Mon–Sat 10:00–18:00 London · UK
Remote & on-site ☎ 0207 096 0936
← Guides
Security

Employee Offboarding: The IT Security Checklist

Deleting a leaver's email isn't offboarding. Here's how to properly revoke a departing employee's access — every account, device and password — before it becomes a security hole.

There’s a common assumption that offboarding is an HR job with a bit of IT tacked on the end — collect the laptop, delete the email, done. It feels tidy. It’s also how businesses end up with former staff who can still log into the CRM three months after they left, shared passwords nobody thought to change, and a personal phone that’s quietly still syncing company files.

Proper offboarding isn’t deleting one account. It’s a deliberate sweep across every place a person could still get in. Most people leave on good terms and would never dream of misusing access — but security isn’t about trusting individuals, it’s about closing doors. A forgotten login is a door left open, and it doesn’t much matter whether the person who walks through it is your ex-employee or someone who later buys their reused password on the dark web. Either way, it’s your data.

Here’s how to do it properly.

Start with a leaver list, before anyone leaves

The reason access gets missed is that no one has a full picture of what a given employee could actually reach. It built up over months — a login here, a shared folder there, a SaaS tool they signed up for one afternoon.

Fix this once and it pays off forever. Keep a simple record, per person or per role, of the systems they use: their main account, the apps they log into, any shared logins they know, and the devices they hold. It doesn’t need to be fancy — a shared spreadsheet beats nothing. When they leave, you work the list instead of trusting your memory at 5pm on someone’s last day.

The core checklist

Work through these in roughly this order.

1. Disable the main identity first. Most businesses run on Microsoft 365 or Google Workspace, and that single account is the master key — email, files, Teams, calendars, and often sign-in to other apps too. Block the sign-in and reset the password. This one step shuts a surprising number of doors at once, which is why it comes first.

2. Kill the active sessions. Disabling an account doesn’t always boot someone who’s already logged in on their phone or a browser. Force a sign-out of all sessions and revoke any saved tokens, so an open laptop lid at home doesn’t stay live for hours.

3. Turn off remote access and VPN. If staff connect to your network or a remote desktop from home, that route has to close too. It’s separate from their email login and easy to forget.

4. Handle the mailbox, don’t just bin it. Block the login, but keep the contents. Convert the mailbox to a shared one or archive it so colleagues can still reach past correspondence, then set forwarding or an auto-reply to whoever’s covering. Deleting it outright loses business records you may need later.

5. Reassign their files and ownership. Anything stored only in their personal drive, or any shared document, workflow or automation they owned, needs a new owner before the account goes cold. Otherwise you lose access to it the moment you fully remove them.

6. Revoke the third-party and SaaS logins. This is the big one people miss. Every tool they signed into with a separate username and password — the accounting system, the design tool, the booking platform, the courier account — is invisible to your main account cleanup. Go through your leaver list and switch each one off or remove them as a user.

7. Change any shared passwords they knew. Shared logins are bad practice, but they exist everywhere. If a departing employee knew the Wi-Fi password, the shared social media login or a communal supplier account, those credentials are now compromised and need changing. A password manager makes this far less painful, because you can see exactly what was shared and rotate it in minutes.

8. Collect and wipe the devices. Laptops, phones, and any hardware token. If they used a personal phone for work email, make sure company data is removed from it — mobile device management lets you wipe just the work profile without touching their photos. Don’t wipe a returned company laptop until you’ve confirmed nothing important lives only on it.

9. Redirect the phone and forwarding. Their direct line, any call forwarding, and shared inbox membership. A customer shouldn’t reach a dead extension or, worse, still reach a former employee.

Don’t skip the paper trail

Whoever does the offboarding should tick each item off and note the date. It sounds bureaucratic, but if a data question ever comes up — a client asks who could have seen their information, or you have a security scare — being able to show that access was revoked on a specific date is worth a great deal. It’s also how you spot the step that got skipped last time.

Build it in before you need it

The businesses that offboard cleanly are the ones that set it up while everyone’s still employed — a leaver list that stays current, no shared passwords floating about, devices enrolled so they can be wiped remotely, and one person who owns the checklist. That groundwork is really just good cyber security hygiene, and it protects you against far more than a disgruntled ex-employee.

If you’re not confident every door closes when someone leaves — or you’ve inherited a setup where nobody’s sure who can still log into what — that’s exactly the kind of thing worth tidying up before it matters. Our team handles offboarding as part of ongoing managed IT support, and we’re happy to run through your current process and point out the gaps. Get in touch and we’ll take a look.

Frequently asked questions

How quickly should we revoke a leaver's access?

For a planned departure, aim to have everything switched off the moment their last working period ends — often by close of business on their final day. For a dismissal or any departure on bad terms, it should happen during the conversation itself, not after. The risky window is the gap between someone knowing they're leaving and their access actually being cut, so shrink it as far as you sensibly can.

Should we delete a departing employee's mailbox straight away?

No — disable the login first, but keep the mailbox. Deleting it can lose important business records, break email history and orphan anything only they had access to. The usual approach is to block sign-in immediately, convert the mailbox to a shared or archived one so colleagues can still reach past correspondence, and set up forwarding or an auto-reply. You can remove it properly later once you're sure nothing is needed.

What about accounts we don't manage centrally, like a supplier portal they signed up for?

Those are the ones that get missed. Anything an employee registered with their work email but that sits outside your main systems — a courier account, a marketing tool, a supplier login — won't be caught by disabling their Microsoft 365 or Google account. The fix is to keep a simple record of which external services each person uses, so at offboarding you have a list to work through rather than relying on memory.

Related services

Free · no obligation

Want a hand with any of this?

Tell us what you're trying to sort out and we'll come back with a clear, no-obligation plan and price.