← All articles

Employee Offboarding IT Checklist: Contain Access, Preserve Evidence

Contain access before deletion. A pragmatic IT offboarding checklist with Microsoft 365 and Google Workspace steps, audit-focused verification, and...

IT administrator documenting employee access removal

On employee departure, immediately block account access and preserve business data before deleting the identity. This sequence matters because premature deletion destroys evidence and orphans files, while delayed containment leaves credentials active for an employee who no longer needs them. The Canadian Centre for Cyber Security treats termination as a coordinated logical-access and physical-security event, not a single account-deletion task. Run the prioritized checklist below across SaaS, privileged accounts, devices, badges and shared secrets before closing the file.


TL;DR:

  • Blocking account access and preserving business data must occur immediately after HR confirms departure to prevent evidence loss and orphaned files.
  • Removing accounts from connected systems, rotating shared credentials, and transferring ownership occur after containment, with delays risking ongoing access or data loss.
  • Privileged accounts and service credentials require separate, thorough rotation and removal, as they often remain accessible even when personal logins are disabled.
  • Automated workflows handle routine offboarding steps, but manual audits are necessary to identify outside provisioning or overlooked accounts.
  • Documenting every action with timestamps and evidence ensures offboarding remains auditable and minimizes the risk of missed access points or data retention issues.

247techify
Strengthen Your Offboarding Controls
247Techify helps Canadian businesses secure IT systems, support compliance, and respond rapidly when access changes create risk.
Explore secure IT services

Table of Contents

The prioritized IT offboarding checklist

A departure triggers a sequence, not a single action. Each step below has an owner, a piece of evidence to capture and a reason it cannot be skipped.

  1. Immediate containment. Disable sign-in, reset the password and revoke active sessions and MFA devices the moment HR confirms the departure date. For involuntary terminations or suspected compromise, escalate to emergency containment and cut access before the conversation ends.
  2. Preserve business data. Reassign or apply holds to the mailbox, OneDrive and shared drive content before anyone deletes the account. Ownership transfer has to happen first, because once the identity is gone, recovery windows start running out.
  3. Deprovision connected systems. Remove the account from SSO-linked SaaS apps, VPN, RDP, SSH and any database logins tied to the person directly rather than through a shared role.
  4. Rotate shared credentials. Change passwords on any shared accounts the employee could have accessed, remove them from password vault entries, and reassign ownership of service accounts they managed.
  5. Recover physical assets. Collect laptops, phones, access badges and security tokens, and log the condition of each item along with who received it and when.
  6. Manage licenses and billing. Hold the license in place until data migration and audits are complete. Deleting too early can break forwarding rules or cut off a legal hold mid-review.
  7. Run final verification. Export access logs, confirm no active sessions remain, and record the owner, timestamp and administrator for every completed step.

Steps that commonly get missed:

  • Vendor portal logins that live outside the identity provider.
  • Personal devices enrolled under BYOD policies that still sync corporate mail.
  • Service accounts the departing employee set up without documenting ownership.
  • Group memberships that grant access indirectly, bypassing individual permission reviews.

Pro Tip: Build the checklist into the HR termination ticket itself so IT receives the trigger the moment a date is set, not the morning the employee walks out.

How Microsoft 365 and Entra handle containment and preservation

Microsoft’s documentation on revoking access lays out the mechanics for Entra ID environments: disable the account, revoke refresh tokens, disable registered devices and block sign-in. These are separate actions, and skipping one leaves a gap an active session can slip through.

  • Reset the password and sign the user out of all sessions as a first move, since this is faster than waiting for a token to expire.
  • Preserve OneDrive and mailbox content before removing the license; Microsoft’s guidance on removing former employees notes that deleted-user OneDrive data is retained for a period after deletion, and license removal can disable mail forwarding.
  • Convert the mailbox to shared or reassign it, and document whether forwarding is kept or cut.
  • Use Entra Lifecycle Workflows for routine provisioning changes, but flag apps that provision outside Entra for manual review.

Blocking sign-in can take some time to propagate fully across sessions, according to Microsoft’s reset and sign-out guidance. Test high-risk apps directly rather than assuming the block has taken effect everywhere at once.

Handling Google Workspace offboarding: suspension and ownership transfer

Google Workspace environments follow the same contain-then-preserve logic with different mechanics. Suspend the user or block sign-in immediately, then work through ownership before anything gets deleted.

  • Suspend the account rather than deleting it outright, which locks access while preserving the data trail.
  • Transfer ownership of My Drive files and any shared drives where the departing employee was the sole owner.
  • Remove OAuth app approvals and any delegated mailbox access granted to or from the account.
  • Check group memberships and shared drive permissions for assets that would otherwise become orphaned.
  • Document the retention decision in writing and hold off on deletion until ownership and legal holds are resolved.

Closing the gaps in privileged access and shared secrets

Privileged accounts and shared secrets are where most offboarding failures happen, because a disabled personal login does not touch the service accounts or shared credentials that person could still reach. Guidance on managing administrative privileges treats this as a distinct risk category from standard user offboarding.

  1. List every privileged role, administrative group and service account the departing employee had access to, not just their primary login.
  2. Rotate API keys and service credentials tied to systems they administered or deployed.
  3. Remove them from password vault entries and assign a new, named owner to every shared credential they could see.
  4. Confirm admins use individual administrator accounts rather than a shared login, and preserve logs of privileged actions for the audit trail.

Pro Tip: Treat every shared credential the departing employee could have viewed as compromised the moment the termination date is set, and rotate it regardless of how the departure played out.

Where automation helps and where manual checks still matter

Lifecycle workflows handle the routine work well: license removal, group changes and standard provisioning can run on a schedule without a human clicking through each step. What automation does not reliably catch is the app that provisions outside the identity provider entirely, so a manual audit still has to close that gap.

  • Log the owner, action, timestamp and evidence link for every item on the checklist, not just the ones that failed.
  • Keep the identity disabled, not deleted, until the final verification pass confirms nothing was missed.
  • Maintain a separate emergency containment playbook for suspected compromise, where steps happen in parallel instead of in sequence.
  • Treat any exception, like an app without a deprovisioning hook, as a ticket of its own rather than a footnote.

What IT teams get wrong about offboarding timing

The most common mistake is running deprovisioning and data preservation as one step. Teams that disable an account and delete it in the same session routinely lose files that a thirty-second ownership reassignment would have saved. Token propagation delays catch teams off guard just as often. Offline devices and vendor portal logins that live outside the identity provider are the quiet failure points, and they rarely surface until an audit asks for proof the access was actually removed.

A managed approach that ties a documented HR-to-IT trigger to an evidence-producing ticket closes most of this gap, because the containment step fires automatically instead of depending on someone remembering to flag it.

— 247techify Team

Why conventional offboarding advice falls short

Most offboarding checklists read like a list of account toggles, and that framing undersells what actually goes wrong. The accounts almost always get disabled. What gets missed is the data sitting in a mailbox nobody reassigned, the service account three other systems depend on, and the vendor portal login that nobody in IT knew existed until a bill arrived. The conventional advice treats offboarding as an identity-management task when it is really a data governance and evidence problem wearing an identity-management checklist.

The priority readers should take from this is sequencing, not thoroughness. A short list executed in the right order, contain first, preserve second, deprovision third, beats a long list executed out of order. Evidence matters just as much as the action itself: a disabled account with no record of who disabled it, when, and what was verified afterward does not hold up in an audit the way a logged, timestamped action does.

Offboarding sequence with timestamped evidence trail

How 247Techify supports secure, auditable offboarding

Offboarding is easy to document and hard to execute consistently when IT is managing it alongside everything else on the ticket queue. Managed IT support can handle Microsoft 365 administration, privileged access controls, device recovery and incident response as part of day-to-day coverage, with availability for urgent moments.

247techify

Relevant services for offboarding specifically include mailbox preservation, license timing and sign-in revocation, privileged access review and incident response, device recovery and asset tracking, and evidence-producing ticketing to track offboarding actions.

If your team wants a checklist review or a faster path to auditable offboarding, check current plans and pricing or reach out for a discovery call.

How 247Techify supports secure, auditable offboarding — overview diagram

Primary sources for offboarding timelines and technical steps

For deeper technical detail, see the Canadian Centre for Cyber Security’s personnel security guidance and Microsoft’s documentation on revoking user access.

Sources

FAQ

When should IT delete a former employee’s account?

Hold the account in a disabled state until data preservation, license transitions and any audit requirements are complete, rather than deleting it on the termination date. Microsoft’s guidance notes deleted-user OneDrive data is retained for 30 days plus 93 days in the recycle bin, so deletion timing affects how much recovery window remains.

How do you handle BYOD devices during offboarding?

Remove corporate mail profiles, revoke app-level access tokens and confirm any mobile device management enrollment is deprovisioned before the employee’s last day. A documented BYOD policy that defines what gets wiped versus what stays personal prevents disputes after the fact, as covered in guidance on BYOD policy controls.

What evidence should IT keep from an offboarding process?

Record the owner, action taken, timestamp and administrator for every checklist item, from password reset to final badge collection. This log is what demonstrates the offboarding was complete and auditable if a compliance review or legal matter arises later.

How fast does blocking sign-in actually take effect?

Blocking sign-in in Microsoft 365 environments can take up to 24 hours to propagate fully, according to Microsoft’s documentation, so resetting the password and revoking sessions separately provides faster containment in the interim.

What makes involuntary termination different from a standard offboarding?

Involuntary or suspected-compromise departures call for immediate, coordinated cutoff of access before the termination conversation happens rather than the staged sequence used for standard departures. The Canadian Centre for Cyber Security treats this as a high-risk case requiring synchronized HR and IT action.