Employee Offboarding IT Checklist for Businesses

Employee Offboarding IT Checklist: Closing Access the Right Way

Offboarding is onboarding in reverse: every account, device and permission you granted gets closed, collected or handed over on a set schedule. Tell IT the departure date and time early, cut sign-in access at the moment the person leaves, and keep the mailbox and files your business still needs.

Most offboarding gaps aren't dramatic. A former employee's email still syncs to a personal phone. A shared vendor password never got changed. A license keeps billing for someone who left in spring. Each one is small, and together they add up to access you no longer control. This checklist mirrors our new employee IT security checklist, because a clean exit depends on a good record of what was handed out at the start.

Before the last day: plan the exit

Notify IT with the date and time

Give IT the last working day and the exact time access should end. "Friday" isn't enough: 5:00 p.m. Friday and 9:00 a.m. Friday are very different plans. Include who the person reports to and who will take over their work, so questions about files and mailboxes have an owner.

Inventory devices and accounts

Pull the onboarding record and confirm what the person actually has today. People collect access over time, so check beyond what they started with:

  • Company laptop, phone, tablet, monitors and peripherals
  • Microsoft 365 or Google Workspace account, plus shared mailboxes and Teams or SharePoint memberships
  • Line-of-business applications (practice management, CRM, accounting, document management)
  • Remote access: VPN, remote desktop, cloud admin consoles
  • Vendor portals, banking and payment platforms, and any SaaS they signed up for on a company card
  • Physical items: badges, keys, alarm codes, hardware security tokens
  • Personal devices enrolled under your BYOD policy

Decide what happens to their data

Identify which mailboxes, OneDrive or Google Drive folders and local files someone else needs, and who that person is. Decide now whether the mailbox will be converted to a shared mailbox, forwarded for a period, or archived. Deciding this on the last afternoon is how files get lost.

Check for a legal hold

If your firm is regulated or involved in litigation, confirm with your compliance lead or counsel whether the person's email and files must be preserved before anything is deleted, converted or wiped. A preservation requirement changes the order of the steps below.

At departure: close access

These steps happen together, ideally while the person is in their exit meeting or right after they leave.

  1. Disable sign-in. Block the account rather than deleting it. Deleting too early can remove mail and files you still need.
  2. Revoke active sessions. Disabling an account doesn't always log out a phone or browser that is already signed in. Revoke sessions and refresh tokens so existing logins end.
  3. Remove MFA methods. Clear the registered authenticator apps, phone numbers and security keys so the old multi-factor authentication (MFA) methods can't be reused if the account is ever re-enabled.
  4. Reset shared passwords. Any shared account the person knew (a front desk login, a vendor portal, Wi-Fi, an alarm code) gets a new password. A password manager with shared vaults shows you which ones they had.
  5. Remove group memberships and admin roles. Take them out of security groups, distribution lists, shared drives and any administrator role. Admin roles deserve a second look.
  6. Handle the mailbox. Convert it to a shared mailbox, set forwarding, or add an automatic reply that points senders to a colleague, according to your policy.
  7. Transfer file ownership. Move OneDrive or Google Drive content to the manager or successor, and reassign ownership of shared documents and folders the person created.
  8. Remove company data from personal devices. For BYOD phones and laptops, use a selective wipe that removes company apps and data without touching personal photos and files.
  9. Collect hardware and physical access. Laptop, phone, chargers, badges, keys and tokens. Change alarm codes and door codes they used.
  10. Disable VPN and remote access. Include remote desktop tools and any firewall or VPN account that sits outside your main directory.
  11. Phone system. Reassign or forward the extension, update the call flow and auto-attendant, and save or forward voicemail.

After they leave: tidy up

  • Reclaim licenses. Once the mailbox and files are handled, remove or reassign the Microsoft 365 or Google Workspace license and any paid app seats. Unused licenses are a quiet monthly expense.
  • Vendor, SaaS and bank access. Remove the person from vendor portals, payment processors and online banking, and update authorized signers or contacts with your bank and key vendors. Tell finance staff to verify any payment or banking change requests by phone, using a number you already have on file.
  • Review sign-in logs. Check for sign-in attempts, mail forwarding rules or large downloads in the days before and after departure. Unusual activity is worth a conversation, and sometimes a closer look.
  • Update documentation. Record what was disabled, transferred and collected, by whom and when. For regulated firms, this record is evidence that access was removed.
  • Wipe and reissue hardware. Once any retention or legal hold question is settled, reset returned devices before they go to the next person.

Special cases

Involuntary terminations

Coordinate timing with IT before the conversation happens. Access should be disabled while the meeting is taking place, not afterward. Give IT the time privately, keep the circle small, and have the hardware collection plan ready. For anyone with administrator rights or access to money movement, plan this with extra care.

When the person leaving is your IT person

If the departing employee managed your systems, the scope gets bigger: admin accounts, domain and DNS registrars, firewall credentials, backup consoles and vendor relationships. See what to secure in the first week after your IT person quits.

Regulated firms and records retention

Disabling access is required. Deleting records may not be allowed. HIPAA requires covered entities and business associates to keep required documentation, such as policies and records of security activities, for six years. SEC-registered investment advisers have books-and-records obligations under Advisers Act Rule 204-2, and broker-dealers under Exchange Act Rule 17a-4, which can include business communications such as email. Converting a mailbox to a shared or archived state, rather than deleting it, keeps you from destroying records you may need. Records of access removal also support the safeguards your firm describes in its written policies, such as a GLBA written information security program or Regulation S-P procedures.

NerdSquad is not a law firm. Confirm your firm's obligations with your compliance counsel.

How NerdSquad handles offboarding

For managed IT clients, an offboarding request is a ticket to our IT help desk. Send it as early as you can with the date, time and who should receive the person's mail and files. We schedule the access cutoff for the time you give us, work through the checklist above, handle the mailbox, file transfer and license steps through our Microsoft 365 support, and document what was done in the ticket. For terminations, call us so we can coordinate the timing directly. If something looks off in the sign-in logs, we tell you.


Talk to NerdSquad

Already a client? Call (239) 465-0079 or submit a ticket. If something is down, call so we can start right away.

Not a client yet? NerdSquad Managed IT Services is a Managed Service Provider (MSP) based in Naples, Florida. We support businesses onsite across Southwest Florida and remotely nationwide. Book a discovery call or call (239) 465-0079.

Related: IT help desk for onboarding and offboarding