Illustration of an ID badge and padlock representing an IT offboarding and access security checklist for UK businesses

IT Offboarding Checklist: How to Secure Access When Staff Leave

Table of Contents

Quick answer: Secure IT access in four stages when someone leaves: block sign-in and remote access on their last working day, secure their email and devices within 24–48 hours, transfer data and change any shared passwords within the first week, then review dormant accounts after 30 days. The full checklist below covers each stage in order, including the Microsoft 365-specific steps most businesses miss.

If someone is leaving your business, whether that’s a resignation, a redundancy or a dismissal, there’s a window where their old logins, devices and email access are still live. Most data protection and insider-risk incidents involving former staff happen in that window, not because anyone plans it, but because offboarding gets handled from memory under time pressure and something gets missed. This checklist is for whoever is responsible for IT in a UK small or mid-sized business, whether that’s an owner-manager, an office manager, or an internal IT lead, and it sets out exactly what to do and when.

4 stagessame day, 24–48 hours, first week, 30-day review
30 daysMicrosoft retains a deleted user’s email and OneDrive data before permanent removal
Least privilegethe NCSC principle behind why access should be revoked promptly
Same daywhen sign-in access should be blocked, regardless of notice period

The National Cyber Security Centre’s guidance on identity and access management recommends applying the principle of least privilege and having a clear policy covering when access should be granted and revoked, built around a joiners, leavers and movers process (NCSC, Introduction to identity and access management). Offboarding is the “leavers” half of that process, and it’s the half most businesses without a formal IT provider tend to do informally, if at all.

The IT Offboarding Checklist

Work through these four stages in order. Not every task will apply to every leaver, skip anything that genuinely doesn’t apply to your setup, but don’t skip a stage just because you’re short on time; that’s usually where gaps creep in.

1Same Day – Before or On Their Last Working Day

  • Block sign-in to email, Microsoft 365 or Google Workspace, and any core business systems
  • Revoke active sign-in sessions so an existing logged-in device can’t keep working after access is blocked
  • Disable remote access: VPN, RDP, and any remote desktop or admin tools
  • Remove them as a recovery contact or approver on any account, so they can’t be used to reset someone else’s access
  • Confirm with their line manager exactly what systems they had access to, don’t rely on a job title to guess

2First 24–48 Hours

  • Set up email forwarding or convert their mailbox to a shared mailbox so business continuity isn’t disrupted
  • Reclaim company devices: laptop, phone, tablet, security keys, ID badges and access cards
  • Remotely wipe or block any company data on a personal device used for work, most mobile device management tools can do this without touching the employee’s own data
  • Log the departing employee out of Microsoft Teams, Slack or any phone system app on personal devices
  • Reassign administrator rights for any software, social media account or shared platform they controlled

3Within the First Week

  • Change any shared or admin passwords the departing employee knew, this step is easy to forget and matters enormously
  • Transfer ownership of OneDrive, SharePoint or Google Drive files and folders to a manager before anything is deleted
  • Reassign or cancel software licences tied to their account so you’re not paying for seats you don’t need
  • Update your IT asset register to show devices and accounts as returned or closed
  • Record what was done and when, a simple dated log is enough, and it matters if questions come up later

430-Day Review

  • Check the account is genuinely closed rather than just disabled, and permanently delete it once you’re confident nothing further is needed from it
  • Confirm any forwarded email is still going to the right person, needs are often different a month on than they were on day one
  • Review whether any personal data connected to the leaver, home address, emergency contact, personal phone number, still needs to be kept
  • Run a wider check for any other dormant accounts across the business while you’re at it, leavers are rarely the only gap
In our experience: the step that gets missed most often isn’t a technical one, it’s step three, changing shared or admin passwords the departing employee knew. Businesses reliably remember to disable the individual’s own account but forget that they also knew the Wi-Fi password, the shared accounting login, or the social media password, all of which stay valid until someone actively changes them.

Standard Leaver or High-Risk Departure? Choosing the Right Timeline

Not every departure carries the same risk, and treating them all identically either wastes time or leaves a genuine risk unmanaged. Before you start, decide which category applies.

Standard departure

  • Resignation with normal notice, or planned retirement
  • Employee remains cooperative through their notice period
  • No disciplinary or grievance issues involved
  • Follow the four-stage checklist on their agreed last day

!High-risk departure

  • Dismissal, redundancy announced with immediate effect, or a disputed exit
  • Any sign the employee is unhappy about leaving
  • Access to financial systems, customer data or sensitive IP
  • Complete stage one immediately, ideally before or during the exit conversation, not after

For a high-risk departure, the order matters: access should be blocked at or before the point the employee is told, not scheduled for later in the day. This isn’t about assuming bad intent, it’s that a disgruntled employee with a live login for even a few extra hours is a risk that costs nothing to avoid. If your business doesn’t have a way to do this quickly out of hours or at short notice, that’s worth raising with whoever manages your IT support or cyber security services, since same-day access removal is something a managed provider can usually action within minutes.

Securing Microsoft 365 When Someone Leaves

Most UK small businesses run on Microsoft 365, and Microsoft’s own admin documentation sets out a specific seven-step sequence for removing a former employee: block sign-in first, save the contents of their mailbox, wipe or block their mobile device, forward their email or convert their mailbox to a shared one, give another employee access to their OneDrive and Outlook content, remove their licence, and only then delete the account itself (Microsoft Learn, Remove a former employee).

Two details from that process are worth knowing before you start. First, disabling sign-in and deleting the account are different actions, block sign-in on day one, but don’t rush to delete the account itself until you’ve confirmed nothing else needs recovering from it. Second, according to Microsoft’s current documentation, if you remove a user’s licence without deleting the account, their OneDrive and Outlook content stays accessible to admins indefinitely; if you delete the account outright, that content is retained for 30 days and then permanently removed. That 30-day window is your practical deadline for deciding what needs transferring to someone else before it’s gone for good.

If your business uses Microsoft 365 support from an external provider, confirm as part of your offboarding process who is responsible for actioning each of these steps and how quickly they can do it, particularly for a same-day, high-risk departure.

Personal Devices, BYOD and MFA Apps

Offboarding gets more complicated when staff use personal phones for work email or as their multi-factor authentication device, which is common in smaller businesses without company-issued mobiles. Three things to check specifically:

  • Remove company email profiles and any mobile device management enrolment from personal phones, most MDM tools can do this without wiping the employee’s personal photos or apps.
  • If their personal phone was set up as an MFA method (an authenticator app or a registered phone number), remove it from the account and register a replacement method for whoever inherits that access.
  • Check messaging apps like Microsoft Teams or Slack that can be signed into on a personal device independently of the email account, these need a separate sign-out or removal step.

Where a leaver’s personal device can’t be centrally managed, the safest approach is to change every credential that device had access to rather than rely on the employee deleting company data themselves.

What Employee Data You Can (and Can’t) Keep After They Leave

Offboarding isn’t purely a technical exercise, it also has a UK GDPR dimension. The ICO’s storage limitation principle means you shouldn’t hold onto a former employee’s personal data for longer than you actually need it, but that doesn’t mean deleting everything on day one. The ICO’s own guidance gives a useful example: an employer should review the personal data it holds about a leaver, keeping what’s genuinely needed, for example, to provide a reference or administer pension arrangements, while deleting information it’s unlikely to need again, such as emergency contact details, previous home addresses or death-in-service beneficiary details (ICO, Principle (e): Storage limitation).

In practice, that means your 30-day review isn’t just an IT task, it’s also a reasonable point to ask HR or whoever handles personal records what genuinely still needs to be kept, and to make sure the rest isn’t sitting untouched in an old mailbox or a shared drive for years after someone’s gone.

What This Checklist Doesn’t Cover

This is an IT and cyber security checklist, not HR or legal guidance. It won’t tell you how to structure a redundancy process, what notice periods apply, or whether a dismissal is fair, and it isn’t a substitute for professional employment law advice where a departure is contested or complex. It also isn’t a guarantee: following every item here significantly reduces the risk of a former employee retaining access, but it doesn’t replace a wider cyber security risk assessment if you’re concerned about broader gaps in how access is managed day to day, not just at the point someone leaves.

Frequently Asked Questions

Should I disable a leaver’s account or delete it straight away?

Disable it first. Deleting an account immediately can cut off access to files, emails or licences that still need transferring to someone else. Block sign-in on the last working day, transfer what’s needed during the following week, then delete the account once you’re confident nothing further is required from it.

What if the employee worked from home and used their own laptop?

Focus on the accounts and credentials rather than the device itself. You can’t wipe a personal computer, but you can revoke its access to company email, files and systems, and you should change any shared password it had access to, which achieves the same practical outcome.

Do we need to do this even for a friendly resignation?

Yes. Most incidents involving former staff aren’t the result of deliberate malice, they happen because a dormant account was never properly closed and an attacker found it, or because access was simply forgotten about. The process should be the same regardless of how the departure feels.

How long should we keep a leaver’s email account?

There’s no fixed rule. Most businesses forward mail to a manager for a set period, often 30 to 90 days, then convert the mailbox to shared or archive it. Match the period to how likely external contacts are to still email that address, then close it down rather than leaving it open indefinitely.

Want Offboarding Handled Automatically?

Talk to our team about a cyber security review that includes a proper joiners, leavers and movers process, so nothing gets missed when staff come and go.

Talk to Our Cyber Security Team

A member of staff leaving is routine, but the access they leave behind isn’t something to handle from memory. Work through the four stages above in order, treat high-risk departures differently from planned ones, and use the 30-day review as your backstop for anything the first week missed. It’s a short process to build once, and it closes a gap that’s genuinely common and genuinely avoidable.

Table of Contents