Bay Geeks logoTampa Bay IT Support · Since 2004
Bay Geeks Guide · Security Checklist

Employee Offboarding Checklist for Small Business IT

The day someone leaves, the account they used is the most dangerous thing in the building, and deleting it is the wrong first move. Here's the list we run, in the order that keeps the data, closes the doors and doesn't strand anyone.

Offboarding is where small businesses lose data and keep risk, usually at the same time. The mailbox gets deleted before anyone saved the client threads in it, while the former employee's phone keeps syncing the calendar for another week. Both come from the same instinct: clean it all up fast. The right order is slower for about an hour and safer for years.

The Short Version

Disable, don't delete. Revoke every open session. Capture the mailbox and the files. Wipe the devices. Rotate the shared passwords. Then, after the retention window, decide what to delete. Most of the mess we see comes from running that list backwards.

Why “Just Delete the Account” Backfires

Deleting drops the mailbox, the files and the calendar, sometimes past the point of getting them back. It also doesn't reliably end a session that's already signed in on a personal phone; the phone keeps syncing until its token expires, which can take days. Disabling and revoking does both jobs and keeps the data.

The Same-Day List

01

Block sign-in and reset the password

Microsoft 365: block sign-in. Google Workspace: suspend the user. Reset the password as well, so nothing cached anywhere still works.

02

Revoke sessions and MFA

Microsoft: revoke sessions and reset the MFA methods. Google: sign the user out of all sessions and reset sign-in cookies. This is what actually ends the access on a personal phone.

03

Capture the mailbox

Microsoft 365: convert it to a shared mailbox, which keeps every message without a license, then set an auto-reply or forward to the manager. Google: export or transfer the mail, then downgrade the account. Decide the retention window now; 30 to 90 days is typical, longer if a dispute is possible.

04

Transfer the files

OneDrive: give the manager access before anything is deleted. Google Drive: transfer ownership. Check SharePoint, Teams and shared drives for documents they owned, and any client folders on their laptop that never synced.

05

Remove from groups and channels

Distribution lists, Teams and Slack, shared calendars, security groups, and the customer-facing aliases like info@ and support@.

06

Revoke app access and tokens

Third-party apps the account authorized, app passwords, API keys, automation tools, the CRM, Dropbox, the company social media pages, Canva, Adobe, and their QuickBooks user.

07

Collect and wipe devices

The laptop, with its BitLocker key already on file. The phone, through Mobile Device Management: wipe the work data on a personal phone, the whole device if company-owned. Keys, badges, hardware tokens. Then remove the devices from MDM.

08

Rotate what they knew

The Wi-Fi passphrase, alarm and door codes, shared logins for vendor portals and social accounts, the office Amazon account, the shared vaults in the password manager, voicemail PINs.

09

Remove from money and admin

Bank and merchant portals, payroll, company cards, the domain registrar and DNS (see who owns your domain), hosting, Microsoft or Google admin roles, the backup console, and the phone system.

10

Look for forwarding rules and exports

Before locking the mailbox down further, check its rules and recent activity: forwarding to a personal address, or a large download from OneDrive in the last week. If you find either, that's a conversation with counsel, not a shrug.

Week One and After

Where they had accessSame dayLater
Email and filesBlock, revoke, convert to sharedDelete after the retention window
Personal phone with work emailRevoke sessions; MDM work-profile wipeRemove from MDM
Company laptopCollect; keep it encrypted; reimageReassign
Shared passwordsRotateAudit the shared vault
Admin rolesReassign, then removeReview quarterly
Banking, payroll, registrarRemove todayConfirm in writing

The Bad-Exit Version

For an involuntary termination, run steps one and two while the conversation is happening, not after it. For the weeks that follow, identity threat detection on our Advanced plan flags any sign-in attempt against a disabled account, or an old session waking up, so a former employee's access is a logged event rather than a surprise. Our wire fraud guide covers the other reason to care: a still-open mailbox is the starting point for most invoice fraud.

Quick Self-Check

QuestionIf “no” or “not sure”...
Is there a written offboarding list, or does it live in someone's head?Copy this one
Could you cut off a former employee's phone access in five minutes, without their phone?Worth a call
Does anyone still know the Wi-Fi password from three hires ago?Rotate it
Who else holds admin, registrar and bank access if the owner is out?Write it down
FIXED ✓

Have Us Run the List

Offboarding is a help-desk ticket on our Premium and Advanced business plans: we block, revoke, capture and wipe the same day, and keep the record for your files.

Frequently Asked Questions

Can I read a former employee's mailbox?

It's the company's account, and for business purposes the answer is usually yes; converting it to a shared mailbox is the clean way to do it. If there's a dispute or the person handled anything sensitive, ask your attorney first.

How long should I keep the mailbox?

Thirty to ninety days covers most handoffs. Regulated industries and anything that might end up in litigation call for longer, and a shared mailbox in Microsoft 365 costs nothing to keep.

They used a personal phone for work email. How do I get it off?

Revoking sessions and resetting the password (steps one and two) ends the access. With Mobile Device Management in place, IT can also wipe the work profile remotely, which is the reason MDM is included on our Premium plans.

What if the person leaving was the administrator?

Move the global admin role, the registrar and DNS logins, hosting, the bank tokens and the backup console first, then run the list. Every business should also keep a break-glass admin account that isn't tied to any one employee.

Do contractors need this too?

Yes. Same list, usually shorter. Contractors are the accounts most often forgotten, because nobody thinks of a project ending as a departure.

Wire Fraud and Fake Invoice Emails

How business email compromise moves real money, and the callback rule that stops it.

Who Owns Your Domain?

The registrant on record owns it, not the person who pays the invoice. How to check.

Passkeys, Explained

The sign-in method a fake login page can't steal, and how to set one up.

Identity Threats 101

Why a stolen password is now the most common way in, and how it's stopped.

Cyber Insurance Questionnaire

What carriers ask about MFA, backups and EDR, and how to get to an honest yes.

Lost or Stolen Phone

Lock it, protect the accounts on it, and suspend the line, in the right order.

📞 727-579-4335  ·  ✉️ support@baygeeks.com  ·  Privacy Policy  ·  Terms of Service

Call Now Schedule