Skip to content

How to Offboard an Employee from Microsoft 365 Without Leaving Security Gaps

Disabling an email account is not the same as removing access. Microsoft 365 environments are far more connected than they look, a single work login controls email, OneDrive, Teams, SharePoint, and dozens of third-party apps simultaneously.

Eric Ryan
Talk to us
·5 min read
Employee carrying a cardboard box of office belongings marked with a security shield and padlock icon.

When an employee leaves, most businesses focus on the obvious: disable the email account, collect the laptop, move on. On paper, it feels done. In practice, Microsoft 365 offboarding is one of the highest-risk moments for data security in any organisation, not because businesses are careless, but because Microsoft 365 environments are far more connected than they look from the surface.

A single work login in Microsoft Entra ID controls email, Teams, SharePoint, OneDrive, Intune-managed devices, and single sign-on to a long list of third-party business applications. Offboarding one person means unwinding all of that deliberately.

What offboarding really means in Microsoft 365

Microsoft 365 is not a single system. It’s a set of services sharing one identity, managed in Microsoft Entra ID. That identity, the work login, is the key that opens multiple doors simultaneously:

  • Outlook and Exchange (email, calendar, shared mailboxes, mail rules)
  • Teams (chats, meetings, files shared in channels)
  • SharePoint and OneDrive (files, permissions, external sharing links, synced devices)
  • Windows sign-in (if devices are Entra ID joined)
  • Intune (device management and compliance enforcement)
  • Single sign-on to business apps (CRM, finance, HR, e-signature, project tools)
  • Microsoft Authenticator (MFA methods and trusted device registrations)

Secure offboarding is the controlled shutdown of that digital identity and everything connected to it, without breaking business continuity in the process.

Two offboarding scenarios

The same tasks apply in both cases, but the order and urgency change.

Planned exit (notice period): The danger is not pressure, it’s drift. Tasks get parked, access stays live longer than it should, and the last day becomes a scramble. A planned exit is the easiest offboarding to get right, but only if it runs as a checklist with dates and a named owner, not a loose set of jobs that will “get done before they go”.

Immediate or high-risk exit (dismissal, dispute): The priority is containment first, continuity second. Stop access and revoke sessions before worrying about who answers the mailbox. If you try to sort continuity first, you extend the window where active access remains live.

The session revocation gap

Blocking a user’s sign-in stops new logins. It does not end existing sessions. A user may still have a live session in Outlook on their phone, a browser profile, or a desktop app. Session revocation, explicitly invalidating all refresh tokens, is the step that closes that gap.

The core steps in the right order

  1. Block sign-in and revoke sessions

    In Microsoft Entra ID (formerly Azure AD): disable the user account, then revoke all sessions and refresh tokens. This forces the user out of every active login. Outlook on mobile, browser sessions, desktop apps. Do this first. Everything else can wait.

  2. Remove privileged access

    Before dealing with the mailbox or files, remove elevated permissions: admin roles (Global Admin, Exchange Admin, etc.), membership of privileged security groups, ownership of Teams and Microsoft 365 Groups, and access to sensitive shared mailboxes (finance, HR, leadership). Privilege should be removed first; continuity work comes after.

  3. Secure the devices

    For Intune-managed devices: confirm BitLocker encryption is enabled, retire or wipe the device if it’s not promptly returned, and check the device’s compliance state. For phones enrolled in Intune: issue a selective wipe to remove corporate data while preserving personal content. For unmanaged devices: physical collection is the primary control. Intune can’t do much without enrolment.

  4. Handle the mailbox

    Convert the mailbox to a shared mailbox (this preserves the mailbox content without an active user account and helps with licensing). Grant controlled access to the manager or named replacement, specific, time-limited. Add an auto-reply directing contacts to the right person. Check for mailbox rules that forward externally, move messages to hidden folders, or delete content, these are a common risk in high-tension departures.

  5. Secure files and sharing

    Grant the manager time-limited access to the user’s OneDrive. Transfer critical working files into a team SharePoint location before closing the OneDrive. Review sharing links the user created, especially “anyone with the link” shares. Remove the user from Teams and Microsoft 365 Groups. Check SharePoint site memberships and direct permissions for sensitive sites. Ensure every Team and SharePoint site still has a remaining owner after the user is removed.

  6. Close down third-party apps and rotate shared secrets

    Review which business apps the user had access to, particularly those with local accounts rather than SSO. Revoke OAuth permissions the user granted to third-party tools connected to their Microsoft 365 account. Rotate any shared credentials the user had access to: shared mailbox passwords, VPN credentials, API keys, service account passwords, finance system approvals. Password managers make this systematic, if you have one, the audit is straightforward.

  7. Clean up and document

    Retain mailbox and OneDrive content for the required period under your data retention policy before deletion. Remove the user’s licence to avoid ongoing charges. Document what was done, when, and by whom, this matters for compliance audits and for troubleshooting access issues that surface weeks later.

The gaps we see most often

Across many Microsoft 365 environments, the same failure points appear repeatedly:

Session revocation is skipped. IT disables the account but doesn’t revoke active sessions. The user remains logged into their phone for days. This is the single most common gap.

OneDrive is deleted too quickly. Finance completes a month-end close, and the departing account manager’s OneDrive contained the client pipeline spreadsheet, proposals, and signed order forms. Nobody transferred the files first.

External sharing links survive the account. A user shared a SharePoint folder with “anyone with the link” and that link remains active after the account is disabled. The data is still publicly accessible.

Privilege removal comes last. The business focuses on the mailbox and files before removing admin roles. If the user still has a live session and elevated privileges, the exposure window is significant.

Shared credentials aren’t rotated. The departing employee knew the finance team’s shared password manager vault. That vault isn’t on anyone’s offboarding checklist.

What offboarding looks like with managed IT

A structured offboarding runbook, checked against the same list every time, with a named owner and completion sign-off, closes most of the gaps above. With a managed IT provider, the runbook runs as a service: the provider handles the technical steps in Microsoft 365, flags anything that needs a business decision (who gets the mailbox access, what to do with the OneDrive), and documents the completion.

That’s the difference between offboarding as admin and offboarding as a security process. The steps are the same; the rigour is different.

Share this article

Written by

Eric Ryan

Part of the Sereno IT team helping growing UK businesses make confident, jargon-free technology decisions. Read more microsoft 365 guidance in our Microsoft 365 library.

Getting More from Microsoft 365

Ready to take the next step?

Friendly, no-jargon guidance from the Sereno team. Tell us what's going on with your IT, we'll tell you what to do about it.

Talk to a Microsoft 365 specialist