A Microsoft 365 offboarding checklist should block sign-in at the right time, revoke sessions, preserve mailbox and OneDrive data, remove group and Teams access, review SharePoint permissions, handle devices, remove admin roles, and clean up licences only after business data is safe. Offboarding must protect access and continuity together.
Small businesses often treat offboarding as a single account-disable task. That is not enough. Microsoft 365 accounts can own files, receive client mail, manage shared mailboxes, hold admin roles, sync data to devices, and connect to third-party applications.
Before The Last Day
Confirm the final working date, cutoff time, departure sensitivity, replacement owner, and data handoff plan. Sensitive departures may require access changes before the person is notified. Routine departures may allow a planned transition. Either way, make the decision before the last day arrives.
List the mailbox, OneDrive, Teams, SharePoint sites, groups, shared mailboxes, calendars, devices, MFA methods, admin roles, and business applications tied to the employee. This inventory prevents rushed decisions when the account is disabled.
Block Access And Revoke Sessions
At the approved time, block sign-in and revoke active sessions so existing browser or mobile sessions cannot continue. Review MFA methods, password reset information, devices, and any privileged roles. Remove admin access immediately when it is no longer needed.
A real scenario: a project manager leaves on good terms, but their phone remains signed into Teams and Outlook for several days because only the password was changed. Revoking sessions and reviewing devices closes that gap while the business handles files and mail separately.
Preserve Mail And Files
Decide what happens to the mailbox. It may need delegation, automatic replies, shared mailbox conversion, retention, or deletion depending on the business need. Check forwarding rules and inbox rules, especially if the user handled clients, invoices, support, or sales.
Review OneDrive before deletion or licence removal. Move team records into SharePoint, assign a manager access where appropriate, and confirm that important files are no longer dependent on the former employee’s personal storage.
Remove Workspace And Application Access
Remove the user from Teams, Microsoft 365 groups, distribution lists, shared mailboxes, SharePoint permissions, security groups, and third-party applications that use Microsoft sign-in. Check direct permissions and delegated access, not only group membership.
Assign new owners to Teams, SharePoint sites, shared mailboxes, recurring meetings, and business processes. Ownerless workspaces create support problems after the departure is forgotten.
Offboarding Checklist
- Confirm cutoff timing, departure sensitivity, and approval.
- Block sign-in and revoke active sessions at the approved time.
- Remove admin roles, risky delegation, and unnecessary group access.
- Preserve mailbox data and decide on delegation, replies, forwarding, or conversion.
- Review OneDrive and move business records to SharePoint.
- Remove Teams, SharePoint, shared mailbox, distribution list, and app access.
- Handle devices, synced data, MFA methods, and licence cleanup after data decisions.
Common Offboarding Mistakes
Do not delete the account before reviewing data. Do not remove the licence before confirming mailbox and OneDrive needs. Do not assume group removal catches direct SharePoint permissions. Do not leave automatic forwarding or mailbox delegation in place without a business reason. These mistakes are common because offboarding is often rushed.
Offboarding should include a communication plan. Managers need to know when access ends, who receives mailbox or file access, and where transferred records will live. Staff may need to know whether a former employee’s email has an automatic reply or whether client communication should go to a shared mailbox. These details prevent avoidable confusion after the technical work is complete.
For sensitive departures, limit the number of people involved and prepare changes before the meeting or notification. For routine departures, use the notice period to transfer ownership, clean up files, and reduce access gradually where appropriate. The same checklist can support both situations, but the timing and confidentiality are different.
Do not forget applications outside Microsoft 365. Many cloud services use Microsoft sign-in or send notifications to the employee mailbox. Offboarding should include line-of-business systems, password managers, accounting tools, CRM access, and vendor portals where the employee had an account or approval role.
Keep a short offboarding record for each departure. Include the cutoff time, who approved it, who received mailbox access, where OneDrive files moved, which devices were returned, which licences were removed, and which applications were checked. This record is valuable when questions arise months later about a file, client message, or invoice.
Review recent departures during the next monthly admin check. Offboarding gaps are easier to fix shortly after a departure than months later when managers have forgotten which files and systems mattered.
Next Step
Turn the checklist into a standard offboarding runbook before the next departure. OnlineV can help create a Microsoft 365 offboarding process through Cloud Management. Related pages include Cybersecurity, Managed IT Services, and Cloud and Microsoft 365 insights.
Sources and further reading
Need Help With Microsoft 365?
Clean up users, files, licenses, and access safely
OnlineV can review Microsoft 365, Teams, SharePoint, OneDrive, licensing, guest users, and permissions without turning cleanup into a disruptive project.
Continue Reading