What Should a Microsoft 365 Offboarding Checklist Include?

IT administrator reviewing a Microsoft 365 employee offboarding checklist at a laptop

What should a Microsoft 365 offboarding checklist include? It should cover more than disabling a sign-in. A reliable process identifies who needs access, preserves business information, transfers ownership, handles devices and licenses, and verifies that the former employee can no longer reach company resources.

Talk with an IT professional about Microsoft 365 offboarding

Why does Microsoft 365 offboarding need a repeatable process?

An employee departure touches accounts, email, files, meetings, shared workspaces, authentication methods, and sometimes personal or company-managed devices. If different people handle each piece without a shared plan, access may remain active longer than intended, or useful business information may be lost when an account or license is removed.

Offboarding is also not one identical sequence for every departure. A planned retirement, a same-day termination, a contractor engagement ending, and an internal role change carry different timing and access needs. Your checklist should specify the decision-maker, the effective time, the resources to transfer, and the person responsible for confirming each action.

An article on Microsoft 365 offboarding describes it as a lifecycle-governance issue rather than only an administrator checklist. That is a useful distinction: technology steps should follow documented decisions about ownership, retention, and access, not replace them. Read the discussion of Microsoft 365 offboarding governance.

What should you decide before disabling the account?

Before the effective departure time, confirm the facts that determine what happens next. HR or the employee’s manager should provide the approved date and time, whether access must end immediately, who becomes the business owner for work in progress, and whether any records need to be retained. IT can then perform the technical steps against an authorized request.

  • Confirm the identity and account. Match the request to the correct user, primary sign-in, aliases, and any additional accounts. Avoid relying on a display name alone.
  • Set the timing and approval. Record who approved the change and when it should take effect. For an urgent departure, arrange a coordinated handoff so the account is secured at the agreed time.
  • List business responsibilities. Identify active projects, scheduled meetings, customer conversations, shared mailboxes, owned groups or teams, and files that others still need.
  • Assign an owner for each handoff. Name a manager or colleague to receive relevant work. Do not assume that transferring access to a supervisor is appropriate for every mailbox or document.
  • Check the account’s dependencies. Ask whether the account is used for service alerts, recurring reports, application sign-ins, or other business processes. Replace individual-user dependencies with approved shared or service arrangements where appropriate.

Keep the request and the completion record together. A short record of the approver, scope, time, and person completing each action makes the process easier to repeat and review.

Which Microsoft 365 access should the checklist address?

Start with the user’s ability to authenticate, then review the related access paths. Disabling or blocking sign-in is a key containment step, but it should not be treated as proof that every session, credential, or connected resource has been addressed. The exact controls available depend on your tenant configuration and identity setup.

  1. Block new sign-ins at the departure time. Use your organization’s approved identity-administration process. If the departure is sensitive or urgent, coordinate the timing with the decision-maker rather than waiting for routine account cleanup.
  2. Review active sessions and credentials. Revoke active sessions or refresh tokens where your configuration supports it. Reset credentials when warranted, and review authentication methods such as registered phones or app-based methods so the former employee cannot use them to regain access.
  3. Remove access that is no longer needed. Review group memberships, administrator roles, application permissions, shared mailbox access, and access to shared files or sites. Remove the departing user’s access and update ownership as needed.
  4. Check connected devices. Identify company-managed computers and mobile devices associated with the account. Apply the organization’s lock, retire, wipe, or recovery procedure based on ownership and business policy. Do not wipe a personal device without the required authorization and process.
  5. Review other sign-in routes. Consider VPN, remote access, business applications, and any third-party tools that use the same identity or credentials. Microsoft 365 offboarding does not automatically settle access to every external system.

If employee-owned devices are in scope, distinguish company data and work access from personal content. The guidance in this BYOD support guide can help frame device ownership and access questions. Organizations using centralized device controls can also review what Microsoft Intune does when planning device enrollment and management.

IT administrator working through a secure employee offboarding process

How should you handle email, files, and collaboration spaces?

Preserve information according to business needs and applicable retention instructions before removing access or changing licenses. Avoid deleting the account as the first step. Deletion and license changes can affect access to services or information, and the right sequence depends on the tenant setup, licensing, retention settings, and the organization’s requirements.

Resource Offboarding action What to verify
Email and calendar Decide whether a manager needs a temporary handoff, mailbox access, or a customer-facing reply plan. Confirm the authorized recipient, duration, forwarding or response approach, and any retention requirements.
OneDrive and work files Identify business files that need a new owner or approved storage location before account cleanup. Check that the assigned colleague can reach the required files and that access is not broader than intended.
Teams, groups, and shared sites Remove the departing user and assign owners or moderators where needed. Confirm essential workspaces remain managed and project participants retain appropriate access.
Licenses and account lifecycle Keep or remove licenses only after required access, preservation, and handoff decisions are complete. Verify the effect of the planned change in your tenant, including any services that depend on the account.

For email, document whether the mailbox should be monitored, delegated, or given an automatic response, and set an end date for any temporary arrangement. Forwarding every message indefinitely is rarely a complete handoff: it can obscure who owns customer requests and may expose information to someone who does not need it. If the person handled customer-facing correspondence, assign a colleague to review open threads and update contacts through the normal business process.

For files, ask managers to name the work that must continue. Transfer or share only what the new owner needs. Review the result from that person’s account, rather than assuming a setting change worked. For SharePoint sites, check that each important site still has an appropriate owner and that project access remains intentional. Do the same for groups and Teams where the departing person held an owner role.

Outlook calendars may include recurring meetings, room bookings, or appointments that need a new organizer. Identify important recurring events and decide who will recreate or manage them. For relevant users, review Outlook support and administration alongside the mailbox handoff.

When should you remove Microsoft 365 licenses?

Do not make license removal an automatic first action. First check whether the mailbox, files, or other services still need to be available and whether the organization’s retention or preservation instructions apply. A license decision may affect how a resource can be accessed or maintained, and the details depend on the services and configuration in use.

Use a deliberate sequence: record the retention and handoff decision; complete the approved transfer or access arrangement; confirm the resource is available to its new owner; then review which licenses are still required. Your administrator should verify the expected outcome in the specific tenant before making a change. For a broader review of plan assignments and services, consult Microsoft 365 licensing and servicing information.

Keep an audit note of what was retained, what was transferred, and who approved the license change. If you are not sure whether a business record must be retained, pause the deletion or license change and ask the appropriate internal owner. Technical convenience is not a substitute for a retention decision.

What should you do with company devices and other accounts?

Record every device issued to the employee, including laptops, phones, tablets, security keys, and accessories that contain or enable access to company resources. Assign someone to recover each item and track its return. If a device is missing, use the organization’s lost-device response rather than treating it as a routine return.

When equipment comes back, follow your approved process to secure it, remove the prior user’s access, and prepare it for reassignment or storage. For a personal device, focus on revoking work access through supported controls and respect the boundaries set by your BYOD policy. A company-owned device and an employee-owned device should not be handled as if they were the same.

Also close the loop beyond Microsoft 365. Use an inventory of business applications and access methods to check accounting, customer-management, file-sharing, remote-access, and industry-specific systems. Remove the user or transfer ownership in each system that the employee used. If a shared credential was exposed to the employee, rotate it under the relevant procedure.

How can you verify that offboarding is complete?

Verification turns a list of intended actions into a completed process. Have a second authorized person or the request owner review the high-risk items, especially for urgent departures or accounts with elevated permissions.

  • Confirm the correct account is blocked from signing in at the approved time.
  • Confirm sessions, authentication methods, roles, group membership, and application access were addressed as planned.
  • Check that the manager or successor can access the approved mailbox, files, sites, and active work.
  • Confirm device recovery or the applicable lost-device response is recorded.
  • Verify that temporary access, forwarding, or mailbox delegation has an owner and a review or end date.
  • Confirm license changes and any account-retention steps match the approved plan.
  • Record exceptions, unresolved dependencies, the person responsible, and the due date for follow-up.

One practical approach is to use a ticket or departure record with a checkbox for each action and a field for evidence or notes. The record should not contain unnecessary sensitive content. Its purpose is to show what was done, by whom, when, and what remains open.

Review your Microsoft 365 offboarding process with an IT professional

How should the checklist change for different departures?

Planned departure: Coordinate the last working time, work handoff, device return, and future mailbox plan in advance. Give the manager time to identify active projects and assign owners before access ends.

Immediate or involuntary departure: Coordinate the access cutoff with the authorized decision-maker. Prepare the account and device actions ahead of the effective time, keep the response limited to people who need to know, and promptly review connected systems. Do not delay containment while waiting to complete low-priority housekeeping.

Contractor or temporary worker: Confirm the end date and sponsor, identify resources shared with the engagement, and check whether other contractors depend on the same access. End only the appropriate identity and permissions, then transfer any work the business has agreed to retain.

Internal role change: This may call for access adjustment rather than full offboarding. Remove permissions tied to the old role, grant only those approved for the new role, and update ownership of active work. Keeping the same access simply because the account remains active can leave unnecessary privileges in place.

In every case, the manager or process owner should decide the business handoff, while authorized administrators carry out the technical changes. If your team needs broader help with account administration and day-to-day support, learn about Microsoft 365 management and support and the company’s managed IT solutions.

Call (866) 365-7798 to discuss your offboarding process

Frequently asked questions

Is disabling sign-in enough to offboard a Microsoft 365 user?

No. It addresses an important access route, but a complete process also reviews sessions, authentication methods, permissions, connected devices, business applications, data handoff, and records that need to remain available.

Should I delete the employee’s account right away?

Usually, account deletion should not be the first step. Confirm retention, mailbox and file ownership, access needs, and license effects first. Follow your organization’s approved policy and verify what a change will do in your tenant.

Can a manager keep access to a former employee’s mailbox?

That depends on business need and internal policy. Name an authorized recipient, decide whether access is temporary, and set a review or end date. Consider a clear customer-response plan instead of indefinite forwarding.

How long should the offboarding process take?

There is no single timeline for every departure. Access changes should occur at the authorized effective time, while data handoffs, device recovery, and license decisions may have separate owners and deadlines. Record exceptions and track them until resolved.

Ready to make employee offboarding more consistent?

A good Microsoft 365 offboarding checklist connects timely access changes with careful decisions about business information, ownership, devices, licenses, and verification. Assign an owner to every step, adapt the sequence to the departure, and keep a concise completion record so the next handoff is clear.

About the Author: Josh Holcombe is a forward-thinking IT leader and the driving force behind IGTech365, where he helps organizations modernize their technology, strengthen cybersecurity, and unlock operational efficiency. With a reputation for delivering innovative, business-focused IT solutions, Josh specializes in guiding companies through digital transformation in a way that is both practical and results-driven. Known for his ability to align technology with real-world business outcomes, Josh has worked with organizations across industries to streamline workflows, improve system reliability, and reduce risk.

To top