Offboarding: what actually has to be switched off when someone leaves
Somebody hands in their notice and everybody thinks about the handover, the holiday balance and the leaving card. The part that gets left until their last Friday afternoon is the list of things they can still log into on Monday.
Most of the time nothing happens, which is exactly why this keeps being done badly. This is what to switch off, the order that actually works, and the point at which a leaver taking data stops being an HR problem and becomes a criminal one.
"We disabled the account" is not the same as "they're out"
Microsoft's own guidance on removing a former employee contains a detail most people never read: blocking an account can take up to 24 hours to take effect. Not seconds. Up to a day. Which is why the same page tells you to reset the password first if you want to stop access straight away.
There's a second delay behind it. Once someone has signed in, they're carrying an access token, and that token is good for about an hour. Resetting a password doesn't reach into a session that's already running. The separate action that does is Sign out of all sessions, and even then Microsoft notes that someone sitting in Outlook on the web may not drop out until they click something else or refresh.
So the order matters more than the individual steps. Reset the password, sign out of all sessions, then block sign-in. Doing only the last of those, on a Friday at five, can leave a working session alive well into the weekend.
The list nobody has written down
Microsoft 365 is the easy part, because it's the bit IT definitely knows about. The exposure lives in everything else.
A typical small business leaver has, somewhere: a VPN profile, an account on the remote support tool, a login to the accounting package, the CRM, the website's admin panel, the domain registrar, the phone system portal, a shared mailbox or two, a Wi-Fi password, a door code, and at least one subscription they bought on a company card and never told anybody about. Some of those are individual accounts you can disable. Some are not.
Shared logins are the genuinely hard case, and they're everywhere. If four people use the same password for the courier account, you cannot remove one of them. The only real revocation is changing the credential for all four, which is precisely the friction that stops it happening. That's an argument for a password manager with individual accounts, which we've written about in password managers for small teams, and it's an argument you'll only win before the leaver, not during.
Email, and the thirty-day clock
The mailbox decision usually gets made badly because it gets made in a hurry.
When you remove or delete a licence, the email, contacts and calendar are retained for 30 days and then permanently deleted. That window is your entire margin for realising you needed something. If the work is being picked up by someone else, the two supported routes are converting the mailbox to a shared mailbox, or forwarding the address to whoever takes over, and both are worth doing deliberately rather than discovering a bounce three weeks later from a customer who's been emailing a dead address.
One useful wrinkle: if you keep the user account and only strip the licence, OneDrive content stays accessible to you beyond the 30 days. Delete the account outright and you're back on the clock, with restore as the only route in. Where there's any chance of a dispute, a legal hold through Purview is the mechanism for keeping the data on purpose rather than by accident.
Devices, and the awkward conversation about personal phones
Company laptop and company phone: straightforward. You can wipe and block a mobile device through the Exchange admin center, and the device goes back on the shelf without last month's client correspondence sitting in a cached mailbox.
Personal phones are where it goes wrong. A full remote wipe on someone's own handset takes their photographs with it, and doing that to a person on their last day is the kind of thing that ends up in a tribunal bundle. The answer is a selective removal of company data only, and, more importantly, a BYOD agreement signed when they joined that says exactly what will happen. That conversation is cheap in month one and expensive in month thirty.
When it stops being an IT problem
Most leavers take nothing. Some take the customer list, usually convinced it's theirs because they built the relationships.
Section 170 of the Data Protection Act 2018 disagrees. Knowingly or recklessly obtaining or disclosing personal data without the consent of the controller is a criminal offence, as is procuring its disclosure, and so is retaining it afterwards without consent. This is not theoretical. The ICO brings these prosecutions: a former RAC employee pleaded guilty at Dudley Magistrates Court in January 2023 to two counts under section 170, over data belonging to people involved in road traffic accidents, and was fined £5,000 plus costs and a victim surcharge. In other cases the fines have run to a few hundred pounds, which sounds trivial until you remember it comes with a criminal conviction attached.
Whether to involve the ICO or the police in a specific case is not our call to make, and we don't pretend otherwise. What decides whether that route is even available to you is whether you can show what was accessed and when, which brings it back to logs, retention and having noticed at the time.
What good looks like, and it isn't complicated
A leaver checklist that works has three properties: it names every system rather than saying "all accounts", it names a person against each one, and it has a date. It also starts with HR or the owner rather than IT, because IT is usually the last to know somebody is leaving.
Run it in this order and most of the risk disappears on day one: reset the password, sign out of all sessions, block sign-in, then work down the list of everything that isn't Microsoft, then deal with devices, then decide about the mailbox. Change any shared credential the person knew. Finally, and this is the step people skip, write down what you did, because "we're pretty sure someone removed their CRM access" is not an answer you want to give a client six months later.
For businesses we look after on a managed plan, that's part of the job: we hold the list, we run it, and we can tell you what was revoked and when. If you're not sure your current setup could answer that question today, a free IT health check will tell you honestly where the gaps are, and our managed plans cover the logging and endpoint tooling the rest of it depends on.
Frequently asked questions
Is disabling the Microsoft 365 account enough?+
Not on its own, and not as fast as people assume. Microsoft's own documentation says blocking an account can take up to 24 hours to take effect, and tells admins to reset the password first if they want to stop access immediately. Even then, an access token already issued is good for about an hour, so someone with a browser tab open may keep working until it expires or they navigate away. The complete version is: reset the password, then use "Sign out of all sessions", then block sign-in. In that order.
What happens to their email when we remove the licence?+
Mailbox contents, contacts and calendar are kept for 30 days after you remove or delete the licence, then permanently deleted. If someone needs continuing access to that email, the usual routes are converting the mailbox to a shared mailbox or forwarding it to whoever is picking up the work. If you keep the user account but only remove the licence, their OneDrive content stays accessible to you beyond the 30 days.
How long do we have to recover a deleted account?+
Thirty days. After an account is deleted, the OneDrive and Outlook content is retained for that window and you can restore the account to get at it. Restore within the 30 days and the content stays accessible afterwards. Leave it, and it goes.
What about the accounts that aren't Microsoft 365?+
That's usually where the real exposure is. VPN, the remote support tool, the accounting package, the CRM, the website admin, the domain registrar, the phone system, social media, and anything bought on a card by one person and never told to anyone else. If a system was reached with a password shared between staff, you cannot revoke one person from it: the only fix is changing the credential itself for everybody.
Should we wipe their phone?+
If it holds company mail, you can wipe and block a mobile device through the Exchange admin center, and for a company-owned phone that's the straightforward answer. On a personal device, a full wipe takes their photos with it, so the sensible route is a selective removal of company data, agreed in writing with staff before they ever connect a personal phone rather than argued about on their last day.
Is it actually illegal for a leaver to take the customer list?+
It can be a criminal offence, not just a contract dispute. Section 170 of the Data Protection Act 2018 makes it an offence to knowingly or recklessly obtain, disclose or procure the disclosure of personal data without the consent of the controller, and also to retain it afterwards without consent. The ICO prosecutes these. A former RAC employee pleaded guilty at Dudley Magistrates Court in January 2023 to two counts under section 170 and was fined £5,000 plus costs and a victim surcharge. Fines in other cases have been in the hundreds. The criminal record is the part that isn't small.
How would we even prove someone took data?+
From logs, if they exist and go back far enough. Mass downloads from cloud storage, unusual mailbox exports, large USB transfers and a spike in access to records the person had no live reason to open all leave traces. Whether you still have those traces a month later depends on retention you set up before it happened, which is the unglamorous half of this job.
Who should own the offboarding checklist?+
Whoever knows first that somebody is leaving, which is HR or the owner, not IT. IT usually finds out after the leaving do. The checklist itself should name the systems, name the person responsible for each one, and have a date against it, so that the question "did anyone revoke the CRM?" has an answer rather than a shrug.