about what that involves on our device management page.
  • Handle personal devices honestly. If the employee used a personal phone for email or Teams, removing the account should also remove the company data. This is far cleaner when access was set up through a managed profile in the first place, which is one of the quiet reasons to set it up that way before anyone leaves.

Transfer the work before you delete anything

Access revoked is not the same as data recovered. Before the account is finally deleted:

  • Convert or delegate the mailbox. Turn it into a shared mailbox, or grant a manager access, so client threads and in-flight conversations are not lost. Set an auto-reply or forward if outside contacts still write to that address.
  • Reassign file ownership. Files sitting only in the person’s personal OneDrive or Drive can vanish when the account is deleted. Move ownership of anything business-critical to a manager or a shared location first.
  • Capture anything device-local. Notes, exports, or working files saved to the laptop rather than the cloud need to come off before the wipe.

Only once the mailbox and files are secured should you schedule the account for actual deletion — and even then, keep it disabled for a defined window rather than deleting in haste.

Rotate the shared secrets

This is the step almost everyone skips, and it is the one that quietly matters most.

  • Rotate any shared credentials the person knew. The Wi-Fi password, the shared admin login for the accounting tool, the social media account, the domain registrar, the “everyone uses this one” logins that never should have existed. Changing an employee’s own password does nothing about the shared ones they also had.
  • Remove them from every third-party tool. Your business runs on more services than live in Microsoft 365 or Google. Payroll, the CRM, the design tools, the code repository, the payment processor, the file-sharing links. Each has its own user list, and each keeps the person’s access until you remove it there specifically. Keep a written inventory of these so the list is not reconstructed from memory under pressure.
  • Check for personal recovery paths. Some tools were signed up with a personal email or phone as the recovery contact. Reset those to a company-controlled address so account recovery cannot route back to the person who left.

Write it down

Record what you disabled, what devices came back, what was transferred, and what still needs finishing. A short offboarding record does two things: it proves the work was done if anyone asks later, and it becomes the template for the next departure so nothing depends on one person remembering the whole sequence. When you evaluate any IT provider, ask how their offboarding process works and whether it is written down — it is one of the questions worth asking before you sign.

Why the delay is the real risk

A former employee with live access is a security exposure whether or not anyone ever misuses it. The accounts show up in no report as a problem until something happens through one of them, and by then the question is not “did we mean to leave that open” but “who used it, and for how long.” Same-day offboarding is not about distrust. It is basic hygiene, the same way you would collect a physical key on the last day rather than a week later.

If this checklist felt like a stretch to run reliably every time — if offboarding currently depends on one busy person remembering every tool and every device — that is usually a sign the informal approach has been outgrown. We wrote about the other signs of that, and the fix is rarely more effort; it is making offboarding a defined, repeatable process instead of a scramble.

If you would like offboarding handled as routine — accounts closed the same day, devices wiped, secrets rotated, and a record kept each time — send us two paragraphs about how departures work at your business today, and we will reply in writing within one business day.

— Newsletter

Get the writing by email.

An occasional note from the team — case studies, new free tools, engineering essays. Never daily.

Three fields, no tracking. Privacy policy.