Offboarding is an identity-and-information-control process, not simply a license removal. A user may have access through Microsoft 365, a managed device, a personal phone, shared mailboxes, distribution groups, Teams, SharePoint, OneDrive, VPN, an ERP platform, line-of-business applications, or a vendor portal. The correct sequence matters because disabling the wrong item too early can interrupt the business or remove access needed to preserve information.
Before the departure time
- Confirm authorization and timing. Record who approved the offboarding, the effective time, whether the departure is routine or sensitive, and which people should receive status updates.
- Identify the full access footprint. Review Microsoft 365 roles, groups, shared resources, devices, VPN, remote access, ERP and application accounts, physical access, vendor portals, and any known personal-device use.
- Decide what the business must preserve. Establish the owner for email, OneDrive, Teams, SharePoint, records, business contacts, and work in progress. Confirm retention or legal-hold requirements with the appropriate business or legal decision-maker.
- Prepare continuity. Identify who will receive urgent messages, own scheduled meetings, manage shared resources, continue workflows, and communicate with customers or vendors.
At the approved cutoff
- Block sign-in. Disable the user's ability to authenticate at the authorized time instead of relying only on a password change.
- Revoke active sessions. Invalidate existing sessions and review authentication methods, registered devices, application passwords, and other persistent access paths supported by the tenant.
- Protect privileged access. Remove administrator roles, delegated authority, group ownership, application ownership, and vendor-management privileges that should no longer remain with the account.
- Review mailbox behavior. Check forwarding, inbox rules, delegates, shared-mailbox access, send-as rights, and automatic replies. Configure continuity only with business approval.
- Address managed devices. Coordinate return, lock, wipe, local-account review, encryption recovery, and evidence preservation according to company policy and device ownership.
Preserve information and transfer ownership
Account access and information retention are separate decisions. The organization may need the account blocked immediately while retaining mailbox and file content for operational, contractual, or legal reasons. Confirm the applicable Microsoft licensing and retention behavior before removing a license or deleting the account.
- Transfer ownership of OneDrive files, Teams, groups, forms, automations, shared calendars, and application connections.
- Review recurring meetings and business workflows that depend on the user's identity.
- Preserve information using the organization's approved retention, backup, export, or legal process.
- Document any information that could not be transferred and the provider or business decision still required.
Verify and close the work
A completed offboarding record should show the approved time, actions performed, important exceptions, transferred resources, devices returned, licenses changed, data retained, follow-up owners, and final verification. Sensitive departures may also require review of recent sign-ins, mailbox activity, file activity, administrative changes, or endpoint alerts—but that review should have a defined authorization and evidence-handling approach.
- Confirm the user can no longer sign in through expected paths.
- Verify replacement owners can reach the resources assigned to them.
- Confirm forwarding, automatic replies, and delegates match the approved plan.
- Record licenses available for reassignment without assuming immediate removal is safe.
- Set a dated follow-up for retained accounts or data that require later disposition.
Frequently asked questions
Should the Microsoft 365 account be deleted immediately?
Usually not before required email, files, ownership, retention, legal, and continuity needs have been reviewed. Block access first, then follow the approved preservation and disposition plan.
Does changing the password sign the user out everywhere?
A password change alone should not be treated as complete containment. Review active sessions, authentication methods, tokens, devices, forwarding, delegates, and connected applications within the authorized scope.
Official platform references
When outside help is useful
Bring in support when administrator ownership is unclear, the tenant includes former vendors, retention requirements are uncertain, the departure involves a privileged user, multiple systems must be coordinated, or the business cannot confidently verify the final state. CTS provides Microsoft 365 support and can help turn the checklist into a controlled, documented project.
