Microsoft 365 Employee Offboarding Checklist
September 4, 2026
Employee offboarding should protect access, preserve company data, transfer ownership, and recover licenses. This checklist covers the Microsoft 365 side of the process.
.jpeg)
Employee offboarding is both an HR process and an IT security process. The technology side needs to remove access quickly while preserving the business information, mailbox history, files, and ownership relationships the organization still needs.
The exact sequence may vary for a normal departure, immediate termination, contractor exit, or employee moving into a different role. The checklist below provides a practical Microsoft 365 baseline.
Before the employee's final access window
HR, the manager, and IT should agree on the timing. For sensitive departures, access may need to be disabled at a specific moment rather than at the end of the workday.
IT should know who will receive ownership of the employee's responsibilities, mailbox information, shared files, and relevant applications.
1. Block sign-in
Disable the user's ability to authenticate to Microsoft 365 at the agreed time. The account may need to remain in the tenant temporarily for data preservation, mailbox conversion, or administrative purposes even though sign-in is blocked.
2. Revoke active sessions
Blocking future sign-in is not the same as terminating every active session. Revoke supported sessions or tokens so previously authenticated devices and browsers do not retain access longer than intended.
3. Reset or secure authentication methods
Remove or reset authentication methods as appropriate to the environment. This is especially important when a departing employee managed shared services or administrative workflows.
4. Review administrative roles
If the user had Microsoft 365 administrative permissions, remove those roles and confirm that necessary responsibilities are assigned elsewhere.
Also review administrative access to non-Microsoft systems, because the employee's Microsoft 365 account may have been used for SSO.
5. Preserve the mailbox
Determine whether the mailbox should be converted to a shared mailbox, retained under an applicable policy, delegated to a manager, or handled another way based on business and legal requirements.
Avoid automatically giving another employee unrestricted mailbox access without confirming the organization's policy and legitimate business need.
6. Handle email forwarding or replies intentionally
Leadership may want incoming mail redirected or an automatic reply explaining the employee is no longer with the organization. Define how long that configuration should remain in place instead of leaving it indefinitely.
7. Transfer OneDrive ownership
Identify business files stored in the user's OneDrive and transfer or preserve the information required by the company. Personal working habits can leave critical business documents in individual storage.
8. Review SharePoint, Teams, and group ownership
A departing employee may own Microsoft 365 groups, Teams, SharePoint sites, distribution lists, shared mailboxes, or recurring workflows. Assign new owners before deleting or permanently removing the account.
9. Remove external and application access
Review enterprise applications, third-party OAuth permissions, SaaS platforms using Microsoft SSO, and any systems where the user had privileged access.
Offboarding should extend beyond the Microsoft tenant into the complete application inventory.
10. Recover Microsoft licensing
Once the mailbox, data, retention, and account requirements are resolved, remove licenses that are no longer needed so they can be reassigned or the subscription count adjusted.
11. Recover and secure company devices
Coordinate laptop, phone, token, key, and other asset recovery. For managed devices, confirm company data and access are handled according to policy before the equipment is reassigned.
12. Update documentation and vendors
Remove the employee from documentation, escalation contacts, vendor accounts, administrative lists, and support contacts. If they were the primary relationship with a vendor, assign a new owner.
Common offboarding mistakes
- Deleting the account before business data is preserved
- Blocking sign-in but leaving active sessions or SSO access
- Forgetting shared mailbox, Teams, or group ownership
- Leaving paid licenses assigned indefinitely
- Ignoring third-party applications
- Leaving a departed administrator as the only owner of a system
- Failing to recover or wipe company devices appropriately
Build offboarding into normal operations
The process should not depend on someone remembering a dozen tasks from memory. HR or operations should trigger a documented workflow that gives IT the departure time, manager, data instructions, and equipment information.
For the broader tenant-security context, use our Microsoft 365 security checklist. Two Factor also manages ongoing identity, licensing, onboarding, and offboarding through Microsoft 365 Managed Services.