Before You Delete That Employee’s Microsoft 365 Account…

An employee turns in a laptop, hands over a key, and walks out the door. From the business side, the departure may feel complete.

However, their digital access tells a different story.

Their phone may still connect to company email. A personal OneDrive folder may hold files that nobody else knows exist. Meanwhile, customer conversations may remain buried in an inbox. The employee may also own a Microsoft Form, a Power Automate workflow, or an account used to manage a critical vendor.

This is where an informal offboarding process creates trouble. For example, one business deletes the employee’s account immediately and later realizes it also lost access to important information. Another leaves the account untouched for weeks because nobody knows what they can safely remove.

A reliable IT offboarding process must do two things at once: close the former employee’s access promptly and preserve the business information others still need.


Start by securing the account—not deleting it

Deleting a Microsoft 365 account should rarely be the first move.

First, prevent the former employee from signing in. That typically includes blocking sign-in, resetting the password, signing the account out of active sessions, and revoking access to email and other connected services.

Microsoft’s own offboarding guidance puts access control ahead of account deletion for a reason. The account may still contain email, contacts, calendar history, OneDrive files, and other information the business needs to transfer or retain.

Timing matters, too. For a planned departure, IT can prepare the transition in advance and disable access at the agreed-upon time. However, an unexpected or involuntary departure requires tighter coordination between leadership, HR, and whoever manages IT. Access should not remain active simply because someone forgot to submit a ticket.

The first question is simple: At what exact time should this person lose access, and who is responsible for making it happen?

If nobody owns that decision, the rest of the process is already on shaky ground.


Decide what should happen to the employee’s email

A former employee’s inbox often contains more than old messages. It may hold open proposals, customer requests, vendor conversations, renewal notices, meeting history, and context the next person needs to keep the work moving.

Before removing the account or its license, decide:

  • Who needs access to the existing mailbox?
  • Should you forward new messages, and for how long?
  • Should the address become a shared mailbox?
  • Does the employee own a shared calendar or recurring meeting?
  • Are they listed on distribution groups, shared mailboxes, or automated alerts?
  • Does the business need to retain the mailbox for legal, regulatory, or contractual reasons?

Microsoft warns administrators not to delete an account that anchors email forwarding or a shared mailbox. Make those decisions before deletion… not after messages begin bouncing.

In addition, forwarding deserves an expiration date. Sending every future message to another employee indefinitely can clutter inboxes and leave old responsibilities in limbo. Instead, assign a temporary owner, communicate the employee’s departure where appropriate, and update customers and vendors with the correct long-term contact.


Transfer the files before the retention clock becomes a problem

OneDrive can look like a company file system while still being tied to an individual user. That distinction becomes important when the employee leaves.

Someone should review the former employee’s OneDrive and transfer business records to an appropriate owner or shared location. In particular, look for private folders, documents linked from old emails, and files that customers or coworkers access through the employee’s personal sharing links.

Microsoft provides a retention window for a deleted user’s OneDrive, but the exact period depends on the organization’s configuration. A default window should never become the company’s offboarding strategy. The safer process is to identify what must be retained and move it deliberately while access is still under control.

As a result, the departure can also test how the company stores information. If critical contracts, procedures, or customer documents exist only inside one employee’s OneDrive, the business has a broader continuity problem. Shared business records generally belong in a properly managed SharePoint, Teams, or departmental location where access does not depend on one person’s employment status.


Look beyond email and Microsoft 365

Microsoft 365 may be the obvious account, but it is rarely the only one. Depending on the employee’s role, their access may include:

  • VPN, remote desktop, and remote support tools
  • Accounting, payroll, banking, or expense platforms
  • CRM, quoting, ticketing, and project-management systems
  • Electronic health record or practice-management software
  • Manufacturing, inventory, or line-of-business applications
  • Cloud storage and file-transfer services
  • Password managers and shared credentials
  • Vendor, insurance, benefits, and purchasing portals
  • Company social media, website, and advertising accounts
  • VoIP extensions, voicemail, call queues, and text messaging
  • Building access, alarm codes, door badges, and physical keys

Then there are the accounts nobody officially approved. An employee may have created a free project-management account, connected a personal file-sharing service, or saved a company password in their browser. Because the company’s normal IT inventory never captured these tools, they become much harder to find.

Therefore, a checklist alone cannot solve every offboarding problem. The business also needs visibility into the systems employees use while they are still employed.


Never overlook phones, tablets, and active sessions

Changing a password does not always close every active session immediately. For that reason, a complete offboarding process should revoke active sessions and review registered devices, authentication methods, app passwords, and remote-access connections.

Next, collect, inventory, and secure company-owned equipment before reassigning it. If an employee accessed business data from a managed mobile device, IT may be able to remotely remove the company account or business data. Microsoft specifically includes wiping and blocking managed mobile access in its former-employee process.

Personally owned devices create a more complicated situation. Once an employee downloads a file to an unmanaged personal computer or phone, the business may have limited ability to remove that local copy. Clear device and data-handling policies keep the company from confronting this question for the first time during a difficult departure.


Transfer ownership of the work hiding behind the account

Email and files receive the most attention, but modern accounts often own processes as well as information.

The departing employee may own:

  • Microsoft Forms that collect customer or internal submissions
  • Power Automate flows that route approvals or notifications
  • Teams, SharePoint sites, shared calendars, or Planner boards
  • Recurring reports and scheduled exports
  • Vendor accounts connected to their individual email address
  • Multifactor authentication for a shared administrative account
  • Website forms, domain registrations, or billing notifications

These dependencies may continue working for a while, which makes them easy to miss. Eventually, the failure appears when an approval stops routing, a renewal notice disappears, or nobody can authenticate to an important account.

For this reason, offboarding should include a review of what the person owned, not only what they could access.


Reclaim the license after the information is protected

Businesses understandably want to stop paying for an unused Microsoft 365 license. That should happen after you address the mailbox, files, workflows, and retention requirements.
Removing a license can start time-sensitive data-retention consequences for services attached to the user. Saving a few dollars immediately is not worth discovering later that a replacement employee cannot access the records needed to do the job.
Finally, remove and reassign the license after your team secures the data and transfers the employee’s responsibilities. Follow the organization’s Microsoft agreement and licensing plan.


Employee IT offboarding checklist

What should happen when an employee leaves?

Follow these three stages to secure access and preserve important work.

Step 1 · Prepare

Before the employee’s final day

  • Set the final working time and access cutoff.
  • Assign an owner for email, files, and ongoing work.
  • Inventory devices, applications, roles, keys, and badges.
  • Confirm retention, legal, compliance, and HR requirements.
  • Plan the customer, vendor, and coworker handoff.
Step 2 · Secure

When access should end

  • Block Microsoft 365 and other business sign-ins.
  • Reset passwords and revoke active sessions.
  • Disable VPN, remote access, and administrator privileges.
  • Secure or remove company data from managed devices.
  • Collect computers, phones, keys, badges, and equipment.
Step 3 · Transfer

After access is secured

  • Transfer email, files, and important records.
  • Reassign calendars, Teams, groups, and workflows.
  • Remove vendor, phone, password manager, and app access.
  • Change shared credentials, then remove licenses after protecting the data.
  • Document what was completed, by whom, and when.

Do not begin by deleting the account. Secure access and preserve the information the business needs first.

Executive Takeaway: Could your business complete this process today?

Consider one practical scenario: a key employee leaves this afternoon. Would someone know every system they can access, where their important files live, which customers rely on their inbox, and what automated processes they own?

If the answer depends on one person’s memory, then the company has more exposure than it realizes.
Strong offboarding does not require a huge internal IT department. It requires a defined process, a current view of user access, and coordination between business leadership and whoever manages the technology.

BrownCOW Technology helps businesses across Cincinnati, Northern Kentucky, Dayton, and Columbus manage employee accounts, devices, Microsoft 365, data protection, and the day-to-day IT controls that are easy to overlook until someone leaves.

*P.S. — Need to tighten up your employee onboarding and offboarding process? Schedule a FREE IT Strategy Call with BrownCOW Technology.

Free Cyber Risk Consultation

Not sure your cybersecurity would hold up under review?

Cyber insurance renewals, security questionnaires, and client requirements are asking businesses to prove their IT controls are actually in place.

Review cyber insurance and security requirements

Strengthen MFA, backups, endpoint protection, and email security

Identify gaps before they become expensive problems

Monitor systems 24/7 with real-time protection

Schedule a Free Cyber Risk Consultation

We’ll help you understand what’s protected, what needs attention, and what to review next.

BrownCOW Technology helps steer your IT in the right direction

PROTECTING OUR HERD FROM CYBER THREATS

Medical & Dental

Property Management

Manufacturing

Professional Services