OnlineV Insight

What To Review After an Employee Leaves the Company

Employee departures create security risk when access, devices, MFA, and shared credentials are not reviewed together. This checklist helps close the gaps without losing business continuity.

After an employee leaves the company, review every place they could still access business systems: Microsoft 365, email, devices, files, shared mailboxes, Teams, cloud apps, password managers, MFA methods, VPN, websites, vendor portals, accounting tools, and physical or recovery access. Disable what is no longer needed, transfer business data carefully, and keep evidence of the review.

Offboarding is not only an HR step. It is one of the most practical cybersecurity controls a small business can improve. A friendly departure can still leave old access behind, and an urgent departure can create confusion if nobody knows where the person had permissions.

Start With Identity And Email

The user account is usually the centre of the review. In Microsoft 365, block sign-in at the right time, reset the password, revoke sessions, remove or update MFA methods, and decide how email will be handled. Do not simply delete the account immediately. The business may need mailbox history, OneDrive files, Teams chats, shared mailbox access, or audit evidence.

Forwarding deserves care. Forwarding all mail to another employee may expose personal information or create confusion. In many cases, an out-of-office message, mailbox delegation, or shared mailbox conversion is cleaner than uncontrolled forwarding.

Review Files, Apps, And Devices

Staff access often extends beyond email. Review SharePoint, OneDrive, Teams, Dropbox, Google Drive, accounting systems, CRM, project management tools, line-of-business software, password managers, remote access tools, and vendor portals. For each system, decide whether access should be removed, transferred, or retained temporarily for business continuity.

Devices need a separate step. Recover company laptops, phones, keys, security tokens, and backup drives. Confirm encryption, wipe or reassign devices through the proper process, and remove personal devices from management or access lists where appropriate.

Business Scenario: The Forgotten Sales App

A salesperson leaves on good terms. The company blocks Microsoft 365 sign-in and collects the laptop, but nobody reviews the CRM, quoting platform, shared password vault, or email marketing system. Two months later, a client asks why the former employee still appears on an automated campaign and still has access to old proposals.

The problem was not hostility. The offboarding checklist stopped too early. A complete review would have included customer data systems, shared credentials, group memberships, integrations, and ownership transfer for recurring workflows.

Offboarding Checklist

  • Block sign-in, reset password, revoke sessions, and remove MFA methods.
  • Transfer or delegate mailbox, OneDrive, SharePoint, Teams, and calendar ownership as needed.
  • Remove access from password managers, accounting, CRM, payroll, ticketing, and business apps.
  • Review shared mailboxes, distribution lists, groups, and Teams memberships.
  • Recover devices, tokens, keys, backup media, and company phone numbers.
  • Remove VPN, remote desktop, Wi-Fi, building access, and vendor portal permissions.
  • Rotate shared credentials the employee may have known.
  • Document exceptions, transfer decisions, and the person who approved them.

Common Mistakes After Departures

  • Deleting the account before transferring business files or preserving needed records.
  • Blocking Microsoft 365 but forgetting password vaults and line-of-business apps.
  • Leaving shared credentials unchanged because the departure was friendly.
  • Forgetting vendor portals, domain registrar access, website logins, and backup consoles.
  • Failing to review mobile devices and authenticator apps tied to business accounts.

The timing of access removal should match the departure type. A planned retirement, normal resignation, immediate termination, and contractor project completion may all need different timing. What should not change is the checklist. The business should still review identity, devices, files, applications, vendors, shared credentials, and recovery access.

Pay attention to ownership of recurring work. Departing staff may own shared calendars, distribution lists, Power Automate flows, website forms, social media pages, billing notifications, or vendor relationships. If those are not transferred, work can fail weeks later even though the security portion seemed complete.

For higher-risk departures, consider a short post-offboarding audit. Confirm the account remains blocked, no new forwarding was added before departure, shared passwords were rotated, and recovered devices were wiped or reassigned properly. This gives leadership evidence that the process finished rather than relying on a verbal update.

Contractors need the same discipline. A short-term bookkeeper, web developer, marketing freelancer, or temporary administrator may receive access quickly during a project. When the work ends, remove accounts, revoke shared links, rotate any shared credentials, and confirm that billing or recovery email addresses were not left under the contractor’s control.

Use the review to improve onboarding too. If offboarding reveals that nobody knew which systems a role used, update the onboarding template for the next hire. Security improves when access is granted from a known role list instead of rediscovered at departure.

Next Step: Build Role-Based Offboarding Templates

Create separate offboarding checklists for finance, sales, operations, administrators, and contractors. Each role touches different systems. OnlineV can help through cybersecurity and access review work that keeps departures controlled without losing business data. Related support: managed IT services, cloud management, and cybersecurity insights.

Sources and further reading

Need Help Reducing Risk?

Separate urgent security gaps from noise

OnlineV can help review MFA, admin access, email risk, devices, backups, and offboarding so the next step is clear and realistic for your business.

Cybersecurity Assessment Cybersecurity Services
Book a Free IT & AI Review View Cybersecurity Services

Continue Reading

Three useful guides on this topic

What Small Businesses Should Know About Cyber Insurance Requirements Cyber insurance applications often expose weak security evidence. This guide helps small businesses prepare honest answers, close common... How To Build a Simple Incident Response Plan for a Small Business A simple incident response plan gives staff clear first-hour actions, contact paths, and recovery order before a breach... Why Shared Admin Accounts Create Security Problems Shared admin accounts hide who changed what, make access harder to remove, and weaken incident response. This guide...